Back to skill

Security audit

Data Analysis

Security checks for vulnerabilities and agentic risk

Overview

This CSV analysis skill is mostly coherent, but it needs review because it can automatically install Python packages and generate reports that load third-party scripts.

Install only if you are comfortable with the agent modifying its Python environment and with generated HTML reports contacting external CDNs. Prefer using an isolated environment, preinstalling reviewed dependencies yourself, and choosing Markdown output for sensitive data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:698
Finding

Automatic Installation of Unpinned Third-Party Python Packages

Content
View full analysis
` against the host's configured package index. 4. The resolver selects an unpinned package version and its transitive dependencies. 5. A compromised distribution, dependency, or package source supplies attacker-controlled code. 6. That code runs during an applicable build or in ...[truncated 692 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:509
Finding

Generated HTML Reports Retrieve and Execute Remote JavaScript

Content
View full analysis
``` ### Technical Analysis The interactive report template loads executable JavaScript from external CDNs whenever a generated report is opened. The Tailwind URL is not version-pinned, and neither script includes Subresource Integrity metadata. As a result, the code that executes is not fully represented by the audited project and can change after report generation. Although the Chart.js URL specifies a version, it still relies on the CDN and network delivery path without an integrity hash. Compromise of an upstream publisher, CDN account, CDN infrastructure, or relevant delivery path could substitute malicious JavaScript. The browser would execute the substituted content in the generated report's origin and page context. ### Attack Path 1. The Agent generates an interactive HTML report using the documented template. 2. A user opens the report while network access is available. 3. The browser requests Chart.js and Tailwind JavaScript from the external CDN endpoints. 4. An upstream or CDN compromise causes one of the endpoints to return attacker-controlled JavaScript. 5. Because no integrity hash is present, the browser accepts and executes the substituted response. 6. The malicious script reads report content available in the DOM, changes displayed findings, and may transmit accessible report data through outbound network requests. ### Impact Assessment A successful attack could compromise the confidentiality and integrity of information embedded in the HTML report. Attacker-controlled JavaScript could inspect displayed metrics and analysis results, falsify charts or recommendations, capture u ...[truncated 287 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill omits any up-front warning that it may install packages automatically, preventing informed user consent for a significant change in capability. Because the skill is framed as standard CSV analysis, users may invoke it expecting read/analyze behavior while it actually performs environment modification and potentially reaches external package sources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says to use this skill whenever the user mentions broad phrases like 'analyzing data', 'data insights', or asks 'what does this data tell us?', which are common requests that could match many unrelated analysis contexts. It does not provide exclusions or tighter scope beyond CSV mentions, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to automatically install Python packages with pip when imports fail, which modifies the host environment and executes external package-management commands without explicit user consent. In this context, that expands a simple CSV-analysis skill into one with environment-changing and supply-chain exposure, especially if package indexes, mirrors, or dependency resolution are untrusted or manipulated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The HTML report template pulls JavaScript and CSS from third-party CDNs at runtime, creating external network dependencies not obvious from a local CSV-analysis skill. If those assets are tampered with, unavailable, or replaced, opening the generated report could execute malicious script in the viewer's browser or leak metadata through outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated HTML template hard-codes lang="en", which imposes an English locale in output. The skill does not mention user language preference, opt-in, or any reason the output must be English-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.