T09 · Insecure Skill Coding Practices
- Location
SKILL.md:137- Finding
Arbitrary Python Code Execution Through Unsafe Query Substitution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent financial-research purpose, but its documented inline invocation can turn a crafted user question into locally executed Python code.
Review before installing. The safer path is the companion query.py script, invoked with the question as an argument, but the documented inline command should be fixed or avoided. Run only in a sandbox you are comfortable with, and remember that each research question is sent to the drillr.ai public API endpoint.
SKILL.md:137Arbitrary Python Code Execution Through Unsafe Query Substitution
query.py:90Denial of Service Through Unbounded SSE Streaming and Response Accumulation
The skill executes an inline Python script via a shell and performs outbound network access, but it declares no explicit tool scope or permissions metadata. That mismatch is dangerous because callers and policy systems cannot reliably constrain or review the skill’s actual capabilities, increasing the risk of unintended data egress or policy bypass if the skill is invoked in a broader agent environment.
No suspicious patterns detected.