Back to skill

Security audit

Score Analysis Publish

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local student score reporting helper with no evidence of hidden network access, persistence, or malicious behavior, but it needs careful handling of student data.

Install in a virtual environment, prefer pinned dependencies, and treat uploaded score files and generated reports as sensitive student records. Minimize names or IDs where possible, share outputs only with authorized recipients, and delete generated files when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:144
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:144
Additional Locations: README.md:35, README_CN.md:33, CONTRIBUTING.md:52
Vulnerability Type: Unpinned third-party dependencies and missing integrity verification
Risk Level: Medium

Vulnerable code:

bash
pip install python-docx matplotlib pandas numpy openpyxl

Technical Analysis

The documented installation command installs multiple third-party packages without fixed versions or cryptographic hashes. Consequently, package resolution depends on mutable releases available through the user's configured Python package index at installation time.

If a named package, one of its transitive dependencies, or the configured package index is compromised, users may install attacker-controlled code. Malicious Python packages can execute code during installation or when imported by the report-generation scripts. The project processes student assessment information, so compromise could expose sensitive educational data available to the running process.

This finding is limited to dependency integrity and reproducibility. The audited project scripts themselves contain no confirmed malicious payload, remote code retrieval, shell execution, credential access, or persistence behavior.

Attack Path

  1. An attacker compromises a listed package, a transitive dependency, or a package source configured in the victim's environment.
  2. The attacker publishes a malicious release that satisfies the unconstrained dependency request.
  3. A user follows the documented pip install command.
  4. pip resolves and installs the malicious or compromised release because no approved version or hash is enforced.
  5. Attacker-controlled code executes during package installation or when the dependency is imported by a project script.
  6. The payload operates with the privileges of the user running pip or the report-generation process and may access student data and files available to that account.

...[truncated 694 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create a dependency lock file containing reviewed, exact versions for every direct and transitive dependency.
  2. Generate and record cryptographic hashes for all approved distributions.
  3. Require hash verification during installation, for example:
bash
python -m pip install --require-hashes -r requirements.txt
  1. Use compatible-release constraints only in source dependency declarations; deploy from a fully resolved lock file.
  2. Install dependencies inside a dedicated virtual environment under a non-privileged account.
  3. Explicitly configure a trusted package index and avoid unreviewed mirrors or fallback indexes.
  4. Add automated dependency vulnerability and provenance scanning to continuous integration.
  5. Regularly review and deliberately update locked versions rather than resolving the latest releases at each installation.
  6. Update all affected documentation locations so they consistently direct users to the verified lock file.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个成绩分析与可视化报告技能,核心应包括读取/处理考试成绩数据、生成统计结果与图表、并进行纵向和横向对比。但提供的代码片段只是在本地创建一个带占位符的 .docx 模板文件,包括页边距、页眉页脚、封面和固定章节标题。它没有输入成绩数据、没有计算统计指标、没有生成图表、没有进行任何比较分析。因此其实际行为与声明的主要用途存在明显且实质性的偏差。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个较完整的班级成绩分析工具,包含成绩分析、可视化图表、分析报告,以及纵向/横向对比能力。实际代码只实现了可视化中的一个子功能:根据已提供的 analysis_data 生成三类学生的雷达图,并保存为图片。代码没有执行成绩分析逻辑、没有生成文字报告、没有实现历次考试对比,也没有实现班级间横向比较。因此声明明显高于实际行为,存在描述与代码能力不一致的情况。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

This file presents the skill entirely in Chinese and does not indicate that language is selectable or user-configurable. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless clearly justified or optional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes handling class exam scores and student-level analysis, but it provides no privacy, consent, retention, or access-control guidance for sensitive educational data. In a skill explicitly designed to process student performance records, this omission can lead operators to upload personally identifiable or regulated student data without safeguards, increasing risk of privacy violations and policy noncompliance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly handles student identifiers, names, class information, rankings, and generates multiple derived output files, but it provides no privacy warning, minimization guidance, or storage/retention safeguards. In an education context, this increases the risk of exposing personally identifiable student data through reports, charts, exported JSON, and shared presentation files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code explicitly configures Chinese font families globally, which imposes a specific locale/language presentation choice on all generated charts. There is no user option, parameter, or documentation here indicating that the Chinese font requirement is optional or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.