Back to skill

Security audit

BrainASLab

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent brain-analysis purpose, but its MATLAB invocation is unsafe because crafted input paths could execute unintended MATLAB or system commands.

Review before installing. This skill should only be used with trusted, ordinary FreeSurfer stats file paths until it is fixed to escape or avoid MATLAB source interpolation, validate inputs, and handle MATLAB failures explicitly. Its file outputs are expected, but the current path handling is the main risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
skill.py:8
Finding

MATLAB Code Injection Through Unescaped Input Paths

Content
View full analysis

Vulnerability Details

File Location: skill.py, lines 8–15
Vulnerability Type: MATLAB code injection caused by unsafe string interpolation
Risk Level: High

Vulnerable Code

python
matlab_script = f"""
addpath('matlab');
brain_as_analysis('{lh_path}', '{rh_path}', '{out_dir}');
exit;
"""

subprocess.run([
    "matlab", "-batch", matlab_script
])

Technical Analysis

The caller-controlled lh_path and rh_path values are interpolated directly into executable MATLAB source as single-quoted string literals. Neither value is validated nor escaped before the generated source is passed to MATLAB through its -batch option.

Although subprocess.run uses an argument list and therefore avoids command interpretation by a system shell at the Python layer, it does not protect against injection into the MATLAB language itself. An attacker can place a single quote in either path to terminate the intended MATLAB string and append arbitrary MATLAB statements. MATLAB provides functions capable of executing operating-system commands, so successful MATLAB code injection can become arbitrary command execution under the account running the skill.

Attack Path

  1. An attacker supplies a crafted value for lh_path or rh_path.
  2. The crafted path contains a single quote that closes the surrounding MATLAB string literal.
  3. The remaining characters introduce attacker-selected MATLAB statements and neutralize or accommodate the original trailing syntax.
  4. Python constructs matlab_script containing the injected statements.
  5. subprocess.run launches matlab -batch with that script.
  6. MATLAB evaluates the injected code with the privileges of the skill process.
  7. The injected MATLAB code can invoke operating-system commands or access files available to that process.

Impact Assessment

Successful exploitation permits arbitrary MATLAB code execution and potentially arbitrary operating ...[truncated 591 chars]

Remediation
View remediation

Remediation Suggestions

  1. Avoid generating MATLAB source code from caller-controlled values. Transfer file paths through a non-code parameter mechanism, such as environment variables that MATLAB reads with getenv, or a securely created data/configuration file.
  2. If source interpolation cannot be eliminated, encode MATLAB string literals correctly by replacing every single quote with two single quotes. Also reject null bytes, line breaks, and other unexpected control characters. Escaping should be treated as defense in depth rather than the primary control.
  3. Resolve both inputs to canonical absolute paths and verify that each points to an expected regular file within an explicitly approved upload directory.
  4. Enforce the expected FreeSurfer filenames or extensions and reject inputs containing unsupported characters or path traversal components.
  5. Generate the output directory beneath a fixed, trusted base directory and use absolute paths when invoking MATLAB.
  6. Run MATLAB using a dedicated, minimally privileged account with narrowly scoped filesystem access and restricted network access.
  7. Invoke subprocess.run(..., check=True) and handle failures explicitly so unsuccessful or malformed analysis runs are not reported as valid results.
  8. Add security tests using paths containing quotes, semicolons, line breaks, traversal sequences, and other MATLAB metacharacters to verify that they are rejected or passed only as inert data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function creates a new output directory and later produces result files in that location, which affects the user's filesystem. The code provides no visible warning, log message, or inline documentation informing the user that files will be created under the output directory.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The code launches MATLAB with a dynamically constructed script that directly interpolates lh_path and rh_path into MATLAB source code. If either path contains quotes or MATLAB statement separators, an attacker may inject arbitrary MATLAB commands, leading to code execution in the MATLAB subprocess with the privileges of the running agent.

Content

Scanner excerpt · skill.py (reported line 15)May include surrounding context.

python
exit;
    """

    subprocess.run([
        "matlab", "-batch", matlab_script
    ])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The function invokes an external MATLAB process via subprocess.run, which is a safety-relevant operation for code files. There is no confirmation prompt, logging/print statement, or explanatory comment/docstring in this file disclosing that external code will be executed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.