Back to skill

Security audit

worldclim-extract

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward WorldClim data extraction helper, with expected local file processing and disclosed dataset downloads.

Install and run this in a virtual environment, expect it to download WorldClim ZIP files into a local cache on first use, and consider manually verifying downloaded data or pinning dependencies if using it in a sensitive workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–22
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
Before using code patterns, verify installed versions match. If versions differ:
- `pip show rasterio pandas openpyxl`

If code throws ImportError, install missing packages:
```bash
pip install rasterio pandas openpyxl
text

### Technical Analysis

The installation command retrieves `rasterio`, `pandas`, and `openpyxl` without exact version constraints, package hashes, or a reviewed lockfile. The documented compatibility ranges do not constrain the versions that `pip` ultimately installs.

Because Python package installation can execute package build and installation logic, the security of this instruction depends on mutable package-index content and the complete transitive dependency graph. A compromised package release, dependency takeover, or unsafe future version could therefore run code with the privileges of the user performing the installation.

No evidence indicates that the currently named packages are malicious. The risk arises from the unpinned and unverifiable dependency installation process.

### Attack Path

1. An attacker compromises a named package, one of its transitive dependencies, or its package-index release channel.
2. The attacker publishes a malicious version that still satisfies the unconstrained installation request.
3. A user follows the Skill instructions and runs `pip install rasterio pandas openpyxl`.
4. `pip` resolves the compromised release and executes its build or installation logic.
5. The malicious package gains code execution under the installing user's account and may subsequently execute again when imported by `extract_worldclim.py`.

### Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running `pip`. Depending on that user's permissions and environment, the attacker could acc
...[truncated 359 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a reviewed dependency manifest containing exact versions for all direct and transitive dependencies.
  2. Generate and verify cryptographic hashes for every permitted distribution.
  3. Install dependencies with hash enforcement, for example:
bash
python3 -m venv .venv
. .venv/bin/activate
python3 -m pip install --require-hashes -r requirements.txt
  1. Use a trusted package index explicitly and disable unexpected extra indexes where operationally appropriate.
  2. Periodically regenerate the lockfile through a controlled dependency-review process rather than allowing automatic upgrades.
  3. Run installation and execution as an unprivileged user in an isolated virtual environment or container.
  4. Add automated dependency vulnerability and integrity scanning to release checks.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents behaviors that read local files and perform network downloads, but its metadata does not declare an explicit tool/permission scope. This creates a transparency and policy-enforcement gap: an agent or user may invoke the skill without clear awareness that it can access local data and fetch remote content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The direct Python example uses Chinese headers and output column names such as 经度, 纬度, and 年均温度_C, and the requirements section presents these as defaults. This creates a language-specific default experience without explicit opt-in or a clear statement that alternative locales are equally supported.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

bash
# 10m resolution (~48 MB)
curl -O https://geodata.ucdavis.edu/climate/worldclim/2_1/base/wc2.1_10m_bio.zip
unzip wc2.1_10m_bio.zip -d ./worldclim_data/

# 2.5m resolution (~650 MB)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing description text in Chinese, and the command-line help and log output throughout the script are likewise Chinese-only. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that it auto-downloads data on first run into a local cache, but does not prominently warn that execution will contact an external server and write files locally. Hidden network and disk side effects can violate user expectations, leak usage metadata, and create supply-chain risk if remote content changes or is tampered with.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.