Back to skill

Security audit

aa-pair-analysis

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible protein-analysis skill, but its installer can fetch and enable an executable insecurely and modify the user's shell environment without enough control.

Review before installing. Do not run scripts/setup.sh as-is on a sensitive machine; install dependencies manually from trusted package managers or an isolated virtual environment, avoid the HTTP binary fallback, and do not allow automatic ~/.bashrc edits. Use simple task names without slashes or .., inspect generated CSV files before opening them in spreadsheets, and independently validate any laboratory formulation tables before use.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/setup.sh:99
Finding

Unverified Native Executable Downloaded over Plaintext HTTP

Content
View full analysis
> "$HOME/.bashrc" export PATH="$HOME/.local/bin:$PATH" fi ``` The English text substituted in the failure branch above represents the original informational message; the security-relevant commands and URL are unchanged. ### Technical Analysis The setup script downloads a native executable through unauthenticated plaintext HTTP. It does not verify a cryptographic checksum, digital signature, certificate-protected transport, or trusted package metadata before granting execute permission. Although the configured domain is associated with the declared Clustal Omega dependency, HTTP provides neither payload confidentiality nor authenticity. A network-positioned attacker can replace the response with an arbitrary executable. A compromise of the remote HTTP endpoint or its delivery infrastructure would have the same effect. The downloaded file is installed as `$HOME/.local/bin/clustalo`. The workflow subsequently executes `clustalo`, making the downloaded content an effective remote payload whose contents can change after the Skill package has been audited. The installer also adds `$HOME/.local/bin` to `.bashrc` if the path is absent. This increases exposure because the downloaded program remains discoverable in later shell sessions. ### Attack Path 1. A user follows the first-use setup instruction and executes `scripts/setup.sh`. 2. `clustalo` is not already installed. 3. Installati ...[truncated 1168 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:33
Finding

Unpinned Python Dependencies Installed into the Active Environment

Content
View full analysis
=]*}" &>/dev/null; then VER=$(python3 -c "import importlib.metadata; print(importlib.metadata.version('${pkg%%[>=]*}'))" 2>/dev/null || echo "unknown") ok "${pkg} (${VER})" else INSTALLED=0 if command -v pip3 &>/dev/null; then pip3 install "$pkg" --quiet && INSTALLED=1 fi if [[ $INSTALLED -eq 0 ]] && python3 -m pip --version &>/dev/null 2>&1; then python3 -m pip install "$pkg" --quiet && INSTALLED=1 fi if [[ $INSTALLED -eq 0 ]] && command -v apt-get &>/dev/null; then APT_PKG="" case "$pkg" in pandas) APT_PKG="python3-pandas" ;; biopython) APT_PKG="python3-biopython" ;; esac if [[ -n "$APT_PKG" ]]; then sudo apt-get install -y "$APT_PKG" --quiet && INSTALLED=1 fi fi fi done ``` ### Technical Analysis The installer specifies package names but no exact versions or artifact hashes. Consequently, installation behavior depends on the package releases and repository state at execution time. Python packages can execute code during installation and can later execute arbitrary code when imported. If a configured package index, upstream account, release artifact, or dependency is compromised, the setup process may install malicious code. Unpinned versions also make the environment non-reproducible and allow future incompatible releases to alter behavior after the Skill has been reviewed. The script uses the active `pip3` or active Python environment instead of creating an isolated virtual environment. This can modify shared user or system environments and affect unrelated ...[truncated 940 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/species_analysis_workflow.py:68
Finding

Task Name Path Traversal Allows Writes Outside the Results Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/species_analysis_workflow.py:145
Finding

Untrusted Species Names Can Produce Spreadsheet Formula Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as performing end-to-end sequence analysis, but the finding indicates it instead batch-updates integrated reports from local CSV/JSON directory structures. In an agent setting, such undocumented local-data traversal and report synthesis are more dangerous than they appear because they expand file-system interaction and can expose or overwrite unrelated analysis artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is described as performing end-to-end sequence analysis, but the finding indicates it instead batch-updates integrated reports from local CSV/JSON directory structures. In an agent setting, such undocumented local-data traversal and report synthesis are more dangerous than they appear because they expand file-system interaction and can expose or overwrite unrelated analysis artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill is described as performing end-to-end sequence analysis, but the finding indicates it instead batch-updates integrated reports from local CSV/JSON directory structures. In an agent setting, such undocumented local-data traversal and report synthesis are more dangerous than they appear because they expand file-system interaction and can expose or overwrite unrelated analysis artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is described as performing end-to-end sequence analysis, but the finding indicates it instead batch-updates integrated reports from local CSV/JSON directory structures. In an agent setting, such undocumented local-data traversal and report synthesis are more dangerous than they appear because they expand file-system interaction and can expose or overwrite unrelated analysis artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script downloads an executable binary over plain HTTP and installs it into the user's local bin directory. Because HTTP lacks transport integrity/authentication, a man-in-the-middle or compromised network can replace the binary with malicious code that will later be executed by the user.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/setup.sh (reported line 111)May include surrounding context.

sh
fail "未找到适配 ${ARCH} 的预编译包,请手动安装 clustalo"
                echo "    参考:http://www.clustal.org/omega/"
                exit 1
            fi

            curl -fsSL "$URL" -o "$INSTALL_DIR/clustalo"
            chmod +x "$INSTALL_DIR/clustalo"

