Back to skill

Security audit

CRISPIR sgRNA Designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple CRISPR guide finder that overstates safety-critical design capabilities and may contact NCBI without enough user control.

Review before installing. Treat outputs as preliminary candidate guides only, not validated low-off-target or precise-edit designs. Use independent CRISPR/off-target tools and expert review before any experimental use, and avoid NCBI lookup for sensitive or proprietary targets unless you are comfortable sending the accession and coordinates to that external service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/design_sgrna.py:8
Finding

Unbounded External HTTP Request May Cause Resource Exhaustion

Content
View full analysis

Vulnerability Details

File Location: scripts/design_sgrna.py:8-14
Vulnerability Type: Unbounded external HTTP request
Risk Level: Low

Vulnerable Code

python
def fetch_ncbi_sequence(accession, start=None, end=None):
    print(f"Fetching sequence for {accession}...")
    url = f"https://eutils.ncbi.nlm.nih.gov/entrez/eutils/efetch.fcgi?db=nuccore&id={accession}&rettype=fasta&retmode=text"
    if start and end:
        url += f"&seq_start={start}&seq_stop={end}"
    
    response = requests.get(url)
    if response.status_code == 200:
        lines = response.text.split('\n')
        return "".join(lines[1:])
    return None

Technical Analysis

The NCBI request is made without connection or read timeouts. Consequently, a stalled endpoint or network connection can block the process indefinitely. The response is also loaded and decoded in full through response.text, split into another in-memory representation, and concatenated before downstream sequence processing. No maximum response or sequence length is enforced.

User-controlled accession and coordinate values are interpolated into the query string rather than supplied through the request library's parameter-encoding interface. Although the destination is fixed to the official NCBI HTTPS host and no arbitrary-host request was identified, explicit input validation and safe query encoding are still absent.

Attack Path

  1. An attacker or untrusted caller supplies an accession or coordinate range that causes retrieval of an excessively large sequence.
  2. The script sends the request to the fixed NCBI endpoint without a timeout.
  3. A slow response can hold the process indefinitely, while a large response is loaded fully into memory.
  4. The code creates additional copies during text decoding, line splitting, concatenation, reverse-complement generation, and candidate scanning.
  5. The process may experience excessive memory con ...[truncated 633 chars]
Remediation
View remediation

Remediation Suggestions

  • Apply explicit connection and read timeouts, for example timeout=(5, 30).
  • Pass query values through the params argument rather than manual string interpolation.
  • Validate accession identifiers against an allowlisted format and reject malformed or excessively long values.
  • Validate coordinates as positive integers, require start <= end, and impose a maximum permitted range.
  • Use streaming response handling and stop reading after a configured byte limit.
  • Enforce a maximum decoded sequence length before reverse-complement generation and PAM scanning.
  • Call response.raise_for_status() and handle requests.Timeout, requests.ConnectionError, and related exceptions explicitly.
  • Avoid unnecessary full-size intermediate copies where practical.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill markets itself as professional-grade and claims low-off-target design, donor-template mutation strategy, and Rule Set 2–style scoring, but the described behavior does not substantively implement those safety-critical capabilities. In a bio-design context, this mismatch is dangerous because users may rely on the tool for experimental design decisions under false assumptions, leading to poor guide selection, elevated off-target risk, failed edits, or unsafe downstream biological work.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly describes automatic retrieval of reference sequences via NCBI E-utils, which implies network access, but it does not declare any tool scope or allowed-tools constraints. This is dangerous because hidden or undeclared external access can surprise users, bypass least-privilege expectations, and enable unintended data exfiltration or unreviewed outbound requests during skill execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow states that the skill automatically pulls reference sequences from NCBI E-utils but provides no warning that external network access will occur. This is dangerous because users may unknowingly cause outbound requests involving sensitive target names, proprietary project context, or regulated research topics, reducing transparency and violating privacy or compliance expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata promises low-off-target sgRNA design and donor-template synonymous mutation strategy, but the implementation only performs PAM scanning plus a simplistic on-target heuristic. In a genome-editing context, this mismatch can mislead users into trusting recommendations that have not been screened for off-target risk, potentially causing unsafe experimental design and unintended edits.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises support for site-specific insertions/tagging and precise genome editing, but the code only emits generic sgRNA candidates without any edit-context-aware logic such as cut-to-edit distance, strand/orientation constraints, donor compatibility, or repair-design checks. In this biological design setting, that overclaim can cause users to select guides unsuitable for the intended edit, leading to failed experiments or unintended editing outcomes.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says to use the skill whenever the user is 'needing to design high-efficiency, low-off-target sgRNAs' for several broad editing tasks, but it does not define specific invocation phrases, boundaries, or exclusion conditions. In a manifest file, this kind of open-ended activation wording can overlap with many general biology-editing requests and may cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends the user-supplied accession and optional coordinate parameters to an external NCBI HTTP endpoint via requests.get. Although there is a simple print indicating that a fetch is happening, it does not disclose that data is being transmitted to a third-party service or describe the privacy/network implication.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.