Back to skill

Security audit

Mlfinlab

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local plain-text reference helper with minor documentation quality issues but no credential access, network behavior, persistence, or destructive actions.

This appears safe to install from a security standpoint, but expect generic reference output and a couple of small documentation inconsistencies rather than authoritative mlfinlab-specific guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Credential Access

High
Category
Privilege Escalation
Content
## Prerequisites
- Basic understanding of devtools concepts
- Required tools and access credentials
- System meeting minimum requirements

## Installation
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Intent-Code Divergence

Low
Confidence
98% confidence
Finding
The help output says `mlfinlab v$VERSION`, which implies it will show the actual version. Because the here-document delimiter is single-quoted (`<< 'HELPEOF'`), shell expansion is disabled and users will see the literal text `$VERSION` instead of `2.0.1`, contradicting the apparent documentation intent.

Intent-Code Divergence

Low
Confidence
99% confidence
Finding
The cheatsheet presents `troubleshooting` as an available command, but the dispatcher only implements `debugging`, not `troubleshooting`. This is an active mismatch between embedded documentation and actual behavior, and users following the cheatsheet would get an unknown-command error.

Static analysis

No suspicious patterns detected.