            # 确保在PATH中
            if ! echo "$PATH" | grep -q "$INSTALL_DIR"; then
                echo "export PATH=\"\$HOME/.local/bin:\$PATH\"" >> "$HOME/.bashrc"
                export PATH="$HOME/.local/bin:$PATH"
            fi
            ok "clustalo 下载完成 → ${INSTALL_DIR}/clustalo"
        fi

    elif [[ "$OS" == "Darwin" ]]; then
        if command -v brew &>/dev/null; then
            brew install clustal-omega && ok "clustalo 安装完成(brew)"
        elif command -v conda &>/dev/null; then
            conda install -y -c bioconda clustalo && ok "clustalo 安装完成(conda)"
        else
            fail "未找到 brew 或 conda,请手动安装 clustal-om

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs users to run shell commands and scripts that can install packages, write files, and invoke external tools, yet it declares no explicit permissions or allowed-tools scope. This increases the risk of over-broad execution in an agent environment, where the skill may gain more file-system or shell capability than reviewers expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the entire user-facing documentation are written only in Chinese, with no indication that other languages are supported or that the user can choose a preferred language. Under the stated policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is entirely presented in Chinese and explicitly states the scheme is 'strictly fixed, must not be modified.' Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation, and no alternative language option or opt-in is provided here.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/method.md (reported line 14)May include surrounding context.

ClustalOmega 安装:

bash
# Linux (apt)
sudo apt-get install clustalo

# macOS (Homebrew)
brew install clustal-omega

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a code file, so natural-language policy checks apply to its docstrings and user-facing strings. The script presents usage instructions and operational output only in Chinese, which can constitute a language/locale policy violation when no user opt-in or documented regional limitation is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script extends a bioinformatics-style amino-acid pair analysis skill into generating monomer formulation tables for laboratory reagent preparation, which is materially outside the stated scope. That scope drift is dangerous because it enables downstream wet-lab synthesis guidance from analysis outputs without clear authorization, review, or safety controls, increasing the chance of misuse or unintended operationalization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code programmatically generates DOCX reagent preparation instructions with per-species monomer amounts, initiator mass, and DMSO fill volumes, effectively turning computational outputs into actionable experimental recipes. In the context of a skill described as protein sequence pair-frequency/φ analysis, this increases dual-use risk and can facilitate unreviewed chemical preparation workflows that were not clearly justified by the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains the module docstring, usage text, and generated report content entirely in Chinese, which effectively forces a specific language for users. Under the policy, locale constraints should either be optional via user choice or clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing docstring, log messages, and console output are written in Chinese throughout, which imposes a specific language on users. There is no indication of language selection, opt-in, or a documented reason that the tool is intended only for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code persistently writes checkpoint data and later also creates FASTA, JSON, CSV, and log files under a workspace directory. Although some runtime logs mention paths after execution starts, there is no confirmation prompt and the top-level docstring does not warn users that the script will create and modify files on disk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L128 的注释明确写着“保存共识序列到文件(含X)”,但该循环写出的 seq 来自 L118 清洗后的 cleaned,已删除所有非 CDEFHIKLMNQRSTVWY 字符,因此不仅不含 X,也不含 A/G/P。这里属于代码内文档对实际输出内容的直接错误描述,可能误导使用者理解输出数据含义。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup script goes beyond local dependency checking and performs package installation via pip, apt, conda, and shell-environment modification. While common for convenience installers, this expands trust and attack surface significantly for a skill whose purpose is sequence analysis, because running it can alter the host system and pull code from external repositories.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script invokes sudo to install packages system-wide. Elevating privileges inside a convenience setup script increases the blast radius of mistakes or compromised package sources and is broader access than necessary for most analysis workflows.

Content

Scanner excerpt · scripts/setup.sh (reported line 59)May include surrounding context.

sh
biopython) APT_PKG="python3-biopython" ;;
            esac
            if [[ -n "$APT_PKG" ]]; then
                sudo apt-get install -y "$APT_PKG" --quiet && INSTALLED=1
            fi
        fi
        if [[ $INSTALLED -eq 1 ]]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
86% confidence
Finding

This sudo apt-get installation similarly introduces privileged system modification during setup. In the context of a research analysis skill, automatic root-level package changes are unnecessary for many users and magnify supply-chain or operator-error risks.

Content

Scanner excerpt · scripts/setup.sh (reported line 87)May include surrounding context.

sh
if [[ "$OS" == "Linux" ]]; then
        # 尝试包管理器
        if command -v apt-get &>/dev/null; then
            sudo apt-get install -y clustalo 2>/dev/null && ok "clustalo 安装完成(apt)" && CLUSTALO_DONE=1
        elif command -v conda &>/dev/null; then
            conda install -y -c bioconda clustalo 2>/dev/null && ok "clustalo 安装完成(conda)" && CLUSTALO_DONE=1
        fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs remote retrieval of a binary and immediately makes it executable, without a strong warning, provenance verification, or integrity check. This normalizes unsafe supply-chain behavior and increases the chance users will execute untrusted code obtained at setup time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script appends a PATH export to ~/.bashrc without prompting the user. Silent shell-profile modification creates persistence for newly installed binaries and can affect future shells in ways the user did not consent to, especially if combined with downloaded executables.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.