Back to skill

Security audit

Data Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward data-analysis guide with one dependency-installation caution, not evidence of malicious behavior.

Reasonable to install for local data exploration. Prefer using an isolated virtual environment and approved package sources before installing pandas or openpyxl, and only provide datasets you intend the agent to read and summarize.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–39
Vulnerability Type: Unpinned runtime dependencies
Risk Level: Medium

Vulnerable Code

markdown
**If Python is available** (recommended for large datasets):
```bash
pip install pandas openpyxl  # if missing
python3 -c "
import pandas as pd
df = pd.read_csv('data.csv')
print(df.info())
print(df.describe())
print(df.head())
"
text

### Technical Analysis

The skill recommends installing `pandas` and `openpyxl` directly from the package index without pinning versions, verifying package hashes, selecting a trusted index explicitly, or requiring an isolated environment. Consequently, the exact dependency artifacts executed can change after the skill has been reviewed.

Although the named packages are legitimate, an upstream compromise, malicious release, compromised package-index account, or package-source configuration attack could cause attacker-controlled package code to run during installation or import. The instruction also does not require explicit user approval before modifying the Python environment.

### Attack Path

1. An attacker compromises an upstream dependency release, package-maintainer account, configured package mirror, or package-resolution path.
2. The skill is invoked on a system where one or both dependencies are considered missing.
3. The runtime follows the documented `pip install pandas openpyxl` instruction.
4. `pip` resolves and installs an unreviewed package version from the configured index.
5. Malicious package behavior executes during installation or when `pandas` is imported by the subsequent command.
6. The payload operates with the privileges of the user or agent running the skill.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the invoking account. The resulting scope could include reading or modifying files accessible to that account, accessing e
...[truncated 367 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not install dependencies automatically as part of skill execution. Detect missing packages and request explicit user approval.
  2. Define dependencies in a reviewed lock file with exact versions and cryptographic hashes.
  3. Install with hash enforcement, such as:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Use a dedicated virtual environment or other isolated runtime rather than modifying the user or system Python environment.
  5. Configure an explicitly trusted package index or internal artifact repository.
  6. Review, scan, and periodically update locked packages through a controlled dependency-management process.
  7. Prefer already-provisioned dependencies and provide a standard-library fallback where practical.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
### Initial Inspection

After loading, always answer these questions:
- **Shape:** How many rows and columns?
- **Column names:** What are they and what data types?
- **Missing values:** Which columns have gaps, and how many?

Static analysis

No suspicious patterns detected.