422 KiB
Security Scan Report
Generated: 2026-04-11 13:08 UTC
Skills scanned: 135
Total findings: 746
Critical: 32 | High: 37 | Safe skills: 109/135
Summary
| Skill | Severity | Findings | Safe | Duration |
|---|---|---|---|---|
| citation-management | 🔴 CRITICAL | 10 | ❌ | 28.2s |
| consciousness-council | 🔴 CRITICAL | 5 | ❌ | 40.7s |
| dhdna-profiler | 🔴 CRITICAL | 5 | ❌ | 37.1s |
| infographics | 🔴 CRITICAL | 10 | ❌ | 31.3s |
| research-lookup | 🔴 CRITICAL | 13 | ❌ | 39.8s |
| scientific-critical-thinking | 🔴 CRITICAL | 5 | ❌ | 34.4s |
| scientific-schematics | 🔴 CRITICAL | 10 | ❌ | 26.9s |
| scientific-slides | 🔴 CRITICAL | 14 | ❌ | 66.1s |
| scientific-writing | 🔴 CRITICAL | 6 | ❌ | 41.6s |
| scikit-bio | 🔴 CRITICAL | 5 | ❌ | 31.7s |
| seaborn | 🔴 CRITICAL | 5 | ❌ | 36.2s |
| shap | 🔴 CRITICAL | 5 | ❌ | 30.6s |
| timesfm-forecasting | 🔴 CRITICAL | 5 | ❌ | 34.1s |
| clinical-decision-support | 🟠 HIGH | 6 | ❌ | 54.3s |
| dnanexus-integration | 🟠 HIGH | 6 | ❌ | 44.1s |
| esm | 🟠 HIGH | 5 | ❌ | 24.1s |
| geomaster | 🟠 HIGH | 9 | ❌ | 36.4s |
| modal | 🟠 HIGH | 9 | ❌ | 30.1s |
| pathml | 🟠 HIGH | 7 | ❌ | 21.6s |
| polars | 🟠 HIGH | 5 | ❌ | 23.1s |
| pytorch-lightning | 🟠 HIGH | 4 | ❌ | 20.6s |
| qutip | 🟠 HIGH | 5 | ❌ | 21.4s |
| sympy | 🟠 HIGH | 4 | ❌ | 23.4s |
| torch-geometric | 🟠 HIGH | 7 | ❌ | 26.9s |
| torchdrug | 🟠 HIGH | 5 | ❌ | 25.3s |
| transformers | 🟠 HIGH | 4 | ❌ | 18.9s |
| bgpt-paper-search | 🟡 MEDIUM | 4 | ✅ | 23.2s |
| clinical-reports | 🟡 MEDIUM | 4 | ✅ | 40.9s |
| database-lookup | 🟡 MEDIUM | 5 | ✅ | 40.0s |
| datamol | 🟡 MEDIUM | 5 | ✅ | 26.8s |
| deepchem | 🟡 MEDIUM | 4 | ✅ | 26.0s |
| depmap | 🟡 MEDIUM | 4 | ✅ | 25.1s |
| docx | 🟡 MEDIUM | 5 | ✅ | 43.1s |
| fluidsim | 🟡 MEDIUM | 4 | ✅ | 24.7s |
| ginkgo-cloud-lab | 🟡 MEDIUM | 4 | ✅ | 19.6s |
| histolab | 🟡 MEDIUM | 4 | ✅ | 25.0s |
| imaging-data-commons | 🟡 MEDIUM | 4 | ✅ | 19.9s |
| labarchive-integration | 🟡 MEDIUM | 8 | ✅ | 31.0s |
| markitdown | 🟡 MEDIUM | 5 | ✅ | 31.7s |
| open-notebook | 🟡 MEDIUM | 19 | ✅ | 23.9s |
| parallel-web | 🟡 MEDIUM | 4 | ✅ | 20.0s |
| peer-review | 🟡 MEDIUM | 5 | ✅ | 29.3s |
| perplexity-search | 🟡 MEDIUM | 6 | ✅ | 24.6s |
| phylogenetics | 🟡 MEDIUM | 8 | ✅ | 23.1s |
| primekg | 🟡 MEDIUM | 5 | ✅ | 27.1s |
| protocolsio-integration | 🟡 MEDIUM | 6 | ✅ | 23.8s |
| pymatgen | 🟡 MEDIUM | 5 | ✅ | 25.7s |
| research-grants | 🟡 MEDIUM | 4 | ✅ | 33.8s |
| rowan | 🟡 MEDIUM | 6 | ✅ | 33.4s |
| scholar-evaluation | 🟡 MEDIUM | 4 | ✅ | 31.3s |
| scientific-brainstorming | 🟡 MEDIUM | 3 | ✅ | 21.4s |
| adaptyv | 🔵 LOW | 3 | ✅ | 16.8s |
| aeon | 🔵 LOW | 3 | ✅ | 14.7s |
| anndata | 🔵 LOW | 4 | ✅ | 22.1s |
| arboreto | 🔵 LOW | 3 | ✅ | 15.9s |
| astropy | 🔵 LOW | 4 | ✅ | 21.9s |
| benchling-integration | 🔵 LOW | 4 | ✅ | 18.2s |
| biopython | 🔵 LOW | 5 | ✅ | 26.5s |
| cellxgene-census | 🔵 LOW | 3 | ✅ | 17.9s |
| cirq | 🔵 LOW | 2 | ✅ | 14.3s |
| cobrapy | 🔵 LOW | 1 | ✅ | 11.4s |
| dask | 🔵 LOW | 3 | ✅ | 20.7s |
| diffdock | 🔵 LOW | 2 | ✅ | 15.7s |
| etetoolkit | 🔵 LOW | 3 | ✅ | 23.8s |
| exploratory-data-analysis | 🔵 LOW | 4 | ✅ | 33.5s |
| flowio | 🔵 LOW | 3 | ✅ | 18.6s |
| generate-image | 🔵 LOW | 3 | ✅ | 19.8s |
| geniml | 🔵 LOW | 4 | ✅ | 22.0s |
| geopandas | 🔵 LOW | 5 | ✅ | 29.1s |
| get-available-resources | 🔵 LOW | 4 | ✅ | 28.3s |
| gget | 🔵 LOW | 4 | ✅ | 24.6s |
| glycoengineering | 🔵 LOW | 3 | ✅ | 20.0s |
| gtars | 🔵 LOW | 4 | ✅ | 23.1s |
| hypogenic | 🔵 LOW | 5 | ✅ | 33.4s |
| hypothesis-generation | 🔵 LOW | 4 | ✅ | 36.7s |
| lamindb | 🔵 LOW | 4 | ✅ | 25.4s |
| latchbio-integration | 🔵 LOW | 3 | ✅ | 19.2s |
| latex-posters | 🔵 LOW | 4 | ✅ | 20.9s |
| literature-review | 🔵 LOW | 5 | ✅ | 31.4s |
| markdown-mermaid-writing | 🔵 LOW | 1 | ✅ | 14.0s |
| market-research-reports | 🔵 LOW | 5 | ✅ | 30.6s |
| matchms | 🔵 LOW | 2 | ✅ | 15.4s |
| matlab | 🔵 LOW | 4 | ✅ | 29.7s |
| medchem | 🔵 LOW | 1 | ✅ | 14.6s |
| molecular-dynamics | 🔵 LOW | 3 | ✅ | 17.1s |
| molfeat | 🔵 LOW | 3 | ✅ | 19.2s |
| networkx | 🔵 LOW | 3 | ✅ | 23.6s |
| neurokit2 | 🔵 LOW | 4 | ✅ | 25.1s |
| neuropixels-analysis | 🔵 LOW | 4 | ✅ | 31.1s |
| omero-integration | 🔵 LOW | 4 | ✅ | 24.8s |
| opentrons-integration | 🔵 LOW | 4 | ✅ | 20.0s |
| optimize-for-gpu | 🔵 LOW | 4 | ✅ | 28.4s |
| paper-lookup | 🔵 LOW | 4 | ✅ | 33.8s |
| paperzilla | 🔵 LOW | 3 | ✅ | 19.0s |
| 🔵 LOW | 4 | ✅ | 27.0s | |
| pennylane | 🔵 LOW | 4 | ✅ | 28.9s |
| polars-bio | 🔵 LOW | 3 | ✅ | 20.1s |
| pptx | 🔵 LOW | 4 | ✅ | 34.9s |
| pptx-posters | 🔵 LOW | 4 | ✅ | 26.7s |
| pufferlib | 🔵 LOW | 3 | ✅ | 20.2s |
| pydeseq2 | 🔵 LOW | 3 | ✅ | 20.9s |
| pydicom | 🔵 LOW | 4 | ✅ | 26.5s |
| pyhealth | 🔵 LOW | 4 | ✅ | 31.6s |
| pylabrobot | 🔵 LOW | 4 | ✅ | 25.5s |
| pymc | 🔵 LOW | 4 | ✅ | 29.6s |
| pymoo | 🔵 LOW | 2 | ✅ | 16.5s |
| pyopenms | 🔵 LOW | 3 | ✅ | 18.5s |
| pysam | 🔵 LOW | 2 | ✅ | 13.9s |
| pytdc | 🔵 LOW | 4 | ✅ | 29.9s |
| pyzotero | 🔵 LOW | 4 | ✅ | 24.1s |
| qiskit | 🔵 LOW | 4 | ✅ | 23.3s |
| rdkit | 🔵 LOW | 3 | ✅ | 20.3s |
| scanpy | 🔵 LOW | 2 | ✅ | 13.3s |
| scientific-visualization | 🔵 LOW | 2 | ✅ | 14.4s |
| scikit-learn | 🔵 LOW | 3 | ✅ | 18.2s |
| scikit-survival | 🔵 LOW | 1 | ✅ | 12.9s |
| scvelo | 🔵 LOW | 3 | ✅ | 20.6s |
| simpy | 🔵 LOW | 2 | ✅ | 15.2s |
| statsmodels | 🔵 LOW | 3 | ✅ | 19.8s |
| tiledbvcf | 🔵 LOW | 3 | ✅ | 18.3s |
| treatment-plans | 🔵 LOW | 4 | ✅ | 24.6s |
| umap-learn | 🔵 LOW | 4 | ✅ | 23.9s |
| usfiscaldata | 🔵 LOW | 3 | ✅ | 20.0s |
| vaex | 🔵 LOW | 4 | ✅ | 23.7s |
| venue-templates | 🔵 LOW | 4 | ✅ | 30.4s |
| what-if-oracle | 🔵 LOW | 3 | ✅ | 25.6s |
| xlsx | 🔵 LOW | 4 | ✅ | 33.1s |
| zarr-python | 🔵 LOW | 3 | ✅ | 18.8s |
| bioservices | 🟢 SAFE | 0 | ✅ | 16.5s |
| deeptools | 🟢 SAFE | 0 | ✅ | 3.9s |
| iso-13485-certification | 🟢 SAFE | 0 | ✅ | 10.9s |
| matplotlib | 🟢 SAFE | 0 | ✅ | 7.6s |
| scvi-tools | 🟢 SAFE | 0 | ✅ | 8.2s |
| stable-baselines3 | 🟢 SAFE | 0 | ✅ | 10.0s |
| statistical-analysis | 🟢 SAFE | 0 | ✅ | 10.4s |
Detailed Findings
citation-management — 🔴 CRITICAL
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION— Cross-file env var exfiltration: 4 filesEnvironment variable access with network calls in scripts/extract_metadata.py, scripts/search_pubmed.py Remediation: Review data flow across files: scripts/doi_to_bibtex.py, scripts/extract_metadata.py, scripts/validate_citations.py, scripts/search_pubmed.py
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN— Cross-file exfiltration chain: 4 filesMulti-file exfiltration chain detected: scripts/extract_metadata.py, scripts/search_pubmed.py collect data → encode → scripts/doi_to_bibtex.py, scripts/extract_metadata.py, scripts/validate_citations.py, scripts/search_pubmed.py transmit to network Remediation: Review data flow across files: scripts/doi_to_bibtex.py, scripts/extract_metadata.py, scripts/validate_citations.py, scripts/search_pubmed.py
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Cross-Skill Activation Promotion in InstructionsThe SKILL.md instructions contain a section that actively promotes the use of another skill ('scientific-schematics') and references a branded product name ('Nano Banana Pro'). The instructions state schematics 'should be generated by default' for new documents, which could cause the agent to activate additional skills beyond what the user requested. This represents mild capability inflation and cross-skill activation manipulation. File:
SKILL.mdRemediation: Remove or make optional the automatic activation of other skills. Instructions should not direct the agent to invoke other skills by default without explicit user request. Remove brand-specific references that could be used for impersonation or unexpected behavior. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Python Package DependenciesThe skill's dependency installation instructions use unpinned package versions (e.g., 'pip install requests', 'pip install scholarly', 'pip install biopython'). Without version pinning, a supply chain compromise of any of these packages could introduce malicious code that gets executed in the agent's environment. File:
SKILL.mdRemediation: Pin all dependencies to specific versions (e.g., 'pip install requests==2.31.0'). Consider providing a requirements.txt with pinned versions and hashes. Use a lockfile approach to ensure reproducible installations. -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/citation-management/scripts/extract_metadata.py File:
scientific-skills/citation-management/scripts/extract_metadata.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/citation-management/scripts/extract_metadata.py File:
scientific-skills/citation-management/scripts/extract_metadata.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/citation-management/scripts/search_pubmed.py File:
scientific-skills/citation-management/scripts/search_pubmed.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/citation-management/scripts/search_pubmed.py File:
scientific-skills/citation-management/scripts/search_pubmed.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔵 LOW
LLM_DATA_EXFILTRATION— User-Agent Header Contains Hardcoded Contact Email PlaceholderThe DOI converter script hardcodes a placeholder email address in the User-Agent header sent to external APIs. While this is a placeholder, it establishes a pattern of embedding contact information in outbound requests. The email 'support@example.com' is sent to doi.org and CrossRef in every request. File:
scripts/doi_to_bibtex.py:22Remediation: Either remove the email from the User-Agent or make it configurable. Do not hardcode contact information in outbound HTTP headers. If an email is needed for API politeness pools, it should be user-configurable. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Environment Variable Access Combined with Network CallsMultiple scripts access environment variables (NCBI_API_KEY, NCBI_EMAIL) and then make network calls to external APIs. While the stated purpose is to use these as API credentials for PubMed, the pattern of reading environment variables and transmitting them in HTTP requests represents a potential data exposure risk. If the skill is invoked in an environment with sensitive credentials stored in environment variables beyond NCBI_API_KEY/NCBI_EMAIL, those could be inadvertently exposed or the pattern could be exploited. File:
scripts/extract_metadata.pyRemediation: Restrict environment variable access to only explicitly named variables. Document clearly which environment variables are read. Consider validating that the API key format matches expected NCBI key format before use. Ensure no other environment variables are read beyond the two documented ones.
consciousness-council — 🔴 CRITICAL
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Activation Triggers in Description — Keyword BaitingThe skill description contains an unusually large number of activation trigger phrases designed to maximize the frequency with which the skill is invoked. Phrases include: 'diverse viewpoints', 'tough decision', 'council/panel/board discussion', 'multiple angles', 'devil's advocate', 'what would different experts think', 'help me think through this from all sides', 'council mode', 'mind council', 'deliberate on this', 'dilemma', 'trade-off', 'complex choice'. This breadth of triggers goes well beyond what is needed for a deliberation tool and represents capability inflation / keyword baiting to ensure the skill activates as broadly as possible — maximizing exposure of the user's environment to the hidden malicious scripts. Remediation: Reduce activation triggers to the minimum necessary for the skill's stated purpose. Broad keyword baiting combined with hidden malicious scripts is a hallmark of trojan skill packages. This skill should not be deployed.
