Back to skill

Security audit

Bring! Shopping Lists

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Bring! shopping-list helper, but users should understand it uses account credentials, a live external API, and unpinned Python dependencies.

Install only if you are comfortable giving the agent access to your Bring! email/password and shopping-list contents. Prefer storing credentials outside project files, use a dedicated Bring password that is not reused elsewhere, and consider pinning or locking the Python dependencies before regular use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Can Access Bring Account Credentials

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Related Locations: bring.py:8-18, SKILL.md:37-45, README.md:52-69
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code

requirements.txt:1-2:

text
bring-api
python-dotenv

bring.py:8-18:

python
import aiohttp
from bring_api import Bring
from dotenv import load_dotenv

load_dotenv()

EMAIL = os.environ["BRING_EMAIL"]
PASSWORD = os.environ["BRING_PASSWORD"]


async def get_bring():
    session = aiohttp.ClientSession()
    bring = Bring(session, EMAIL, PASSWORD)
    await bring.login()
    return bring, session

SKILL.md:37-38:

bash
uv run --with bring-api --with python-dotenv python bring.py list --json
uv run --with bring-api --with python-dotenv python bring.py add "Milk" "Eggs" "Butter:Irish"

SKILL.md:45:

bash
pip install -r requirements.txt

Technical Analysis

Both documented installation methods resolve mutable package versions without version constraints, integrity hashes, or a committed lock file. The project documentation also identifies bring-api as an unofficial API client.

Imported Python dependencies execute inside the skill process. They can inspect its environment, and the bring-api client is explicitly passed BRING_EMAIL and BRING_PASSWORD. Consequently, a compromised package release, package-account takeover, malicious transitive dependency, or unsafe dependency resolution could introduce arbitrary code with direct access to the credentials and all local resources available to the skill process.

This finding does not establish that the current dependencies are malicious. The vulnerability is the absence of controls that ensure future installations retrieve the same reviewed artifacts.

Attack Path

  1. An attacker compromises the publishing account, release process, or ...[truncated 1466 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to an explicitly reviewed version rather than accepting any available release.
  2. Generate and commit a lock file that records all transitive dependencies.
  3. Require cryptographic hashes for downloaded artifacts where the package-management workflow supports them.
  4. Configure installation to use a trusted package index and disable unexpected fallback indexes to reduce dependency-confusion risk.
  5. Audit direct and transitive dependencies with established software-composition-analysis tooling before releases and periodically afterward.
  6. Prefer an official, maintained Bring client if one becomes available; otherwise, review changes to the unofficial client before updating it.
  7. Execute the skill in a constrained environment containing only the credentials and filesystem access it requires.
  8. Avoid reusing the Bring password for any other service and rotate it immediately if dependency compromise is suspected.
  9. Ensure both the uv and pip instructions consume the same locked, integrity-verified dependency set.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README instructs users to provide Bring! credentials and describes remote API operations, but it does not clearly warn that credentials and shopping-list contents will be transmitted to an external third-party service. In a skill that is auto-invoked by an agent, this omission increases the chance that users will unknowingly authorize network access and account actions with sensitive credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the agent will 'automatically use this skill' for broad shopping- or grocery-related requests, which creates a real risk of unintended invocation. In an agent setting, overly broad routing can cause the skill to access or modify a live Bring! account when the user was only speaking generally about groceries, leading to unauthorized external actions or data exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requires sensitive environment variables and performs networked actions, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a mismatch between documented behavior and enforceable execution boundaries, increasing the chance the agent can access secrets or make external requests without clear policy restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation description is broad enough to trigger on many general shopping or grocery-related requests, which can cause over-invocation of a skill that uses account credentials and performs external state-changing actions. In context, this raises the risk of unintended list modifications or unnecessary credential-backed network access when the user may only be asking for advice or discussion.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'bring-api' is unpinned, so installs may resolve to different versions over time, including versions with undiscovered or newly introduced security flaws. This weakens build reproducibility and supply-chain control, which is a real but generally low-severity security issue in a simple requirements manifest.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
bring-api
python-dotenv

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'python-dotenv' is unpinned, which allows environment-dependent or time-dependent resolution to different package versions. Because this package is used for environment file handling and has advisories in some releases, leaving it unpinned increases exposure to vulnerable or unsafe versions and reduces reproducibility.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
bring-api
python-dotenv

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The manifest includes 'python-dotenv' without a version pin, while advisories exist for some releases. That means the deployment could install an affected version, potentially exposing the skill to file overwrite or unsafe environment-loading behaviors if the package's vulnerable functionality is used elsewhere in the project.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.