Back to skill

Security audit

Adaptyv

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent API documentation, but it under-emphasizes user confirmation around lab submissions, quote acceptance, invoice creation, and token revocation.

Review this skill before installing if agents may act autonomously. Keep quote acceptance, skip_draft, experiment submission, and token revocation behind explicit user approval, use scoped/attenuated tokens where possible, protect .env credentials, and pin or lock the SDK dependency in controlled environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party SDK Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 35
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
Install: `uv add adaptyv-sdk` (falls back to `uv pip install adaptyv-sdk` if no `pyproject.toml` exists)

Technical Analysis

The skill directs the agent to install adaptyv-sdk without an exact version constraint, integrity hash, lockfile requirement, or provenance-verification procedure. Consequently, package resolution may select a future release that was not available during this audit.

Python package installation can execute package-controlled build and installation logic. If the package distribution or publisher account is compromised, following this instruction could execute attacker-controlled code with the privileges of the user running the agent.

This finding represents supply-chain exposure rather than evidence that the current adaptyv-sdk package is malicious.

Attack Path

  1. An attacker compromises the package publisher account, distribution infrastructure, or a future release of adaptyv-sdk.
  2. The attacker publishes a malicious version under the expected package name.
  3. An agent follows the skill instruction and runs uv add adaptyv-sdk or uv pip install adaptyv-sdk.
  4. The package manager resolves and downloads the malicious release because no reviewed version or hash is required.
  5. Package-controlled build, installation, or runtime code executes in the agent's environment.
  6. The malicious code accesses resources available to that process, potentially including project files, environment variables, .env contents, and API credentials.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the installation. The accessible scope would be limited by that account's permissions, but could include:

  • Reading or modifying files available to the agent.
  • Reading environment variable ...[truncated 261 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin adaptyv-sdk to an exact version that has undergone review, for example:
    bash
    uv add 'adaptyv-sdk==X.Y.Z'
    
  2. Commit and enforce a dependency lockfile so installations resolve to reviewed artifacts.
  3. Require cryptographic hash verification where supported.
  4. Verify the package publisher, registry origin, release signatures or attestations, and artifact provenance before installation.
  5. Perform dependency installation in an isolated, least-privilege virtual environment or container.
  6. Prevent installation processes from receiving production API credentials unless they are strictly required.
  7. Use automated dependency scanning and controlled update review before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The automated pipeline example enables skip_draft and auto_accept_quote without prominently warning that this can commit submissions and accept charges without an explicit human review step. In a cloud lab context, that can lead to unintended experiment execution, financial cost, and irreversible processing of proprietary biological sequences if copied into automation blindly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation text says to use this skill whenever the user mentions broad terms like "Adaptyv" or assay types, which could match casual discussion rather than an actual request to use the API or SDK. It does not provide exclusion conditions or narrower trigger constraints, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The request field documentation notes that auto_accept_quote will auto-accept a quote and create an invoice. Because this can trigger billing-related actions automatically, the markdown should clearly warn users about the financial and workflow implications rather than only describing the parameter behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The endpoint documentation says accepting a quote creates a draft invoice and transitions the experiment to a new state, and a similar operation appears again for quote-based confirmation. These are consequential actions affecting billing and workflow state, but the markdown does not provide a cautionary warning to users about those effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file documents a revocation operation that revokes a root token and all attenuated descendants, which can disrupt all dependent access. The description states the behavior but does not include any explicit warning or caution about the irreversible operational impact, which is relevant for user data and system access integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.