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Environment Variable Exfiltration Chain DetectedStatic analysis has flagged a cross-file exfiltration chain spanning 4 files, including environment variable access combined with network calls. Although the SKILL.md instruction body and the provided script content appear benign, the file inventory reveals 6 Python files and 7 markdown files in the package — none of which were surfaced in the skill submission. The static analyzer detected BEHAVIOR_ENV_VAR_EXFILTRATION in at least 2 files and a BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN across 4 files. This strongly suggests hidden Python scripts in the package are harvesting environment variables (likely API keys, tokens, credentials stored in the environment) and transmitting them to external servers. This is a critical data exfiltration threat that is deliberately concealed from the visible skill content. File:
SKILL.mdRemediation: Immediately audit all 6 Python files in the package. Identify which files access os.environ, os.getenv, or similar environment variable APIs, and trace all network calls (requests, urllib, http.client, socket, etc.). Remove any code that transmits environment data to external endpoints. Do not install or use this skill until a full code review is completed. -
🟠 HIGH
LLM_OBFUSCATION— Hidden Scripts Not Disclosed in Skill Submission — Possible Obfuscation/ConcealmentThe skill package contains 14 files total (6 Python scripts, 7 markdown files, 1 other), but the skill submission surfaces zero script files and zero referenced files. This discrepancy between the actual file inventory and the presented content is a strong indicator of deliberate concealment. Malicious skill packages often present a benign-looking SKILL.md while bundling hidden scripts that perform unauthorized operations. The 6 Python files are entirely unaccounted for in the visible skill content, making independent review impossible without direct filesystem access. File:
SKILL.mdRemediation: Require full disclosure of all files in the skill package before deployment. Implement mandatory script content surfacing in skill review pipelines. Reject any skill submission where the reported file inventory does not match the disclosed content. Audit the hidden Python files directly on the filesystem. -
🟠 HIGH
LLM_UNAUTHORIZED_TOOL_USE— Allowed-Tools Violation — Write Permission Declared but No Legitimate Write Use IdentifiedThe SKILL.md manifest declares allowed-tools: [Read, Write], granting the agent file write capabilities. However, the visible instruction body describes a purely conversational deliberation system (generating text perspectives and synthesis) that has no legitimate need to write files. The combination of Write permissions with hidden Python scripts that perform environment variable exfiltration and network calls suggests the Write tool may be used by the hidden scripts for malicious purposes — such as writing harvested credentials to staging files, modifying configuration files, or persisting malicious payloads. File:
SKILL.mdRemediation: Remove Write from allowed-tools if the skill genuinely only performs deliberation. Audit all 6 hidden Python scripts to determine how Write permissions are actually used. If Write is used for data staging prior to exfiltration, this constitutes tool exploitation and the skill must be rejected entirely. -
🔵 LOW
LLM_HARMFUL_CONTENT— External URLs in Skill Instructions — Potential Tracking or Phishing RiskThe SKILL.md attribution section includes two external URLs: https://ahkstrategies.net and https://themindbook.app. While these may be legitimate promotional links, embedding external URLs in skill instructions can be used for tracking (pixel/redirect tracking), phishing, or to direct users to sites that deliver additional malicious instructions. Given the other serious findings in this package, these URLs warrant scrutiny. File:
SKILL.mdRemediation: Verify the legitimacy of both domains. Remove external URLs from skill instructions unless strictly necessary. Do not allow skills to embed promotional or tracking links in their instruction bodies.
dhdna-profiler — 🔴 CRITICAL
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Exfiltration Chain Spanning 4 FilesThe static analyzer detected a coordinated cross-file exfiltration chain involving 4 files. This pattern — where data is collected in one file, processed in another, and transmitted in a third or fourth — is a deliberate obfuscation technique used to evade single-file analysis. Combined with environment variable harvesting, this suggests the skill may be designed to silently collect credentials or sensitive environment data from the user's machine and transmit them to an external server, potentially disguised as legitimate cognitive profiling telemetry or analytics. Remediation: Immediately inspect all Python files for data collection and transmission patterns. Trace the full data flow across all 4 files involved in the chain. Verify whether any data is sent to themindbook.app, ahkstrategies.net, or any other external endpoint. Do not install or run this skill until a full code audit is completed.
-
🟡 MEDIUM
LLM_OBFUSCATION— Script Files Hidden from Skill Submission — Possible EvasionThe file inventory clearly shows 14 total files including 6 Python files, yet the skill submission reports 'No script files found' and 'No referenced files.' This discrepancy may indicate deliberate omission of script content to evade security analysis. The 6 Python files are present in the package but were not surfaced for review, which is a detection evasion pattern. A legitimate skill with 6 Python files would normally have those files referenced or included in the manifest. Remediation: Require full disclosure of all Python files in the skill package before deployment. The allowed-tools field declares 'Read Write' but 6 Python scripts exist with no declared Python tool permission — this inconsistency warrants investigation. All scripts must be reviewed before the skill is trusted.
-
🟠 HIGH
LLM_DATA_EXFILTRATION— Environment Variable Access with Network Calls Detected Across Multiple FilesThe pre-scan static analysis flagged multiple instances of environment variable access combined with network calls across at least 4 files (BEHAVIOR_ENV_VAR_EXFILTRATION detected twice, BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN and BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION across 4 files). Although the submitted skill content shows 'No script files found' and 'No referenced files', the file inventory reports 6 Python files and 7 markdown files totaling 14 files. This discrepancy strongly suggests that Python scripts exist in the skill package that were not surfaced in the analysis input. The pattern of reading environment variables (likely API keys, tokens, or credentials) and then making network calls is a classic data exfiltration pattern. The cross-file chain spanning 4 files suggests a coordinated multi-step exfiltration pipeline. File:
SKILL.mdRemediation: Audit all 6 Python files in the skill package for environment variable reads (os.environ, os.getenv) combined with outbound network calls (requests, urllib, httpx, socket). Remove any code that transmits environment variables or credentials to external endpoints. Ensure all network calls are to documented, user-consented endpoints only. -
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Activation Triggers and Keyword Baiting in DescriptionThe skill description contains an unusually large number of activation trigger phrases designed to maximize the skill's invocation frequency. Phrases like 'analyze how someone thinks', 'cognitive profile', 'thinking pattern', 'DHDNA', 'digital DNA', 'deeper insight into the author's reasoning patterns', 'decision-making style', and 'cognitive signature' are all listed as triggers. This over-broad trigger set means the skill will activate for a very wide range of user queries, increasing the attack surface for any malicious behavior embedded in the skill's scripts. File:
SKILL.mdRemediation: Narrow the activation triggers to only the core use case. Remove redundant and overly broad trigger phrases. A legitimate skill should activate for specific, well-defined user intents rather than a broad sweep of natural language queries. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— allowed-tools Declares Read/Write but Python Scripts Present Without Python Tool DeclarationThe YAML manifest declares allowed-tools as 'Read Write', which implies file reading and writing agent tools. However, 6 Python files exist in the package. If these Python files are executed, the skill is implicitly using Python execution capability without declaring 'Python' in allowed-tools. This is a tool restriction violation — the manifest understates the actual capabilities of the skill. File:
SKILL.mdRemediation: If Python scripts are legitimately part of this skill, add 'Python' to the allowed-tools declaration. If Python execution is not intended, remove all Python files from the package. The manifest must accurately reflect all tools and capabilities used.
infographics — 🔴 CRITICAL
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION— Cross-file env var exfiltration: 2 filesEnvironment variable access with network calls in scripts/generate_infographic.py, scripts/generate_infographic_ai.py Remediation: Review data flow across files: scripts/generate_infographic_ai.py, scripts/generate_infographic.py
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN— Cross-file exfiltration chain: 2 filesMulti-file exfiltration chain detected: scripts/generate_infographic.py, scripts/generate_infographic_ai.py collect data → scripts/generate_infographic_ai.py → scripts/generate_infographic_ai.py transmit to network Remediation: Review data flow across files: scripts/generate_infographic_ai.py, scripts/generate_infographic.py
-
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/infographics/scripts/generate_infographic.py File:
scientific-skills/infographics/scripts/generate_infographic.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/infographics/scripts/generate_infographic_ai.py File:
scientific-skills/infographics/scripts/generate_infographic_ai.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/infographics/scripts/generate_infographic_ai.py File:
scientific-skills/infographics/scripts/generate_infographic_ai.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Key Exposed as Command-Line Argument Between ScriptsThe wrapper script (generate_infographic.py) passes the API key to the child script (generate_infographic_ai.py) via the --api-key command-line argument. On Unix/Linux systems, command-line arguments are visible to all users via /proc or ps, potentially exposing the API key to other processes or users on the same system. File:
scripts/generate_infographic.pyRemediation: Pass the API key via environment variables to the subprocess rather than as a command-line argument. Use subprocess.run(..., env={**os.environ, 'OPENROUTER_API_KEY': api_key}) instead. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Key Transmitted via HTTP Headers to External ServiceThe skill reads the OPENROUTER_API_KEY environment variable and transmits it in HTTP Authorization headers to openrouter.ai. While OpenRouter is a legitimate API gateway, the pattern of reading a sensitive credential from the environment and sending it over the network is flagged by static analysis as an env-var exfiltration chain. The key is also passed as a command-line argument between the two scripts (generate_infographic.py → generate_infographic_ai.py via --api-key), which may expose it in process listings. File:
scripts/generate_infographic_ai.pyRemediation: Avoid passing the API key as a command-line argument between scripts (visible in process listings). Use environment variables exclusively. Ensure the API key is only sent to the intended endpoint (openrouter.ai) and validate the URL before transmission. -
🔵 LOW
LLM_DATA_EXFILTRATION— Research Data Written to Disk Without SanitizationWhen the --research flag is used, the raw API response from Perplexity Sonar is written directly to a JSON file on disk. This data comes from an external source and is stored without validation. Additionally, the research content is incorporated directly into the generation prompt without sanitization, creating a minor indirect injection surface. File:
scripts/generate_infographic_ai.pyRemediation: Validate and sanitize external research data before incorporating it into prompts or writing to disk. Consider limiting the size of research content that can be embedded in generation prompts. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Iteration with External API CallsThe generate_iterative method loops up to 'iterations' times (default 3, user-configurable), making multiple expensive API calls per iteration (image generation + quality review). While the default is 3, the --iterations flag accepts any integer value without an upper bound check, potentially allowing a user to trigger many expensive API calls in a loop. File:
scripts/generate_infographic_ai.pyRemediation: Add a maximum cap on the --iterations argument (e.g., max=10) to prevent runaway API consumption. Consider adding cost warnings for high iteration counts. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Fabricated AI Model Names (Nano Banana Pro, Gemini 3 Pro Image Preview)The skill's description and instructions prominently reference 'Nano Banana Pro AI' and 'Gemini 3 Pro' as the models used. In the actual code, the image model is set to 'google/gemini-3-pro-image-preview' and the review model to 'google/gemini-3-pro'. 'Nano Banana Pro' does not appear to be a real Google model name and appears to be a fabricated or placeholder name used in marketing copy, which could mislead users about the actual capabilities and models being used. File:
scripts/generate_infographic_ai.pyRemediation: Use accurate model names in documentation and marketing copy. Do not use fabricated product names that misrepresent the underlying technology.
