Back to skill

Security audit

Aeon

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent documentation skill for using the Aeon time-series machine-learning toolkit, with expected package installation and benchmark dataset download guidance.

Install Aeon in an isolated virtual environment, pin a reviewed version or use a lockfile when reproducibility matters, and expect the dataset examples to contact external benchmark archives and store data locally. Review storage, bandwidth, and compute impact before running bulk downloads or deep-learning examples.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22-24
Vulnerability Type: Unpinned package installation from a mutable third-party registry
Risk Level: Low

Vulnerable Code

bash
uv pip install aeon

Technical Analysis

The installation instructions retrieve aeon without specifying a reviewed version or validating an integrity hash. Consequently, the package version installed depends on the state of the package registry at execution time. This makes installations non-reproducible and means that a release published after this Skill was audited may be installed without further review.

No evidence indicates that the named aeon package is malicious or that dependency confusion or typosquatting is currently occurring. The risk is conditional on a future upstream compromise, malicious release, registry compromise, or incompatible package update.

Attack Path

  1. An attacker compromises the upstream package publisher account, distribution infrastructure, or another component in the dependency chain.
  2. The attacker publishes a malicious release under the legitimate aeon package name.
  3. A user follows the Skill instructions and runs uv pip install aeon.
  4. The package resolver selects the malicious or compromised release because no approved version or hash is specified.
  5. Malicious package behavior executes during installation, import, or subsequent use with the privileges of the invoking user.

Impact Assessment

Exploitation could allow arbitrary code execution under the account that installs or imports the compromised package. Accessible resources could include files, environment variables, credentials, network services, and application data available to that account. Administrative privileges are not inherently obtained; broader impact would require the user to perform the installation with elevated privileges or the attacker to exploit a separate privilege-escalation weaknes ...[truncated 335 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin aeon to a specific, reviewed version:
    bash
    uv pip install "aeon==<reviewed-version>"
    
  2. Maintain a lockfile that records the complete resolved dependency graph.
  3. Require cryptographic hashes for downloaded distributions where the package-management workflow supports them.
  4. Periodically review and deliberately update the pinned version rather than automatically accepting the latest release.
  5. Install dependencies in an isolated virtual environment using a non-privileged account.
  6. Use a trusted internal mirror or an allowlisted package index for higher-assurance deployments.
  7. Add the expected package source, version, and integrity-verification procedure to the installation documentation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file includes examples that trigger downloads from external archives, which implies network access and likely local file writes for cached or downloaded datasets. The surrounding documentation does not warn users that running these commands may contact remote services and store data locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The text states that loading a dataset automatically downloads content from an external website, but it does not include a user-facing warning about the resulting network activity or local storage effects. For markdown files, externally fetching data should be clearly disclosed because it can affect privacy, bandwidth, and system state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.