Back to skill

Security audit

usgs-data-download

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward USGS water-data download guide with a normal dependency-install caution.

Before installing, use a virtual environment and consider pinning `dataretrieval` to a reviewed version, especially in production or regulated workflows. The skill does not show deceptive behavior or request unusual access beyond fetching USGS data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–16
Vulnerability Type: Insecure dependency installation
Risk Level: Medium

Vulnerable Code:

markdown
## Installation
```bash
pip install dataretrieval
text

### Technical Analysis

The installation command resolves and installs the latest available version of `dataretrieval` and its transitive dependencies without a version constraint, cryptographic hashes, or a lockfile. Consequently, the code installed in the future may differ from the code reviewed during this audit.

Python package installation can execute package-controlled build or installation logic. If the package, one of its transitive dependencies, or the package-index resolution process is compromised, following this instruction could execute attacker-controlled code. This finding identifies a supply-chain weakness; it does not establish that the named package is currently malicious.

### Attack Path

1. An attacker compromises a future release of `dataretrieval` or one of its transitive dependencies, or otherwise influences package resolution.
2. A user follows the Skill's unpinned `pip install dataretrieval` instruction.
3. `pip` resolves and downloads the attacker-controlled package version.
4. Malicious installation/build logic or imported package code executes in the user's environment.
5. The payload operates with the privileges and network/file access of the user running the installation or subsequent examples.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the account running `pip` or importing the package. The attacker could access or modify files available to that account, read environment variables and credentials, make network requests, or alter the Python environment. If installation is performed with elevated privileges, the scope could extend system-wide; the Skill itself does not instruct users to el
...[truncated 17 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin dataretrieval to a reviewed, exact version rather than resolving the latest release.
  • Maintain a lockfile that pins all transitive dependencies.
  • Require cryptographic hashes during installation, for example through a hash-pinned requirements file and pip install --require-hashes -r requirements.txt.
  • Install the dependency in an isolated virtual environment using a non-privileged account.
  • Review dependency provenance, release history, and known vulnerabilities before updating pinned versions.
  • Use an internally controlled package mirror or allowlist where stronger supply-chain assurance is required.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.