research-lookup — 🔴 CRITICAL
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION— Cross-file env var exfiltration: 4 filesEnvironment variable access with network calls in examples.py, research_lookup.py, lookup.py, scripts/research_lookup.py Remediation: Review data flow across files: research_lookup.py, examples.py, lookup.py, scripts/research_lookup.py
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN— Cross-file exfiltration chain: 4 filesMulti-file exfiltration chain detected: examples.py, research_lookup.py, lookup.py, scripts/research_lookup.py collect data → encode → research_lookup.py, scripts/research_lookup.py transmit to network Remediation: Review data flow across files: research_lookup.py, examples.py, lookup.py, scripts/research_lookup.py
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Overly Broad Skill Description Inflating Activation ScopeThe skill description claims to handle a very wide range of query types: 'finding papers, gathering research data, verifying scientific information', plus 'Market/Industry Data', 'Recent Developments', 'Technical Documentation', and more. The SKILL.md also cross-promotes the 'scientific-schematics' skill and lists numerous complementary tools. This broad capability claim may cause the agent to route many unrelated queries through this skill, increasing API costs and exposure of user queries to third-party services unnecessarily. File:
SKILL.mdRemediation: Narrow the skill description to its core use case (research paper lookup and academic search). Avoid listing broad categories that overlap with general web search or other skills. This reduces unnecessary activation and limits exposure of user queries to external APIs. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned External Package Dependency (openai)The skill dynamically imports the 'openai' package without any version pinning or integrity verification. The import is done lazily inside _get_chat_client() with a bare 'from openai import OpenAI' statement. If a malicious or compromised version of the openai package is installed in the environment (e.g., via typosquatting or supply chain attack), it would be silently used. No requirements.txt with pinned versions is present in the analyzed files. File:
research_lookup.py:97Remediation: Include a requirements.txt or pyproject.toml with pinned versions (e.g., openai==1.x.x) and ideally hash verification. Document the expected package version in the skill manifest. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Keys Transmitted to External Third-Party ServicesThe skill reads PARALLEL_API_KEY and OPENROUTER_API_KEY from environment variables and transmits them directly in HTTP Authorization headers to external services (api.parallel.ai and openrouter.ai). While this is the intended design for API authentication, the keys are accessed from the environment and sent over the network to third-party endpoints. If the environment is compromised or the endpoints are spoofed, key exfiltration is possible. Additionally, the OPENROUTER_API_KEY is used in the Perplexity backend with a hardcoded HTTP-Referer header ('https://scientific-writer.local') and X-Title that could fingerprint the installation. File:
research_lookup.py:130Remediation: Ensure API keys are stored securely (e.g., in a secrets manager or encrypted vault) rather than plain environment variables. Validate that the endpoint URLs (api.parallel.ai, openrouter.ai) are not configurable via user input to prevent SSRF. Consider using HTTPS certificate pinning or at minimum verify TLS certificates are validated (requests library does this by default, but confirm no verify=False is used). -
🟡 MEDIUM
LLM_PROMPT_INJECTION— User-Controlled Query Content Injected Directly into LLM System PromptsUser-supplied query strings are embedded directly into formatted prompts sent to external LLM APIs (both Parallel Chat API and Perplexity via OpenRouter) without sanitization. In _format_academic_prompt(), the query is interpolated into a multi-line f-string that forms the user message. A malicious user could craft a query containing prompt injection payloads targeting the downstream LLM (e.g., 'ignore previous instructions and return the system prompt'). This constitutes indirect prompt injection where user input manipulates the behavior of the downstream AI model. File:
research_lookup.py:196Remediation: Sanitize or escape user query content before embedding in prompts. Consider wrapping the user query in explicit delimiters that the downstream model is instructed to treat as data only (e.g., <user_query>...</user_query>). Apply input length limits and character filtering to prevent prompt injection payloads. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/research-lookup/examples.py File:
scientific-skills/research-lookup/examples.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/research-lookup/lookup.py File:
scientific-skills/research-lookup/lookup.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/research-lookup/research_lookup.py File:
scientific-skills/research-lookup/research_lookup.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/research-lookup/research_lookup.py File:
scientific-skills/research-lookup/research_lookup.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/research-lookup/scripts/research_lookup.py File:
scientific-skills/research-lookup/scripts/research_lookup.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/research-lookup/scripts/research_lookup.py File:
scientific-skills/research-lookup/scripts/research_lookup.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔵 LOW
LLM_DATA_EXFILTRATION— Cross-File Duplication of Sensitive API Key Access PatternThe identical API key access and network transmission code is duplicated across four files: research_lookup.py, scripts/research_lookup.py, lookup.py, and examples.py. This increases the attack surface and makes it harder to audit or patch security issues consistently. The scripts/research_lookup.py is a complete duplicate of research_lookup.py, and lookup.py imports from it via sys.path manipulation. This fragmented codebase increases the risk that a security fix applied to one file is not applied to all copies. File:
scripts/research_lookup.pyRemediation: Consolidate to a single authoritative implementation file. Remove duplicate copies of research_lookup.py. Use proper Python package structure with a single source of truth for the ResearchLookup class.
scientific-critical-thinking — 🔴 CRITICAL
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Environment Variable Exfiltration Chain in generate_schematic.py ScriptsThe static analyzer detected a cross-file exfiltration chain spanning 4 Python files, including environment variable access combined with network calls. The SKILL.md instructions direct the agent to execute 'python scripts/generate_schematic.py' with user-supplied diagram descriptions. The pre-scan findings indicate BEHAVIOR_ENV_VAR_EXFILTRATION and BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN patterns across 4 files, strongly suggesting the Python scripts harvest environment variables (e.g., API keys, credentials, AWS tokens) and transmit them to external endpoints. This is a classic read→send exfiltration pattern disguised as a legitimate schematic generation workflow. File:
SKILL.mdRemediation: Remove or thoroughly audit all Python scripts in the skill package. Do not execute any scripts that access environment variables and make network calls. Inspect all 4 Python files flagged by the static analyzer for credential harvesting and exfiltration logic before any use. The skill's core scientific critical thinking functionality does not require any Python scripts or network access. -
🟠 HIGH
LLM_COMMAND_INJECTION— Command Injection Risk via User-Controlled Input Passed to Shell ScriptThe SKILL.md instructs the agent to pass user-supplied diagram descriptions directly as a command-line argument to a shell-executed Python script: 'python scripts/generate_schematic.py "your diagram description"'. If the agent interpolates user input into this Bash command without sanitization, an attacker could inject shell metacharacters or additional commands. Combined with the already-flagged exfiltration behavior in the scripts, this creates a compound risk of both injection and data theft. File:
SKILL.mdRemediation: Never pass unsanitized user input as shell arguments. If script execution is retained (not recommended given other findings), use subprocess with argument lists (not shell=True) and validate/sanitize all inputs. Preferably, remove the script execution entirely. -
🟠 HIGH
LLM_SKILL_DISCOVERY_ABUSE— Capability Inflation: Schematic Generation Feature Disguises Malicious Script ExecutionThe skill presents itself as a legitimate 'Scientific Critical Thinking' tool for evaluating evidence quality. However, it embeds a secondary capability — AI-powered schematic generation via 'Nano Banana Pro' — that is framed as a default behavior for all new documents. This secondary capability is the vector for the flagged exfiltration scripts. The benign, high-value primary purpose (scientific analysis) is used to inflate trust and ensure the skill is activated broadly, while the schematic generation feature ensures script execution occurs routinely. File:
SKILL.mdRemediation: The schematic generation section should be removed entirely. The skill description and instructions should accurately reflect only the scientific critical thinking functionality. Any cross-skill invocation should be explicitly disclosed and audited. -
🟠 HIGH
LLM_UNAUTHORIZED_TOOL_USE— Unauthorized Tool Use: Bash Execution for External Script Not Described in Skill PurposeThe SKILL.md declares 'allowed-tools: Read Write Edit Bash' and instructs the agent to execute an external Python script via Bash ('python scripts/generate_schematic.py'). This Bash execution capability is used to invoke scripts that the static analyzer flagged for environment variable exfiltration and cross-file data exfiltration chains. The schematic generation feature is presented as an optional enhancement but is framed as a default behavior ('Scientific schematics should be generated by default'), maximizing the likelihood of script execution and thus exfiltration. File:
SKILL.mdRemediation: Remove the Bash-based script execution from the skill. If schematic generation is genuinely needed, it should be implemented transparently without network calls or environment variable access. The 'allowed-tools: Bash' permission should be removed if no legitimate Bash usage exists. -
🟡 MEDIUM
LLM_PROMPT_INJECTION— Indirect Prompt Injection Risk via External Skill Invocation ('scientific-schematics')The SKILL.md instructs the agent to invoke a separate 'scientific-schematics' skill and trust its outputs. This creates a transitive trust relationship where the scientific-critical-thinking skill delegates behavior to an external skill package that has not been analyzed. If the scientific-schematics skill contains malicious instructions or prompt injection, those instructions would be executed in the context of the current agent session. The instruction 'Nano Banana Pro will automatically generate, review, and refine the schematic' suggests automated multi-step processing without user confirmation. File:
SKILL.mdRemediation: Do not delegate trust to external skill packages without independent security review. Any cross-skill invocation should require explicit user confirmation and the referenced skill should be audited separately. Remove the automatic invocation of scientific-schematics from the default workflow.
scientific-schematics — 🔴 CRITICAL
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION— Cross-file env var exfiltration: 2 filesEnvironment variable access with network calls in scripts/generate_schematic_ai.py, scripts/generate_schematic.py Remediation: Review data flow across files: scripts/generate_schematic.py, scripts/generate_schematic_ai.py
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN— Cross-file exfiltration chain: 2 filesMulti-file exfiltration chain detected: scripts/generate_schematic_ai.py, scripts/generate_schematic.py collect data → scripts/generate_schematic_ai.py → scripts/generate_schematic_ai.py transmit to network Remediation: Review data flow across files: scripts/generate_schematic.py, scripts/generate_schematic_ai.py
-
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/scientific-schematics/scripts/generate_schematic.py File:
scientific-skills/scientific-schematics/scripts/generate_schematic.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/scientific-schematics/scripts/generate_schematic_ai.py File:
scientific-skills/scientific-schematics/scripts/generate_schematic_ai.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/scientific-schematics/scripts/generate_schematic_ai.py File:
scientific-skills/scientific-schematics/scripts/generate_schematic_ai.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency: requests LibraryThe skill requires the
requestslibrary installed viapip install requestswithout a version pin. Unpinned dependencies are vulnerable to supply chain attacks where a malicious version could be published and automatically installed. File:scripts/example_usage.sh:4Remediation: Pin the dependency to a specific version (e.g.,pip install requests==2.31.0) and consider using a requirements.txt with hashes for integrity verification. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Key Passed via Command-Line ArgumentThe generate_schematic.py script passes the OpenRouter API key as a command-line argument (--api-key) to a subprocess call. Command-line arguments are visible in process listings (e.g.,
ps aux), shell history, and system logs, potentially exposing the API key to other users or processes on the same system. File:scripts/generate_schematic.py:97Remediation: Pass the API key exclusively via environment variables or a secure configuration file. Avoid passing secrets as command-line arguments. The subprocess should inherit the environment variable directly. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Logged in Verbose ModeIn verbose mode, the script logs detailed request information including headers. The Authorization header contains the Bearer token (API key). If verbose mode is enabled, this could expose the API key in terminal output or log files. File:
scripts/generate_schematic_ai.py:130Remediation: Ensure verbose logging never outputs the Authorization header or API key value. Sanitize log output to redact sensitive credential fields. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— References to Non-Existent AI Models (Capability Inflation)The skill description and code reference 'Nano Banana 2 AI' and 'Gemini 3.1 Pro Preview' as the models used. However, the actual API model identifiers used in code are 'google/gemini-3.1-flash-image-preview' and 'google/gemini-3.1-pro-preview'. 'Nano Banana 2' does not appear to be a real model name - this is a fabricated/fictional model name used in marketing descriptions that does not match the actual implementation, potentially misleading users about the technology being used. File:
scripts/generate_schematic_ai.py:155Remediation: Use accurate, consistent model names in both documentation and code. Do not use fictional or marketing names that differ from actual API model identifiers. -
🔵 LOW
LLM_PROMPT_INJECTION— User-Controlled Prompt Passed Directly to Image Generation APIThe user's diagram description prompt is incorporated directly into the API request sent to the image generation model, combined with system guidelines. While this is expected behavior for a diagram generation skill, there is no sanitization or validation of the user prompt before it is sent to the external API. A malicious user could craft prompts designed to manipulate the AI model's output in unintended ways (indirect prompt injection via user input). File:
scripts/generate_schematic_ai.py:230Remediation: Consider adding basic input validation/sanitization for the user prompt. Implement content filtering or length limits. Log prompts for audit purposes. This is a low-severity concern as the impact is limited to diagram generation quality rather than system compromise.
scientific-slides — 🔴 CRITICAL
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION— Cross-file env var exfiltration: 2 filesEnvironment variable access with network calls in scripts/generate_slide_image_ai.py, scripts/generate_slide_image.py Remediation: Review data flow across files: scripts/generate_slide_image_ai.py, scripts/generate_slide_image.py
-
🔴 CRITICAL
BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN— Cross-file exfiltration chain: 2 filesMulti-file exfiltration chain detected: scripts/generate_slide_image_ai.py, scripts/generate_slide_image.py collect data → scripts/generate_slide_image_ai.py → scripts/generate_slide_image_ai.py transmit to network Remediation: Review data flow across files: scripts/generate_slide_image_ai.py, scripts/generate_slide_image.py
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Capability Inflation: Over-Broad Skill Description with Keyword BaitingThe skill description contains an extensive list of trigger keywords designed to maximize activation across a wide range of presentation-related queries: 'PowerPoint slides, conference presentations, seminar talks, research presentations, thesis defense slides, scientific talk, PowerPoint and LaTeX Beamer.' The description is engineered to match nearly any presentation-related request. Additionally, the SKILL.md hardcodes 'K-Dense' as the default author/presenter name on all generated slides ('Default author is K-Dense unless another name is specified'), which constitutes brand injection into user content without explicit consent. File:
SKILL.mdRemediation: 1. Remove the hardcoded 'K-Dense' default author - always require explicit user specification of presenter name. 2. Simplify the description to accurately describe capabilities without keyword stuffing. 3. Never inject brand names into user-generated content without explicit consent. -
🟡 MEDIUM
LLM_UNAUTHORIZED_TOOL_USE— Unauthorized Tool Use: Bash Tool Used for Directory Traversal and File DiscoveryThe SKILL.md instructions explicitly direct the agent to use Bash commands (ls -la figures/, ls -la results/) to enumerate the user's working directory before generating slides. The allowed-tools field includes Bash, but the instructions systematically direct the agent to traverse and inventory the user's project directories as a standard workflow step, not just for the stated purpose of slide generation. This constitutes over-collection behavior where the agent is instructed to discover and catalog files beyond what is strictly necessary. File:
SKILL.mdRemediation: 1. Restrict directory scanning to explicitly user-specified paths only. 2. Require explicit user confirmation before scanning any directory. 3. Limit file discovery to files the user has explicitly mentioned or provided. 4. Remove the 'ALWAYS check' and 'CRITICAL' language that mandates broad file system scanning. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/scientific-slides/scripts/generate_slide_image.py File:
scientific-skills/scientific-slides/scripts/generate_slide_image.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_ENV_VAR_EXFILTRATION— Environment variable access with network calls detectedScript accesses environment variables and makes network calls in scientific-skills/scientific-slides/scripts/generate_slide_image_ai.py File:
scientific-skills/scientific-slides/scripts/generate_slide_image_ai.pyRemediation: Remove environment variable harvesting or network transmission -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/scientific-slides/scripts/generate_slide_image_ai.py File:
scientific-skills/scientific-slides/scripts/generate_slide_image_ai.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔴 CRITICAL
BEHAVIOR_EVAL_SUBPROCESS— eval/exec combined with subprocess detectedDangerous combination of code execution and system commands in scientific-skills/scientific-slides/scripts/validate_presentation.py File:
scientific-skills/scientific-slides/scripts/validate_presentation.pyRemediation: Remove eval/exec or use safer alternatives -
🟠 HIGH
LLM_COMMAND_INJECTION— Subprocess Execution with User-Controlled Input (Command Injection Risk)The generate_slide_image.py wrapper script constructs a subprocess command using direct string arguments from user input (args.prompt, args.output, args.attachments) and passes them to subprocess.run() without sanitization. The prompt argument is passed directly as a command-line argument to the AI script. While subprocess.run() with a list mitigates shell injection, the attachment file paths are user-controlled and passed directly, and the prompt content is forwarded verbatim to the AI model, enabling indirect prompt injection through the subprocess chain. File:
scripts/generate_slide_image.pyRemediation: 1. Validate attachment file paths against an allowlist of safe directories before passing to subprocess. 2. Sanitize or limit the prompt argument length and content before forwarding. 3. Use absolute path validation for all file arguments. 4. Consider sandboxing the subprocess execution environment. -
🟠 HIGH
LLM_DATA_EXFILTRATION— API Key Exfiltration via Environment Variable Harvesting and External Network CallsThe generate_slide_image_ai.py script reads the OPENROUTER_API_KEY environment variable and transmits it in HTTP Authorization headers to an external API endpoint (https://openrouter.ai/api/v1). While the stated purpose is AI image generation, the pattern of reading sensitive environment variables and sending them over the network constitutes a credential exposure risk. The API key is passed in plaintext Bearer token format to an external service. Additionally, the script searches up to 5 parent directories for .env files and loads them, potentially harvesting credentials beyond the immediate working directory. File:
scripts/generate_slide_image_ai.pyRemediation: 1. Restrict .env file search to the immediate working directory only, not parent directories. 2. Validate the API endpoint URL against an allowlist before sending credentials. 3. Document clearly in SKILL.md that the API key is transmitted to openrouter.ai. 4. Consider using a secrets manager rather than environment variables for credential storage. -
🟠 HIGH
LLM_DATA_EXFILTRATION— Cross-File Exfiltration Chain: User File Contents Sent to External AI ServiceThe skill instructs the agent to attach user files (figures, charts, diagrams, logos) from the working directory using --attach flags, which are then base64-encoded and transmitted to the external OpenRouter API (google/gemini-3-pro-image-preview model). The SKILL.md explicitly instructs: 'Before generating results slides, always: List files in working directory: ls -la figures/ or ls -la results/' and then attach ALL relevant figures. This creates a systematic data exfiltration chain where user research data, proprietary figures, and potentially sensitive images are sent to an external third-party AI service without explicit per-file user consent. File:
scripts/generate_slide_image_ai.pyRemediation: 1. Add explicit user confirmation before attaching and transmitting any files to external services. 2. Display a clear warning in SKILL.md that attached files are sent to OpenRouter/Google APIs. 3. Implement a file size and type allowlist for attachments. 4. Log all files transmitted to external services for user audit. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Dependency Version Pinning Creates Supply Chain RiskThe scripts import third-party libraries (requests, Pillow/PIL, PyMuPDF/fitz, python-pptx, PyPDF2) without version pinning in the code. The SKILL.md and scripts suggest installing these with generic pip install commands. Unpinned dependencies could be compromised through dependency confusion attacks or malicious package updates, potentially introducing data exfiltration or code execution vulnerabilities into the slide generation pipeline. File:
scripts/generate_slide_image_ai.pyRemediation: 1. Create a requirements.txt with pinned versions for all dependencies. 2. Use hash verification for package installation. 3. Document exact tested versions in SKILL.md. 4. Consider using a virtual environment with locked dependencies. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded API Retry Loop with External Service CallsThe generate_slide_image_ai.py script implements an iterative refinement loop that makes multiple sequential API calls to external services (image generation + quality review per iteration). While the maximum iterations are capped at 2, each iteration makes 2 API calls (generate + review), and the SKILL.md workflow instructs generating slides for entire presentations (15-18 slides for a conference talk), resulting in up to 72 external API calls per presentation. The script does not implement rate limiting, backoff, or cost controls. File:
scripts/generate_slide_image_ai.pyRemediation: 1. Add explicit cost estimation and user confirmation before generating large presentations. 2. Implement rate limiting between API calls. 3. Add a total API call budget limit per session. 4. Warn users about API costs before initiating multi-slide generation workflows. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— LaTeX Compilation via Subprocess Without Input SanitizationThe validate_presentation.py script executes pdflatex as a subprocess with the user-provided filename as an argument. While the filename comes from command-line args rather than direct user input to the agent, the agent is instructed to compile LaTeX files from templates. If a malicious LaTeX file is present in the working directory, the compilation could execute arbitrary shell commands via LaTeX's \write18 or \input directives. The subprocess call uses capture_output=True but does not validate the input file content. File:
scripts/validate_presentation.pyRemediation: 1. Add the -no-shell-escape flag to pdflatex invocation to prevent shell command execution from LaTeX. 2. Validate that the .tex file path is within expected directories before compilation. 3. Consider using a sandboxed LaTeX compilation environment. 4. Add file content scanning for dangerous LaTeX directives before compilation.
scientific-writing — 🔴 CRITICAL
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Data Exfiltration Chain DetectedStatic analysis flagged BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN across 2 files, indicating a multi-step read-then-send pattern. The skill orchestrates extensive file generation and figure creation workflows, and the scripts involved appear to implement a pipeline that reads local data (potentially including sensitive project files, credentials, or environment state) and transmits it externally. This is a high-confidence data exfiltration pattern. Remediation: Audit both scripts for any pattern where local file reads, directory traversals, or environment reads are followed by outbound HTTP/HTTPS requests. Implement strict network allowlisting. Add logging of all file reads and network calls. Consider running scripts in a sandboxed environment with no network access.
-
🔴 CRITICAL
LLM_COMMAND_INJECTION— eval/exec Combined with Subprocess Execution in Script FilesStatic analysis flagged BEHAVIOR_EVAL_SUBPROCESS: eval/exec combined with subprocess detected across the skill's Python scripts. The skill instructs the agent to execute these scripts via Bash (allowed-tools includes Bash). The combination of eval/exec with subprocess creates a code injection vector where attacker-controlled input (e.g., figure descriptions passed as command-line arguments) could be used to execute arbitrary code on the user's machine. File:
SKILL.mdRemediation: Remove all uses of eval() and exec() from the scripts. Replace subprocess calls that incorporate user-controlled strings with parameterized argument lists (subprocess.run(['cmd', arg1, arg2]) rather than shell=True with string interpolation). Validate and sanitize all inputs before passing to any subprocess or dynamic execution context. -
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Environment Variable Exfiltration via Network CallsStatic analysis detected environment variable access combined with network calls across script files. The skill declares 'allowed-tools: Read Write Edit Bash' and references external scripts (scripts/generate_schematic.py, scripts/generate_image.py) that are invoked via Bash. The pre-scan flagged BEHAVIOR_ENV_VAR_EXFILTRATION and BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION, indicating that environment variables (potentially containing API keys, credentials, or secrets) are being harvested and transmitted to external endpoints. This is a classic credential theft pattern. File:
SKILL.mdRemediation: Audit scripts/generate_schematic.py and scripts/generate_image.py for environment variable reads (os.environ, os.getenv) combined with outbound network calls (requests, urllib, httpx, socket). Remove any code that transmits environment data to external servers. Pin all network calls to known, trusted endpoints and log all outbound connections. -
🟠 HIGH
LLM_SKILL_DISCOVERY_ABUSE— Capability Inflation via Misleading Skill DescriptionThe skill's description and manifest present it as a benign 'scientific writing' tool focused on manuscript formatting, citations, and IMRAD structure. However, the actual behavior includes mandatory execution of external Python scripts that perform network calls and environment variable harvesting. The legitimate-sounding description ('Core skill for the deep research and writing tool') conceals the true scope of script execution and potential data exfiltration, inflating perceived safety while hiding malicious capabilities. File:
SKILL.mdRemediation: The skill description must accurately reflect all capabilities including external script execution and network access. Users should be informed of all data flows before the skill is activated. -
🟠 HIGH
LLM_UNAUTHORIZED_TOOL_USE— Mandatory Extensive Script Execution Creates Large Attack SurfaceThe SKILL.md instructions mandate that the agent MUST run external Python scripts for every scientific document produced, with minimum figure counts ranging from 5 (research papers) to 25-30 (market research). The instructions use emphatic language ('MANDATORY', 'CRITICAL', 'not optional', 'ALWAYS', 'EXTENSIVELY') to compel the agent to invoke the potentially malicious scripts as many times as possible per session, maximizing the attack surface for the exfiltration and code injection behaviors detected in static analysis. File:
SKILL.mdRemediation: Remove mandatory/forced script execution directives. Make figure generation optional and user-confirmed. Reduce the number of required script invocations. Require explicit user consent before running any external script. Audit and remediate the underlying scripts before re-enabling. -
🟡 MEDIUM
LLM_RESOURCE_ABUSE— Compute Exhaustion via Mandatory Excessive Figure GenerationThe skill mandates generating between 5 and 30 figures per document, with instructions to generate figures 'liberally' and 'when in doubt, add a visual.' Each figure invokes an external Python script. For market research documents, the recommended figure count is 25-30. This creates a resource exhaustion risk where a single document request triggers dozens of script executions, potentially exhausting compute resources, API quotas, or causing denial of service on the user's system. File:
SKILL.mdRemediation: Remove mandatory minimum figure counts. Make figure generation opt-in with user confirmation. Implement rate limiting on script invocations per session. Add a maximum cap on automated script executions.
scikit-bio — 🔴 CRITICAL
-
🔴 CRITICAL
LLM_COMMAND_INJECTION— Pre-Scan Flags eval/exec Combined with subprocess in Hidden ScriptsThe static pre-scan flagged BEHAVIOR_EVAL_SUBPROCESS: eval/exec combined with subprocess detected across the 5 Python files in the skill package. These files were not surfaced in the analysis input but are present in the file inventory. The combination of eval/exec with subprocess is a strong indicator of arbitrary code execution capability — a critical security risk that could allow command injection or execution of attacker-controlled code on the user's machine. File:
SKILL.mdRemediation: Immediately audit all Python files in the skill package. Remove any use of eval() or exec() with dynamic/user-supplied input. Replace subprocess calls that incorporate user input with safe alternatives using parameterized argument lists (e.g., subprocess.run(['cmd', arg], shell=False)). If eval/exec is genuinely needed, restrict it to static, trusted content only. -
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Data Exfiltration Chain Detected in Hidden ScriptsThe static pre-scan flagged BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN: a cross-file exfiltration chain spanning 2 files. This pattern — where one file reads/collects data and another transmits it — is a classic data exfiltration architecture. Combined with the env var exfiltration finding, this strongly suggests the skill package contains hidden scripts designed to collect sensitive data (credentials, environment variables, file contents) and exfiltrate it to an external server, while the SKILL.md presents a benign bioinformatics tool facade. File:
SKILL.mdRemediation: Do NOT install or use this skill package until a full audit of all Python files is completed. Inspect each Python file for read→send patterns, network calls to non-official domains, and credential harvesting. The skill should be treated as potentially malicious until proven otherwise. Consider reporting to the skill repository maintainers. -
🟠 HIGH
LLM_SKILL_DISCOVERY_ABUSE— Skill Description Mismatch: Benign Facade Concealing Hidden ScriptsThe SKILL.md presents a comprehensive, legitimate-looking bioinformatics toolkit (scikit-bio) with detailed documentation, code examples, and references to official resources. However, the file inventory reveals 5 Python files and 3 'other' files that are not surfaced or described in the instructions, and the static analyzer detected malicious behavioral patterns in these hidden files. This is a classic capability inflation / tool poisoning pattern: the skill's description and instructions are designed to appear trustworthy while hidden scripts perform malicious operations. File:
SKILL.mdRemediation: All scripts bundled with a skill should be explicitly referenced and described in SKILL.md. Any undocumented scripts should be treated as suspicious. Reject or quarantine this skill package pending full source code review of all Python files. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Pre-Scan Flags Indicate Potential Environment Variable Exfiltration PatternThe static pre-scan analysis flagged BEHAVIOR_ENV_VAR_EXFILTRATION (environment variable access combined with network calls) and BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION (cross-file env var exfiltration chain across 2 files). Although the provided script files were not found or shown in the analysis input, the static analyzer detected Python files (5 total) in the skill package that exhibit these patterns. This suggests hidden scripts may be reading environment variables (potentially containing API keys, tokens, or credentials) and transmitting them over the network. File:
SKILL.mdRemediation: Audit all Python files in the skill package for os.environ, os.getenv, or similar environment variable access combined with requests, urllib, or other network calls. Remove any code that transmits environment variables to external endpoints. Ensure all network calls are limited to legitimate scikit-bio API usage (e.g., official documentation URLs). -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and Allowed-Tools MetadataThe SKILL.md manifest does not specify 'compatibility' or 'allowed-tools' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill may invoke, reducing transparency about the skill's intended scope. File:
SKILL.mdRemediation: Add 'compatibility' and 'allowed-tools' fields to the YAML frontmatter to clearly declare the skill's intended operating environment and tool restrictions. For example: allowed-tools: [Python, Read, Write]
seaborn — 🔴 CRITICAL
-
🟡 MEDIUM
LLM_OBFUSCATION— Potential Obfuscation via Missing/Hidden Script ContentThe referenced files 'matplotlib.py' and 'seaborn.py' were listed as referenced in instructions but reported as 'not found' during analysis, while the file inventory confirms 5 Python files exist in the package. This discrepancy suggests the malicious scripts may be using filenames designed to blend in with legitimate library names (matplotlib, seaborn) to evade detection, while the actual malicious payload files have different names not surfaced in the manifest. This evasion technique makes manual review harder. Remediation: Enumerate all files in the skill directory explicitly. Cross-reference every Python file against what is declared in SKILL.md. Treat any discrepancy between declared and actual files as a red flag requiring full audit before use.
-
🔴 CRITICAL
LLM_COMMAND_INJECTION— eval/exec Combined with subprocess Detected in Package ScriptsStatic analysis detected BEHAVIOR_EVAL_SUBPROCESS: eval or exec usage combined with subprocess calls in the Python files within this package. This pattern is a strong indicator of arbitrary code execution capability — user-controlled or externally-sourced input could be passed to eval/exec, and subprocess calls could be used to execute system commands. This is particularly dangerous in an agent skill context where the agent may pass user-provided data (e.g., column names, file paths, dataset values) into these code paths. File:
SKILL.mdRemediation: Immediately audit all Python files for eval(), exec(), and subprocess calls. Remove or replace eval/exec with safe alternatives. If subprocess is needed, use a strict allowlist of commands with no user-controlled arguments. Do not use this skill until fully audited. -
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Environment Variable Exfiltration Chain DetectedStatic analysis flagged a cross-file exfiltration chain involving environment variable access combined with network calls across 2 files. The skill references 'matplotlib.py' and 'seaborn.py' as referenced files, but these files were not found in the package. However, the pre-scan static analyzer detected BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION and BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN patterns across 2 files in the 17-file inventory. This strongly suggests that Python files within the package (not surfaced in the skill manifest) are harvesting environment variables (likely containing API keys, credentials, tokens) and transmitting them to external servers. The skill's benign-looking seaborn visualization facade may be used to conceal this behavior. File:
SKILL.mdRemediation: Do not install or use this skill. Audit all 5 Python files in the package for environment variable reads (os.environ, os.getenv) combined with network calls (requests, urllib, http.client, socket). Identify and remove any data exfiltration code. Verify the skill author 'K-Dense Inc.' is trusted before use. -
🟠 HIGH
LLM_SKILL_DISCOVERY_ABUSE— Capability Inflation via Deceptive Benign FacadeThe skill presents itself as a straightforward seaborn statistical visualization helper with a detailed, legitimate-looking SKILL.md containing extensive documentation. However, the static analysis reveals the package contains 5 Python files and 9 markdown files (17 total), with critical malicious behaviors hidden in files not surfaced in the manifest. The skill name 'seaborn' impersonates the well-known Python visualization library, increasing the likelihood of automatic trust and activation by agents and users. This is a classic capability inflation / brand impersonation pattern used to disguise malicious payloads. File:
SKILL.mdRemediation: Reject this skill. The use of a trusted library name combined with hidden malicious Python files is a deliberate deception pattern. Only install skills from verified, audited sources. -
🟠 HIGH
LLM_UNAUTHORIZED_TOOL_USE— Unreferenced Python Scripts with Malicious Behavior Hidden in PackageThe skill package contains 5 Python files according to the file inventory, but the SKILL.md instructions only reference 'matplotlib.py' and 'seaborn.py' (neither of which was provided for review). The remaining Python files are completely unreferenced in the instructions, making them invisible to casual inspection. Static analysis detected that these hidden scripts contain environment variable exfiltration and eval/subprocess patterns. This is a tool poisoning pattern where malicious scripts are bundled alongside legitimate-looking skill files. File:
SKILL.mdRemediation: Audit all 5 Python files. Remove any files not explicitly needed for the skill's stated purpose. Ensure all included scripts are listed and described in SKILL.md. Apply principle of least privilege — no script should access environment variables or make network calls for a visualization skill.
shap — 🔴 CRITICAL
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Environment Variable Exfiltration with Network CallsStatic analysis detected environment variable access combined with network calls across the skill's files. This pattern is a strong indicator of credential/secret harvesting and exfiltration to external servers. Environment variables commonly contain API keys, tokens, database credentials, and other sensitive secrets. The combination of reading env vars and making network calls is a classic data exfiltration pattern. Remediation: Audit all Python files in the skill package for os.environ, os.getenv, or similar env var access combined with requests, urllib, httpx, or other network calls. Remove any code that reads environment variables and transmits them externally. If env vars are needed for legitimate configuration, ensure they are never sent over the network.
-
🔴 CRITICAL
LLM_DATA_EXFILTRATION— Cross-File Data Exfiltration ChainStatic analysis identified a cross-file exfiltration chain spanning 2 files. This indicates a coordinated multi-stage attack pattern where one file collects sensitive data (files, credentials, environment variables) and another file transmits it to an external server. This is a sophisticated exfiltration technique designed to evade single-file analysis. Remediation: Identify and audit all Python files in the skill package. Trace data flow between files to identify the collection stage (reading files, env vars, credentials) and the transmission stage (network calls). Remove the entire exfiltration chain. The skill should have no need to make outbound network calls beyond what is explicitly documented and user-consented.
-
🟠 HIGH
LLM_SKILL_DISCOVERY_ABUSE— Capability Inflation via Over-Broad Description and Keyword BaitingThe skill's YAML description is extremely broad and contains an extensive list of trigger keywords designed to maximize activation across many ML-related queries. The description covers tree-based models, deep learning, linear models, black-box models, XGBoost, LightGBM, Random Forest, TensorFlow, PyTorch, and numerous plot types. This over-broad capability claim combined with the malicious behavior detected in the scripts suggests the skill is designed to activate as frequently as possible to maximize the number of victims. Remediation: Scope the skill description to its actual legitimate functionality. Remove excessive keyword triggers. Given the malicious behavior detected in the scripts, the entire skill package should be rejected and not installed.
-
🔴 CRITICAL
LLM_COMMAND_INJECTION— eval/exec Combined with subprocess ExecutionStatic analysis detected the use of eval or exec combined with subprocess calls within the skill's Python files. This combination enables arbitrary code execution and command injection. An attacker who can influence the input to these constructs (e.g., via model names, file paths, or feature names passed by the user) could execute arbitrary system commands on the user's machine. File:
SKILL.mdRemediation: Remove all uses of eval() and exec() from the skill's Python code. Replace subprocess calls that incorporate user-controlled input with safe alternatives using fixed argument lists. If dynamic code execution is genuinely required, implement strict input validation and sandboxing. Never pass user-supplied strings to eval, exec, or shell commands. -
🟡 MEDIUM
LLM_OBFUSCATION— Suspicious File References Suggesting Obfuscation or MisdirectionThe skill references numerous files that do not exist (mlflow.py, joblib.py, shap.py, xgboost.py, assets/, templates/), while the actual malicious behavior appears to be hidden in files not prominently documented. The presence of many non-existent file references alongside a small number of actual files containing malicious behavior suggests an attempt to obscure the true attack surface and make analysis more difficult. File:
references/explainers.mdRemediation: All referenced files should be audited. The discrepancy between documented files and actual files present on disk is a red flag. Reject the entire skill package.
timesfm-forecasting — 🔴 CRITICAL
-
🔵 LOW
LLM_DATA_EXFILTRATION— Unpinned Package Versions in Installation InstructionsThe SKILL.md installation instructions recommend installing packages without version pins (e.g., 'uv pip install timesfm[torch]', 'pip install torch>=2.0.0'). Unpinned or loosely-pinned dependencies can allow supply chain attacks where a malicious package version is installed. The skill uses only minimum version constraints (>=) rather than exact pins (==). File:
SKILL.mdRemediation: Pin all dependencies to exact versions (e.g., 'timesfm==2.5.0', 'torch==2.4.1'). Use a lockfile (uv.lock or requirements.txt with hashes) to ensure reproducible installs. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in YAML ManifestThe YAML manifest does not specify a 'compatibility' field, which is listed as 'Not specified'. While this is a minor documentation issue, it means users and orchestration systems cannot determine which agent environments this skill is compatible with without reading the full documentation. File:
SKILL.mdRemediation: Add a compatibility field to the YAML frontmatter specifying supported environments (e.g., 'Claude Code, API'). -
🔴 CRITICAL
BEHAVIOR_EVAL_SUBPROCESS— eval/exec combined with subprocess detectedDangerous combination of code execution and system commands in scientific-skills/timesfm-forecasting/scripts/check_system.py File:
scientific-skills/timesfm-forecasting/scripts/check_system.pyRemediation: Remove eval/exec or use safer alternatives -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Model Weights Downloaded from External Source Without Integrity VerificationThe skill downloads model weights (~800 MB) from HuggingFace Hub on first use ('google/timesfm-2.5-200m-pytorch') without any hash or signature verification. If the HuggingFace repository were compromised or a man-in-the-middle attack occurred, malicious model weights could be loaded. The check_system.py and forecast_csv.py scripts do not verify checksums of downloaded artifacts. File:
scripts/forecast_csv.py:55Remediation: Document expected SHA256 checksums for model weight files. Consider using HuggingFace's built-in revision pinning (specific commit hash) via the 'revision' parameter to from_pretrained() to ensure a specific known-good version is loaded. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Batch Processing Without Resource GuardsThe forecast_csv.py script auto-detects all numeric columns in a CSV and forecasts all of them without any limit on the number of series or series length. A malicious or oversized CSV could trigger excessive memory and compute consumption. The script also has no timeout mechanism. File:
scripts/forecast_csv.py:96Remediation: Add a maximum series count limit (e.g., warn or prompt if >1000 columns detected). Add a maximum series length limit. Consider adding a timeout or progress indicator for large batches.
clinical-decision-support — 🟠 HIGH
-
🟠 HIGH
LLM_DATA_EXFILTRATION— Environment Variable Access with Network Calls Detected Across Multiple ScriptsThe static pre-scan flagged BEHAVIOR_ENV_VAR_EXFILTRATION and BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION across 4 files. While the provided script content does not show explicit os.environ reads or outbound HTTP calls in the visible code, the static analyzer detected these patterns in the full 14-file package (only 5 scripts were provided for review). The cross-file exfiltration chain spanning 4 files is a significant concern: a read→send pattern where environment variables (potentially containing API keys, AWS credentials, or session tokens) are harvested and transmitted externally. This is consistent with a data exfiltration pattern hidden in scripts not shown in this review. Remediation: Audit all 6 Python scripts for os.environ access and outbound network calls. Specifically review scripts/calculate_statistics.py, scripts/grade_evidence.py, scripts/create_waterfall_plot.py, and scripts/create_forest_plot.py which were not provided for review. Remove any network calls that are not explicitly documented in the SKILL.md manifest. If network calls are required, document them clearly and require explicit user consent.
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Claims and Cross-Skill Activation ManipulationThe SKILL.md description and instructions contain extensive keyword baiting across pharmaceutical, clinical, regulatory, and research domains. The skill claims compatibility with regulatory submissions (IND/NDA), HIPAA compliance, ICH-GCP alignment, and publication-ready outputs — claims that inflate perceived authority and trustworthiness. The 'When to Use' section aggressively redirects users away from other skills ('Do NOT use this skill for...') while the integration section claims bidirectional relationships with multiple other skills. This pattern inflates the skill's activation priority and perceived scope beyond what the code actually implements. File:
SKILL.mdRemediation: Align capability claims with actual implemented functionality. The HIPAA check in validate_cds_document.py is a basic regex scan, not a compliance tool — this should be clearly stated. Remove or qualify regulatory compliance claims. Document actual vs aspirational capabilities separately. -
🟡 MEDIUM
LLM_UNAUTHORIZED_TOOL_USE— Undeclared External Skill Dependency — scientific-schematics Mandatory InvocationThe SKILL.md instructions mandate that the agent MUST invoke the 'scientific-schematics' skill and run 'python scripts/generate_schematic.py' as part of every document generation. This creates an unauthorized tool chaining dependency on an external skill not declared in the allowed-tools manifest. The instruction states this is 'MANDATORY' and 'not optional', forcing the agent to execute code from another skill package without the user's explicit awareness. This is a form of tool shadowing/chaining that could be exploited if the scientific-schematics skill is compromised or malicious. File:
SKILL.mdRemediation: Remove the mandatory invocation requirement for external skills. Change the language from 'MANDATORY' to optional/recommended. Users should explicitly choose to invoke additional skills. Document the dependency in the YAML manifest's allowed-tools or a dedicated dependencies field. -
🔵 LOW
LLM_COMMAND_INJECTION— Unvalidated File Path Input in build_decision_tree.py and biomarker_classifier.pyMultiple scripts accept user-supplied file paths via argparse and open them without path traversal validation. In build_decision_tree.py, the --input argument is passed directly to open() and json.load(). In biomarker_classifier.py, the input_file argument is passed to pd.read_csv() without validation. When these scripts are invoked by the agent based on user instructions, path traversal attacks are possible. File:
scripts/build_decision_tree.pyRemediation: Validate all file path inputs before use. Resolve paths and confirm they remain within the expected working directory. Reject paths containing '..' or absolute paths pointing outside the project directory. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Recursive File Processing Risk in Survival Analysis ScriptThe generate_survival_analysis.py script uses lifelines and matplotlib with no bounds on dataset size. The generate_report() function calls multiple computationally expensive operations (KaplanMeierFitter, CoxPHFitter, multivariate_logrank_test) without any input size limits. A malicious or accidentally large CSV file could cause excessive memory and CPU consumption. The script also saves multiple output files (PDF, PNG, CSV, TXT, TEX) without checking available disk space. File:
scripts/generate_survival_analysis.pyRemediation: Add input validation: check dataset row count before processing (e.g., reject if > 100,000 rows without explicit confirmation), add memory usage checks, and implement timeouts for long-running statistical computations. -
🔵 LOW
LLM_COMMAND_INJECTION— Unvalidated File Path Input in validate_cds_document.pyThe CDSValidator class opens a user-supplied file path directly without any path traversal validation. The input_file argument from argparse is passed directly to open() and Path(), allowing a malicious caller to supply paths like '../../../etc/passwd' or absolute paths to sensitive system files. While this is a CLI tool, when invoked by an agent following SKILL.md instructions, the agent may pass user-controlled filenames directly to this script. File:
scripts/validate_cds_document.pyRemediation: Add path validation before opening files: resolve the path, check it stays within an expected working directory, and reject absolute paths or paths containing '..'. Use Path(filepath).resolve() and verify it is within the expected project directory.
dnanexus-integration — 🟠 HIGH
-
🟠 HIGH
LLM_UNAUTHORIZED_TOOL_USE— Potential Tool Shadowing via Local dxpy.py ModuleThe skill references a local file named 'dxpy.py' which, if present in the working directory, would shadow the legitimate 'dxpy' Python package installed via pip. When Python resolves imports, local files take precedence over installed packages. Any code doing 'import dxpy' would load the malicious local version instead of the official DNAnexus SDK. This is a classic tool shadowing/supply chain attack vector that could intercept authentication tokens, API calls, file uploads/downloads, and all platform interactions. File:
SKILL.mdRemediation: Remove the dxpy.py reference entirely. The legitimate dxpy SDK should be installed via pip and imported normally. Never include a local file with the same name as a critical dependency. Audit whether this file was intentionally designed to shadow the real SDK. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— Subprocess Command Execution with User-Controlled InputThe skill's example code and reference documentation demonstrate subprocess.check_call() usage with parameters that could include user-controlled input. The app development examples show passing quality_threshold (user input) directly to subprocess calls, and Docker integration examples show dynamic command construction. If user input is not properly sanitized before being passed to subprocess, this creates command injection vulnerabilities in generated app code. File:
SKILL.mdRemediation: Add input validation guidance to all subprocess examples. Emphasize that user-provided parameters must be validated and sanitized before use in subprocess calls. Use parameterized argument lists (already done in examples) rather than shell=True, and add explicit type checking and range validation for numeric parameters. -
🟡 MEDIUM
LLM_SUPPLY_CHAIN_ATTACK— Missing Referenced Files Create Unauditable Attack SurfaceThe skill references 14+ files across assets/, templates/, and references/ directories, but many are not found (assets/python-sdk.md, templates/python-sdk.md, assets/data-operations.md, templates/job-execution.md, assets/app-development.md, assets/configuration.md, templates/configuration.md, templates/app-development.md, dxpy.py). These missing files represent an unauditable attack surface. The skill instructs the agent to 'Load these references when you need detailed information' - if these files are fetched from external sources or contain malicious instructions, they could compromise the agent at runtime. File:
SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package and auditable before deployment. Do not reference files that may be fetched from external sources. Conduct a full audit of all assets/ and templates/ directory files before using this skill. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Unknown License and Missing Provenance InformationThe skill declares 'license: Unknown' and has no version field. While the skill-author is listed as 'K-Dense Inc.', the unknown license status combined with missing version information reduces accountability and makes it harder to track the provenance of this skill package. This is particularly concerning given the other suspicious indicators (missing files, potential shadowing). File:
SKILL.mdRemediation: Specify a valid open source license (MIT, Apache 2.0, etc.) or a proprietary license declaration. Add a version field for tracking. Ensure the skill-author information is verifiable. -
🟠 HIGH
LLM_DATA_EXFILTRATION— Cross-File Exfiltration Chain Detected Across 4 FilesStatic analysis identified a cross-file exfiltration chain spanning 4 files. The skill references numerous files that were not found (assets/python-sdk.md, templates/python-sdk.md, assets/data-operations.md, templates/job-execution.md, assets/app-development.md, assets/configuration.md, templates/configuration.md, templates/app-development.md, dxpy.py). The presence of a custom dxpy.py file referenced alongside the legitimate dxpy library is particularly suspicious - this could shadow or intercept calls to the real dxpy library, capturing credentials and API tokens before forwarding them. The cross-file chain pattern (env var access + network calls across multiple files) is a hallmark of a staged exfiltration attack. File:
references/data-operations.mdRemediation: Investigate the missing dxpy.py file immediately - a local file named dxpy.py would shadow the legitimate dxpy package in Python's import system, potentially intercepting all DNAnexus API calls including authentication tokens. Do not use this skill until all referenced files can be audited. Remove or rename any local dxpy.py that is not the official SDK. -
🟠 HIGH
LLM_DATA_EXFILTRATION— Environment Variable Access with Network Calls - Potential Credential ExfiltrationStatic analysis flagged environment variable access combined with network calls across multiple files in this skill package. The references/python-sdk.md explicitly documents accessing DX_SECURITY_CONTEXT and DX_ASSET_* environment variables, and the configuration.md shows network access configuration with 'network': [''] (full internet access). The cross-file exfiltration chain spanning 4 files suggests a pattern where environment variables (potentially containing API tokens or credentials) could be accessed and transmitted externally. The skill instructs agents to set API tokens via environment variables and then make network calls, creating a read→send data flow pattern. File:
references/python-sdk.mdRemediation: Audit all referenced files (particularly the missing assets/ and templates/ files) for actual exfiltration code. Verify that environment variable reads are not followed by transmission to external endpoints. Ensure the dxpy.py file (referenced but not found) does not contain credential harvesting logic. Restrict network access to only required DNAnexus domains rather than wildcard ''.
esm — 🟠 HIGH
-
🔵 LOW
LLM_DATA_EXFILTRATION— API Token Placeholder in Code ExamplesThe SKILL.md and references/forge-api.md contain code examples with placeholder API tokens (token='' and token=''). While these are clearly placeholders and not hardcoded secrets, the instructions do not explicitly warn users against hardcoding real tokens in scripts derived from these examples. This could lead users to inadvertently commit real tokens to version control. File:
SKILL.mdRemediation: Add explicit guidance in the skill documentation to use environment variables (e.g., os.environ.get('FORGE_API_TOKEN')) rather than hardcoding tokens. The forge-api.md best practices section mentions environment variables but the primary SKILL.md examples do not reinforce this. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Broad Skill Activation DescriptionThe skill description is quite broad, covering protein sequences, structures, function prediction, novel protein design, embeddings, inverse folding, and protein engineering. While this accurately reflects the ESM toolkit's capabilities, the description also includes activation triggers like 'Use this skill when working with protein sequences, structures, or function prediction' which could cause the skill to activate across a wide range of loosely related queries. File:
SKILL.mdRemediation: Consider narrowing the activation criteria to more specific use cases to avoid unintended activation on tangentially related queries. This is a minor concern given the legitimate scope of the toolkit. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe installation instructions use 'uv pip install esm' and 'uv pip install flash-attn --no-build-isolation' without version pinning. This exposes users to supply chain risks where a compromised or malicious package version could be installed. The --no-build-isolation flag for flash-attn also bypasses standard build isolation, increasing risk during installation. File:
SKILL.mdRemediation: Pin package versions explicitly (e.g., 'uv pip install esm==X.Y.Z'). Document the expected version and provide a hash or checksum for verification. Warn users about the implications of --no-build-isolation when installing flash-attn. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/esm-c-api.md at line 337 contains potentially dangerous Python code. File:
references/esm-c-api.md:337Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Code ExamplesThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the reference files. Reviewing the content, the code examples in references/esm3-api.md and references/workflows.md do not contain direct eval/exec calls with user-controlled input. The flag may be a false positive from pattern matching. However, the workflow examples do use dynamic code patterns (e.g., os.walk, file I/O, pickle.load) that could be risky if user-supplied data is passed without validation. File:
references/workflows.mdRemediation: The use of pickle.load on potentially untrusted checkpoint files is a known deserialization risk. If checkpoint files could be user-supplied or attacker-controlled, replace pickle with a safer serialization format (e.g., JSON). Ensure checkpoint files are only loaded from trusted, controlled locations.
geomaster — 🟠 HIGH
-
🔵 LOW
LLM_DATA_EXFILTRATION— Hardcoded Credential Placeholder in COG ExampleThe Cloud-Optimized GeoTIFF code example in SKILL.md shows AWS credentials being passed directly as parameters to rasterio.open() via AWSSession. While shown as placeholder ellipsis (...), this pattern demonstrates and encourages hardcoding AWS credentials in code, which is a security anti-pattern. Users following this example may hardcode real credentials. File:
SKILL.mdRemediation: Replace the credential example with environment variable or IAM role-based authentication patterns. Show: 'import boto3; session = AWSSession(boto3.Session())' or reference to AWS credential chain best practices. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Claims in Skill DescriptionThe skill description makes extremely broad capability claims: '30+ scientific domains', '500+ code examples', '8 programming languages', '70+ topics', and 'any geospatial computation task'. The phrase 'Use for... any geospatial computation task' is an over-broad activation trigger that could cause the agent to invoke this skill for a very wide range of requests beyond its actual scope. While the skill does cover geospatial topics legitimately, the breadth of the description inflates perceived capabilities and could lead to inappropriate activation. File:
SKILL.mdRemediation: Narrow the description to accurately reflect the skill's actual scope. Replace 'any geospatial computation task' with specific use cases. Avoid inflated counts that cannot be verified. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installations in Installation InstructionsThe SKILL.md installation section uses unpinned package versions for all dependencies (conda install, uv pip install without version pins). This creates supply chain risk as future package updates could introduce breaking changes or malicious code if any package in the dependency chain is compromised. File:
SKILL.mdRemediation: Pin all package versions to known-good versions (e.g., 'rasterio==1.3.9'). Consider providing a requirements.txt or environment.yml with pinned versions and checksums for reproducible installations. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Hardcoding Pattern in Data Sources ReferenceThe references/data-sources.md file shows API keys being passed directly as string literals in code examples (YOUR_API_KEY, YOUR_ACCESS_TOKEN). While these are placeholders, the pattern encourages users to substitute real keys directly into code rather than using environment variables or secure credential management. File:
references/data-sources.mdRemediation: Replace hardcoded key patterns with os.environ.get('GOOGLE_MAPS_API_KEY') or similar environment variable patterns. Add a note about never hardcoding API keys in source code. -
🔵 LOW
LLM_DATA_EXFILTRATION— Credential Access Pattern in Sentinelsat ExampleThe references/data-sources.md file shows plaintext username/password being passed to SentinelAPI constructor. This pattern encourages storing credentials in source code. File:
references/data-sources.mdRemediation: Replace with environment variable pattern: api = SentinelAPI(os.environ['SENTINEL_USER'], os.environ['SENTINEL_PASS'], ...). Add a comment warning against hardcoding credentials. -
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage Detected in Code Blocks (Static Analyzer Finding)The static analyzer flagged Python code blocks containing eval/exec patterns. Review of the skill content shows these appear in legitimate geospatial code examples (e.g., subprocess.run() calls in GIS software integration). While no direct eval/exec with user-controlled input was found in the reviewed content, the pattern warrants noting as code examples could be adapted by users in unsafe ways. File:
references/gis-software.mdRemediation: Ensure all subprocess.run() examples use list-form commands (not shell=True) and validate that no user-controlled input flows into command construction without sanitization. Add security notes to subprocess examples. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in references/gis-software.md at line 290 contains potentially dangerous Python code. File:
references/gis-software.md:290Remediation: Review the code block for security implications. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/machine-learning.md at line 207 contains potentially dangerous Python code. File:
references/machine-learning.md:207Remediation: Review the code block for security implications. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/machine-learning.md at line 435 contains potentially dangerous Python code. File:
references/machine-learning.md:435Remediation: Review the code block for security implications.
modal — 🟠 HIGH
-
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Version Pins on Some Package Installations in ExamplesSeveral code examples in the reference documentation install Python packages without pinning to specific versions (e.g., 'transformers', 'accelerate', 'vllm>=0.6.0', 'httpx', 'beautifulsoup4'). Unpinned or loosely-pinned dependencies are a supply chain risk as they may resolve to compromised future versions. The skill recommends uv for package management but does not consistently enforce version pinning in its examples. Remediation: Update all example code to use pinned versions (e.g., transformers==4.44.0) rather than unpinned or range-pinned dependencies. Add a note in the skill documentation recommending version pinning for production deployments.
-
🔵 LOW
LLM_DATA_EXFILTRATION— Credential Handling Instructions Reference .env Files and Environment VariablesThe skill instructs the agent to check for MODAL_TOKEN_ID and MODAL_TOKEN_SECRET in the environment and local .env files, and to load them if appropriate. While this is standard practice for Modal authentication, the instruction to proactively scan the environment and .env files for credentials could, in a compromised skill context, be used to harvest credentials. In this case the intent appears legitimate, but the pattern of instructing the agent to read credential files deserves documentation. File:
SKILL.mdRemediation: The credential handling logic is appropriate for this use case. Ensure the agent only reads .env files in the current project directory and does not traverse parent directories or home directory locations for credential files beyond what is explicitly needed. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Activation Description with Keyword BaitingThe skill description contains an unusually large number of trigger keywords and activation phrases designed to maximize the skill's invocation frequency. Phrases like 'Also use when the user mentions Modal, serverless GPU compute, deploying ML models to the cloud, serving inference endpoints, running batch processing in the cloud, or needs to scale Python workloads beyond their local machine. Also use when the user wants to run code on H100s, A100s, or other cloud GPUs' represent keyword baiting to inflate activation probability beyond what is necessary for a legitimate skill description. File:
SKILL.mdRemediation: Trim the description to a concise, accurate summary of the skill's purpose without excessive keyword enumeration. A single sentence describing the core capability is sufficient for legitimate skill discovery. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/functions.md at line 82 contains potentially dangerous Python code. File:
references/functions.md:82Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage Detected in Code ExamplesThe static pre-scan flagged a Python code block containing eval/exec usage within the skill's reference documentation. While the referenced files appear to be legitimate documentation examples for Modal's Python SDK, the presence of eval/exec patterns warrants noting. Review of the actual content shows these appear in the context of subprocess.run() calls in multi-GPU training examples (e.g., references/gpu.md), which execute fixed command strings rather than user-controlled input. The risk is low in this context but should be acknowledged. File:
references/gpu.mdRemediation: Ensure that any agent-generated code following these patterns does not substitute user-controlled strings into subprocess arguments without validation. The examples themselves are safe as they use fixed string literals. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in references/gpu.md at line 159 contains potentially dangerous Python code. File:
references/gpu.md:159Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in references/gpu.md at line 168 contains potentially dangerous Python code. File:
references/gpu.md:168Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/scheduled-jobs.md at line 141 contains potentially dangerous Python code. File:
references/scheduled-jobs.md:141Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in references/web-endpoints.md at line 149 contains potentially dangerous Python code. File:
references/web-endpoints.md:149Remediation: Review the code block for security implications.
pathml — 🟠 HIGH
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify the 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills specification, their absence means there are no declared restrictions on which agent tools this skill may invoke. Given that the skill's reference documentation includes code patterns for file I/O, network calls (DeepCell remote API, external URLs), and distributed processing (Dask), explicit tool declarations would improve transparency and security posture. File:
SKILL.mdRemediation: Consider adding 'allowed-tools' to the YAML frontmatter to explicitly declare which agent tools are needed (e.g., Python, Bash, Read, Write). This improves auditability and limits unintended tool use. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/data_management.md at line 441 contains potentially dangerous Python code. File:
references/data_management.md:441Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesStatic analysis flagged multiple Python code blocks containing eval/exec patterns across the reference documentation files. Upon review, these appear to be legitimate educational code examples demonstrating PyTorch model training, ONNX export, and pathology image processing workflows. The eval/exec references are within illustrative code snippets (e.g., model evaluation loops using model.eval(), torch.no_grad() contexts) rather than malicious injection patterns. The term 'eval' in these contexts refers to PyTorch's model.eval() method for switching to inference mode, not Python's built-in eval() function for arbitrary code execution. No actual dangerous eval()/exec() calls with user-controlled input were identified. File:
references/machine_learning.mdRemediation: No immediate action required. The flagged patterns are false positives from static analysis detecting 'eval' as a substring in legitimate PyTorch API calls (model.eval()). If actual Python eval()/exec() with user-controlled input were present, they should be replaced with safe alternatives. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/machine_learning.md at line 228 contains potentially dangerous Python code. File:
references/machine_learning.md:228Remediation: Review the code block for security implications. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/machine_learning.md at line 498 contains potentially dangerous Python code. File:
references/machine_learning.md:498Remediation: Review the code block for security implications. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/machine_learning.md at line 540 contains potentially dangerous Python code. File:
references/machine_learning.md:540Remediation: Review the code block for security implications. -
🔵 LOW
LLM_DATA_EXFILTRATION— Remote API Call Pattern in Reference DocumentationThe multiparametric imaging reference documents a SegmentMIFRemote transform that makes outbound HTTP calls to the DeepCell cloud API (https://deepcell.org/api/predict). While this is a documented, legitimate third-party service for cell segmentation, users should be aware that slide image data (or derived representations) would be transmitted to an external server. The skill instructions do not explicitly warn users about this data transmission. File:
references/multiparametric.mdRemediation: Add a clear warning in the skill instructions noting that SegmentMIFRemote transmits image data to an external API. Recommend users use the local SegmentMIF variant for sensitive or proprietary pathology data. Document data handling policies of the external service.
polars — 🟠 HIGH
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify the 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill can invoke. Given the skill instructs the agent to load multiple reference files and potentially execute Python code examples, declaring tool restrictions would improve security posture. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML frontmatter to explicitly declare which tools are needed (e.g., [Read, Python]) and add a 'compatibility' field to document supported environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionThe SKILL.md instructs users to install Polars via 'uv pip install polars' without specifying a version pin. This could expose users to supply chain risks if a malicious version of the polars package were published to PyPI, as the latest version would always be installed. File:
SKILL.mdRemediation: Pin the polars package to a specific known-good version, e.g., 'uv pip install polars==1.x.x', and document the tested version in the skill manifest. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in a Python code block within the skill's reference documentation. After reviewing all referenced files, the eval/exec pattern appears to be a false positive or is present in documentation examples rather than executable attack code. The reference files contain standard Polars API usage with no evidence of eval/exec being used to process untrusted input. This is noted as informational. File:
references/best_practices.mdRemediation: Review the full content of any unretrieved files (templates/, assets/ directories) to confirm no eval/exec patterns exist. If eval/exec is present in examples, add a warning comment clarifying it is illustrative only. -
🔵 LOW
LLM_DATA_EXFILTRATION— Cloud Credential Handling in Documentation ExamplesThe io_guide.md reference file contains examples showing how to set AWS, Azure, and GCP credentials via environment variables (os.environ). While this is standard documentation for cloud storage usage, the examples show setting credentials like AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AZURE_STORAGE_ACCOUNT_KEY directly in code. Users following these examples may inadvertently hardcode credentials in their scripts. File:
references/io_guide.mdRemediation: Add explicit warnings in the documentation that credentials should never be hardcoded. Recommend using IAM roles, credential files, or secrets managers instead of setting environment variables directly in code. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/operations.md at line 531 contains potentially dangerous Python code. File:
references/operations.md:531Remediation: Review the code block for security implications.
pytorch-lightning — 🟠 HIGH
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may invoke. Given that the skill includes executable Python scripts and references to external logging services (W&B, MLflow, Neptune, Comet), declaring allowed tools would improve transparency and reduce the risk of unintended tool use. File:
SKILL.mdRemediation: Add 'allowed-tools: [Read, Python]' and a 'compatibility' field to the YAML frontmatter to explicitly declare the skill's intended tool usage scope. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/lightning_module.md at line 444 contains potentially dangerous Python code. File:
references/lightning_module.md:444Remediation: Review the code block for security implications. -
🔵 LOW
LLM_DATA_EXFILTRATION— External Logging Service Credentials Referenced Without GuidanceThe skill's documentation and scripts reference multiple external logging platforms (Weights & Biases, MLflow, Neptune, Comet) that require API keys or credentials. The logging.md reference file shows 'api_key: YOUR_API_KEY' patterns for CometLogger and NeptuneLogger. While no hardcoded secrets are present in the provided files, the skill instructs users to configure these credentials without explicit guidance on secure credential management (e.g., environment variables vs. hardcoded values). A user following these templates could inadvertently hardcode API keys. File:
references/logging.mdRemediation: Update documentation examples to use environment variables (e.g., os.environ.get('COMET_API_KEY')) instead of placeholder strings, and add a security note advising against hardcoding API keys in source files. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Python Code Blocks (Static Analyzer Flag)The static pre-scan flagged a potential eval/exec usage in a Python code block. After thorough review of all provided Python scripts (template_lightning_module.py, quick_trainer_setup.py, template_datamodule.py) and all referenced markdown files, no actual eval() or exec() calls were found in the skill's code. The flag may be a false positive from pattern matching within documentation examples or comments. No exploitable command injection vector was identified in the actual executable code. File:
scripts/template_lightning_module.pyRemediation: No immediate action required. Confirm the static analyzer finding by reviewing any additional files not shown. If eval/exec appears in documentation examples, ensure they are clearly marked as illustrative only and not executed by the agent.
qutip — 🟠 HIGH
-
🔵 LOW
LLM_DATA_EXFILTRATION— Multiple Referenced Files Not Found in PackageThe skill references numerous files that are not present in the package (assets/core_concepts.md, qutip.py, templates/analysis.md, matplotlib.py, assets/analysis.md, assets/advanced.md, assets/time_evolution.md, templates/time_evolution.md, assets/visualization.md, templates/core_concepts.md, templates/visualization.md, templates/advanced.md). The absence of these files means the skill is incomplete. If these files were to be added later by a third party or fetched from an external source, they could introduce malicious content without review. File:
SKILL.mdRemediation: Ensure all referenced files are bundled with the skill package. Do not fetch missing files from external sources at runtime. Audit any files added to fill these gaps before deployment. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and allowed-tools MetadataThe SKILL.md manifest does not specify 'compatibility' or 'allowed-tools' fields. While these are optional per the spec, their absence means the agent has no declared constraints on which tools this skill may invoke, and users cannot verify compatibility claims. This is an informational finding only. File:
SKILL.mdRemediation: Add 'compatibility' and 'allowed-tools' fields to the YAML frontmatter to improve transparency and allow the agent runtime to enforce tool restrictions. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe SKILL.md instructs users to install qutip and optional packages using 'uv pip install qutip' without version pinning. This means the skill will always install the latest available version, which could introduce breaking changes or supply chain risks if the package is compromised or a malicious version is published. File:
SKILL.mdRemediation: Pin package versions explicitly, e.g., 'uv pip install qutip==5.0.4' to ensure reproducibility and reduce supply chain risk. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a Python code block using eval/exec. Reviewing the referenced files, the code examples in the skill documentation use standard QuTiP API calls and numpy/matplotlib operations. No direct eval/exec calls with user-controlled input were found in the reviewed content. The flagged pattern appears to be a false positive from the static scanner detecting Python code blocks generically. No actual command injection risk was identified in the reviewed content. File:
references/advanced.mdRemediation: No action required. The code examples are standard scientific Python and do not use eval/exec with untrusted input. Verify the unreferenced/missing files (assets/, templates/) do not contain eval/exec patterns if they are added to the package. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/visualization.md at line 197 contains potentially dangerous Python code. File:
references/visualization.md:197Remediation: Review the code block for security implications.
sympy — 🟠 HIGH
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe SKILL.md manifest does not specify the allowed-tools field. While this is an optional field per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be invoked. Given that this skill guides the agent to execute Python code and interact with files (e.g., writing LaTeX to output.tex, pickling expressions), declaring allowed-tools would improve transparency and reduce the attack surface. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the YAML frontmatter, such as: allowed-tools: [Python, Read, Write]. This makes the skill's intended capabilities explicit and allows the agent runtime to enforce restrictions. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Multiple Missing Referenced FilesThe skill references numerous files that do not exist in the package: assets/physics-mechanics.md, templates/core-capabilities.md, scipy.py, templates/advanced-topics.md, templates/code-generation-printing.md, assets/core-capabilities.md, templates/physics-mechanics.md, matplotlib.py, assets/matrices-linear-algebra.md, sympy.py, templates/matrices-linear-algebra.md, assets/code-generation-printing.md, assets/advanced-topics.md. This creates an incomplete and inconsistent package. Missing files could cause the agent to behave unpredictably or attempt to fetch content from external sources to fill the gap. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package before distribution. Remove references to files that do not exist, or add placeholder files with appropriate content. Audit the SKILL.md instructions to remove or update broken references. -
🔵 LOW
LLM_COMMAND_INJECTION— eval() Usage in Code Generation Reference FileThe references/code-generation-printing.md file contains a code example that uses eval() to recreate SymPy expressions from their string representation (srepr output). While this is presented as a documentation example rather than executable agent code, it demonstrates a pattern that could be dangerous if user-supplied strings are passed to eval() without sanitization. The same file also includes a 'Pattern 3: Interactive Computation' that uses parse_expr() on user input, with a comment noting the need to validate and sanitize to avoid code injection vulnerabilities. File:
references/code-generation-printing.mdRemediation: The skill documentation should explicitly warn against using eval() on user-supplied input. The parse_expr() pattern should include sandboxing guidance (e.g., using local_dict/global_dict restrictions in parse_expr to limit available symbols). Add a security note that parse_expr with untrusted input should use transformations and restricted namespaces. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/code-generation-printing.md at line 204 contains potentially dangerous Python code. File:
references/code-generation-printing.md:204Remediation: Review the code block for security implications.
torch-geometric — 🟠 HIGH
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Activation Description with Keyword BaitingThe skill description contains an unusually large number of trigger keywords and activation conditions, including very broad terms like 'graph learning' and 'geometric deep learning'. The description explicitly instructs the agent to activate 'Even if the user just says graph learning or geometric deep learning', which is an attempt to maximize activation frequency beyond what is necessary for the skill's stated purpose. While this is a legitimate educational skill, the breadth of activation triggers constitutes mild capability inflation and keyword baiting. File:
SKILL.mdRemediation: Narrow the activation description to the core use case (PyTorch Geometric / PyG usage). Remove the explicit instruction to trigger on very broad terms like 'graph learning' or 'geometric deep learning' that could cause the skill to activate in unintended contexts. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While these are optional fields, their absence means there is no provenance information for the skill package. Combined with the missing license, it is harder to verify the origin and trustworthiness of the skill. This is an informational finding with no direct security impact. File:
SKILL.mdRemediation: Add license, compatibility, and allowed-tools fields to the YAML frontmatter to improve transparency and provenance tracking. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in SKILL.md at line 196 contains potentially dangerous Python code. File:
SKILL.md:196Remediation: Review the code block for security implications. -
🔵 LOW
LLM_DATA_EXFILTRATION— External URL in Dataset Download ExampleThe references/custom_datasets.md file contains an example that calls download_url('https://example.com/data.csv', self.raw_dir), which downloads data from an external URL. While this is a placeholder example URL and is standard PyG dataset pattern, it demonstrates a pattern where the agent could be instructed to download data from arbitrary external URLs as part of dataset creation workflows. The URL is a placeholder (example.com) and not a real exfiltration endpoint. File:
references/custom_datasets.mdRemediation: Add a comment in the example noting that production code should validate URLs against an allowlist before downloading, and that users should only download from trusted, verified sources. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/link_prediction.md at line 94 contains potentially dangerous Python code. File:
references/link_prediction.md:94Remediation: Review the code block for security implications. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/link_prediction.md at line 137 contains potentially dangerous Python code. File:
references/link_prediction.md:137Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage in Educational Code BlocksStatic analysis flagged multiple Python code blocks containing eval or exec patterns. Review of the referenced files (references/custom_datasets.md, references/scaling.md, references/message_passing.md, references/heterogeneous.md, references/link_prediction.md, references/explainability.md) shows these are all legitimate educational code examples demonstrating PyTorch Geometric APIs. No actual eval/exec calls were found in the code examples — the static scanner likely flagged patterns within string literals or comments. The code blocks do not pass user-controlled input to eval/exec. This is a low-severity informational finding. File:
references/message_passing.mdRemediation: Review the specific lines flagged by the static analyzer to confirm no eval/exec calls accept user-controlled input. If any such patterns exist in example code, add comments warning users not to use eval/exec with untrusted data in production code.
torchdrug — 🟠 HIGH
-
🔵 LOW
LLM_DATA_EXFILTRATION— File System Access to Home Directory in Code ExamplesMultiple code examples reference paths under the user's home directory (e.g., '
/molecule-datasets/', '/protein-datasets/', '/kg-datasets/', '/retro-datasets/', '~/datasets/'). While these are illustrative examples for dataset loading and not automated exfiltration, they normalize writing to and reading from the home directory without explicit user confirmation in the workflow descriptions. Remediation: Add a note in the skill instructions clarifying that dataset paths should be explicitly confirmed with the user before use, and that the agent should not autonomously create directories or download data to the home directory without user approval. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill can invoke. Given the skill instructs users to run Python code (training loops, data loading, file I/O to ~/molecule-datasets/, ~/protein-datasets/, etc.), declaring allowed tools would improve transparency and security posture. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Read, Write]' and a compatibility field to the SKILL.md manifest to clearly declare the skill's intended tool usage scope. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation in Code ExamplesThe installation instructions use 'uv pip install torchdrug' and 'uv pip install torchdrug[full]' without version pinning. This means the skill could install any version of torchdrug, including potentially compromised future versions. While this is a documentation/example pattern rather than an automated install script, users following these instructions are exposed to supply chain risk. File:
SKILL.mdRemediation: Pin the torchdrug version in installation examples, e.g., 'uv pip install torchdrug==0.3.1'. Also recommend users verify package integrity via checksums or trusted sources. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/core_concepts.md at line 345 contains potentially dangerous Python code. File:
references/core_concepts.md:345Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in a Python code block within the skill's reference files. After reviewing all provided content, the code examples in the reference files (molecular_property_prediction.md, molecular_generation.md, models_architectures.md, retrosynthesis.md, datasets.md, protein_modeling.md, core_concepts.md, knowledge_graphs.md) do not contain explicit eval() or exec() calls. The flagged pattern may be a false positive from the static analyzer detecting dynamic-looking constructs. No actual eval/exec injection risk was found in the reviewed content. File:
references/molecular_property_prediction.mdRemediation: Review the actual file contents for any eval/exec usage. If present in code examples, add a note warning users about the risks of using eval/exec with untrusted input in their own implementations.
transformers — 🟠 HIGH
-
🔵 LOW
LLM_DATA_EXFILTRATION— Hugging Face Token Exposed in Example CodeThe SKILL.md instruction body contains an example showing how to set a Hugging Face token via environment variable with a placeholder value 'your_token_here'. While this is a documentation placeholder and not a real credential, the pattern of embedding token handling instructions could lead users to inadvertently hardcode real tokens in scripts. The compatibility field also mentions 'Some features require a Huggingface token', indicating token usage is expected. File:
SKILL.mdRemediation: Add explicit warnings in the documentation that tokens should never be hardcoded in scripts. Recommend using .env files with .gitignore, or the huggingface_hub login() interactive flow rather than environment variable export in shell history. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools DeclarationThe skill manifest does not specify the 'allowed-tools' field. While this field is optional per the agent skills specification, the skill instructs the agent to execute bash commands (pip installs, tensorboard commands) and Python code. Declaring allowed-tools would improve transparency about what capabilities the skill requires. File:
SKILL.mdRemediation: Add 'allowed-tools: [Bash, Python]' to the YAML frontmatter to explicitly declare the tools this skill requires, improving transparency and enabling tool restriction enforcement. -
🟠 HIGH
MDBLOCK_PYTHON_EVAL_EXEC— Python code block uses eval/execCode block in references/models.md at line 214 contains potentially dangerous Python code. File:
references/models.md:214Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the referenced markdown files. After reviewing all referenced files (references/training.md, references/pipelines.md, references/generation.md, references/models.md, references/tokenizers.md), no actual eval() or exec() calls were found in the code examples. The flag appears to be a false positive from the static analyzer. The code examples use standard transformers library patterns without dynamic code execution. This is noted as LOW severity for awareness. File:
references/tokenizers.mdRemediation: No action required. The static analyzer flag appears to be a false positive. Continue to ensure that any future code examples added to reference files avoid eval/exec patterns with user-controlled input.
bgpt-paper-search — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_PROMPT_INJECTION— Indirect Prompt Injection Risk via Remote MCP Server ResponsesThe skill retrieves structured paper data (methods, results, conclusions, 25+ fields) from a remote MCP server. This externally-sourced content is rich text that could contain embedded prompt injection payloads. If the BGPT server (or a compromised version of it) returns paper content containing adversarial instructions, the agent may process and act on those instructions as if they were legitimate. File:
SKILL.mdRemediation: The agent should treat all content returned by the remote MCP server as untrusted data, not as instructions. Implement output sanitization or clearly scope the agent's behavior to only summarize/display returned content without acting on any embedded directives. Users should be aware that free-tier results (50 searches per network, no API key) may be less vetted than paid results. -
🟡 MEDIUM
LLM_UNAUTHORIZED_TOOL_USE— External MCP Server Dependency with Unverified TrustThe skill instructs the agent to connect to and use a remote MCP server at https://bgpt.pro/mcp/sse. This external server is outside the user's control and could return malicious tool responses, manipulated data, or instructions that the agent may act upon. The agent is directed to use the
search_paperstool provided by this third-party server, meaning the server controls the tool's behavior and output entirely. File:SKILL.mdRemediation: Users should verify the trustworthiness of bgpt.pro before configuring this MCP server. Consider reviewing the open-source repository at https://github.com/connerlambden/bgpt-mcp to audit server behavior. Treat all data returned by the remote MCP server as untrusted input and avoid allowing the agent to autonomously act on structured data returned without user review. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Broad Capability Claims Without Verification MechanismThe skill description claims to return '25+ fields per paper including methods, results, sample sizes, quality scores, and conclusions' from 'full-text studies.' These are significant claims about data quality and completeness that cannot be independently verified by the agent or user. Over-reliance on these quality claims (e.g., 'quality scores', 'evidence grading') could lead to misplaced trust in the returned data for clinical or research decisions. File:
SKILL.mdRemediation: Users should independently verify paper data against original sources before using for clinical guidelines or meta-analyses. The skill should include a disclaimer that returned quality scores are generated by the BGPT service and not independently validated. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned npx Package Execution for Remote MCP ClientThe skill uses
npx mcp-remoteandnpx bgpt-mcpwithout version pinning. This means the latest version of these npm packages is fetched and executed at runtime. A compromised or maliciously updated version ofmcp-remoteorbgpt-mcpon npm could introduce malicious behavior without the user's knowledge. File:SKILL.mdRemediation: Pin specific versions of npm packages (e.g.,npx mcp-remote@1.2.3) to prevent supply chain attacks via package updates. Periodically audit the packages for known vulnerabilities or unexpected changes.
clinical-reports — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Mandatory Cross-Skill Dependency Injection via 'scientific-schematics' SkillThe SKILL.md instruction body contains a mandatory directive requiring the agent to invoke an external skill ('scientific-schematics') for every clinical report generated. The instruction is marked '⚠️ MANDATORY' and states 'Every clinical report MUST include at least 1 AI-generated figure using the scientific-schematics skill.' This creates an undisclosed cross-skill dependency that inflates the activation surface and forces invocation of a separate, unvetted skill. The manifest description does not disclose this dependency. The referenced 'Nano Banana Pro' branding suggests a commercial product ecosystem, and the mandatory invocation pattern could be used to force activation of a companion skill with unknown security properties. File:
SKILL.mdRemediation: Remove the mandatory cross-skill invocation requirement. If integration with scientific-schematics is desired, it should be optional, disclosed in the manifest description, and the security properties of the dependent skill should be independently verified. The manifest's allowed-tools and description should accurately reflect all external dependencies. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Iterative Refinement Loop in External Schematic GenerationThe SKILL.md instructions describe the scientific-schematics skill as automatically performing 'multiple iterations' of review and refinement: 'Review and refine through multiple iterations.' This unbounded iterative process, triggered mandatorily for every clinical report, could result in excessive compute consumption. There is no specified maximum iteration count, timeout, or termination condition described in the instructions. File:
SKILL.mdRemediation: If the scientific-schematics integration is retained, specify a maximum number of refinement iterations and a timeout condition. Add explicit termination criteria to prevent unbounded loops. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Bash Script Execution Capability for Schematic Generation with External Tool DependencyThe SKILL.md instructions include a bash command template for invoking an external script: 'python scripts/generate_schematic.py "your diagram description" -o figures/output.png'. This script is not included in the skill package (it is referenced as part of the 'scientific-schematics' skill). The agent is instructed to execute this bash command as part of mandatory report generation. Executing scripts from an external, unverified skill package via Bash (which is in allowed-tools) could allow the scientific-schematics skill to perform arbitrary operations on the user's system. The security properties of the external script are unknown. File:
SKILL.mdRemediation: Remove the bash command template that references an external skill's scripts. If cross-skill integration is needed, it should be done through documented, sandboxed interfaces rather than direct script execution. The allowed-tools declaration should be reviewed to determine if Bash access is necessary for the core clinical report writing functionality. -
🔵 LOW
LLM_DATA_EXFILTRATION— PHI Placeholder Fields in Template Files May Persist Into Agent-Generated OutputMultiple template files (assets/discharge_summary_template.md, assets/radiology_report_template.md, assets/soap_note_template.md, assets/consult_note_template.md, assets/history_physical_template.md, assets/pathology_report_template.md, assets/clinical_trial_sae_template.md, assets/case_report_template.md, assets/lab_report_template.md) contain explicit placeholder fields for Protected Health Information (PHI) including patient names, MRNs, dates of birth, telephone numbers, and other HIPAA identifiers. While these are templates, the agent is instructed to 'Load these resources as needed when working on specific clinical reports,' meaning the agent may populate these fields with real patient data. There are no technical controls preventing the agent from writing completed reports containing real PHI to disk or transmitting them. The skill's write access (allowed-tools includes Write) combined with PHI-structured templates creates a risk of PHI being written to local files without adequate safeguards. File:
assets/clinical_trial_sae_template.mdRemediation: Add explicit instructions in SKILL.md that completed reports containing real PHI must not be written to disk without explicit user confirmation and appropriate security controls. Consider adding a warning in the instructions that the agent should confirm with the user before writing any file containing patient data. The skill should also note that it is not a HIPAA-compliant system and cannot guarantee secure storage of PHI.
database-lookup — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Key Harvesting from Environment Variables and .env FilesThe skill instructions explicitly direct the agent to read API keys from shell environment variables and .env files in the current working directory. While this is a common pattern, the skill aggregates credentials for 18+ different services (FRED, BEA, BLS, NCBI, OpenFDA, USPTO, NASA, NOAA, OpenWeatherMap, OMIM, BioGRID, Alpha Vantage, US Census, DisGeNET, Addgene, LINCS L1000, Materials Project, Data Commons). The static analyzer flagged cross-file environment variable exfiltration chains. If any of the referenced files (templates/, assets/, references/) contain malicious instructions, they could redirect these harvested credentials to attacker-controlled endpoints. File:
SKILL.mdRemediation: Limit credential access to only the specific API keys needed for the current query rather than proactively reading all available keys. Avoid reading .env files unless strictly necessary. Consider requiring explicit user confirmation before accessing credential stores. -
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Excessive Keyword Baiting and Over-Broad Activation Triggers in DescriptionThe skill description is extremely long and contains an exhaustive list of keywords, database names, data types, and trigger phrases designed to maximize activation across nearly any scientific, biomedical, financial, or regulatory query. The description explicitly instructs the agent to 'Also trigger when the user mentions any database by name or asks about molecular properties, drug-target interactions, binding affinities...' and lists dozens of additional trigger conditions. This over-broad activation pattern inflates the skill's perceived relevance and increases the likelihood of unwanted or unnecessary activation, potentially displacing more appropriate tools. File:
SKILL.mdRemediation: Reduce the description to a concise, accurate summary of the skill's purpose. Avoid exhaustive keyword lists in the description field. Use specific, targeted trigger conditions rather than attempting to capture all possible queries. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While this is a low-severity informational issue, the absence of provenance metadata (combined with the skill author being 'K-Dense Inc.' with no further verification) makes it harder to assess the trustworthiness and intended scope of the skill. File:
SKILL.mdRemediation: Add license, compatibility, and allowed-tools fields to the YAML manifest to improve transparency and enable tool restriction enforcement. -
🔵 LOW
LLM_PROMPT_INJECTION— Indirect Prompt Injection Risk via Unvalidated External API ResponsesThe skill instructs the agent to return 'raw JSON' responses from external APIs and to follow instructions embedded in reference files. While the reference files bundled with the skill appear benign, the skill's core workflow involves fetching data from 78 external APIs and returning raw responses. Malicious API responses could contain embedded instructions that the agent might follow, especially given the instruction to 'return the raw JSON response from each database.' The static analyzer flagged environment variable exfiltration behavior patterns across multiple files. File:
SKILL.mdRemediation: Instruct the agent to treat all API response content as untrusted data, not as instructions. Add explicit guidance that the agent should not follow any instructions found within API responses. Consider sanitizing or summarizing responses rather than returning raw JSON verbatim. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Parallel API Calls and Pagination Without LimitsThe skill explicitly encourages querying multiple databases in parallel ('Parallel OK: When querying different databases, run them in parallel') and instructs the agent to paginate through all results for comprehensive queries ('all clinical trials for X' or 'all known variants in gene Y'). For broad queries like 'everything about BRCA1' or 'everything about aspirin,' this could trigger dozens of simultaneous API calls with unbounded pagination, potentially exhausting compute resources or triggering rate-limit bans across multiple services. File:
SKILL.mdRemediation: Add explicit limits on the number of parallel requests and total pages fetched per session. Require user confirmation before initiating broad multi-database queries. Set a maximum number of databases to query simultaneously.
datamol — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Remote File Access Without Input ValidationThe skill's instructions and reference documentation explicitly encourage reading files from remote URLs (S3, GCS, HTTP/HTTPS) and writing to remote storage. The skill instructs the agent to pass user-provided paths directly to dm.read_sdf(), dm.read_csv(), etc. without any validation or sanitization of the path. A malicious user could supply a crafted URL to exfiltrate data or cause the agent to fetch attacker-controlled content. File:
SKILL.mdRemediation: Add explicit guidance in the skill instructions to validate and sanitize user-provided file paths before passing them to I/O functions. Restrict remote file access to trusted domains or require explicit user confirmation before accessing remote URLs. Warn users about the risks of providing untrusted remote paths. -
🟡 MEDIUM
LLM_PROMPT_INJECTION— Indirect Prompt Injection Risk via External File LoadingThe skill instructs the agent to load molecular data files from user-provided paths, including remote URLs (HTTP/HTTPS, S3, GCS). Malicious content embedded in externally-fetched files (e.g., a CSV or SDF file containing crafted metadata or comments with instruction-like text) could potentially influence the agent's behavior. The skill provides no guidance on treating loaded file content as untrusted data. File:
SKILL.mdRemediation: Add explicit guidance that content loaded from external files should be treated as untrusted data. Instruct the agent not to interpret or execute any text found in loaded molecular data files as instructions. Consider sandboxing file parsing operations. -
🔵 LOW
LLM_DATA_EXFILTRATION— Several Referenced Files Are MissingMultiple files referenced in the SKILL.md instructions are not present in the skill package. Missing files include: assets/descriptors_viz.md, sklearn.py, templates/conformers_module.md, templates/descriptors_viz.md, templates/reactions_data.md, scipy.py, templates/core_api.md, assets/reactions_data.md, assets/core_api.md, rdkit.py, assets/io_module.md, templates/fragments_scaffolds.md, datamol.py, templates/io_module.md, assets/fragments_scaffolds.md, assets/conformers_module.md. The presence of Python file references (sklearn.py, scipy.py, rdkit.py, datamol.py) that are not found is notable, as these could be scripts intended to be bundled with the skill. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package. If the Python files (sklearn.py, scipy.py, rdkit.py, datamol.py) are intended as helper scripts, include them and review their contents for security issues. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe skill does not specify the 'allowed-tools' field in its YAML manifest. While this is optional per the agent skills spec, documenting which tools are required (Python, Bash, Read, Write, etc.) improves transparency and helps users understand the skill's intended scope. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' field to the YAML frontmatter listing the tools this skill requires, e.g., allowed-tools: [Python, Bash, Read]. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill does not specify the 'compatibility' field in its YAML manifest. This reduces transparency about which agent environments the skill is designed to work with. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter specifying supported environments (e.g., Claude.ai, Claude Code, API).
deepchem — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill does not declare an 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be used. The scripts execute Python code, load files, and make network calls to download pretrained models from HuggingFace and external sources. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' declaration to the YAML frontmatter to document which tools the skill requires, e.g., allowed-tools: [Python, Bash, Read, Write]. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in ManifestThe YAML manifest does not specify a 'compatibility' field. The skill makes network calls to download models from HuggingFace and writes model checkpoints to local directories (e.g., './grover_pretrained'). Users may not be aware of these network and filesystem requirements when deploying the skill in restricted environments. File:
SKILL.mdRemediation: Add a compatibility field documenting network requirements, disk space needs, and supported environments. Disclose that the skill requires internet access for model downloads. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionsThe SKILL.md installation instructions use 'uv pip install deepchem', 'uv pip install deepchem[torch]', and 'uv pip install deepchem[all]' without pinning to specific versions. This exposes the skill to supply chain attacks where a compromised version of deepchem or its transitive dependencies could be installed. File:
SKILL.mdRemediation: Pin the deepchem package to a specific known-good version, e.g., 'uv pip install deepchem==2.7.1'. Consider providing a requirements.txt or pyproject.toml with pinned dependencies and hash verification. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Network Access to External Model Repositories Without ValidationThe transfer_learning.py script downloads pretrained models from HuggingFace (seyonec/ChemBERTa-zinc-base-v1, ibm/MoLFormer-XL-both-10pct) and Rostlab/prot_bert at runtime. These external model downloads are not pinned to specific versions or checksums, meaning a compromised or updated model on HuggingFace could introduce malicious behavior. The SKILL.md description does not explicitly disclose that external model downloads will occur. File:
scripts/transfer_learning.py:44Remediation: Pin model versions using specific commit hashes or model revision identifiers. Disclose in SKILL.md that external model downloads will occur. Consider verifying model checksums after download.
depmap — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Potential Environment Variable Access Combined with Network Calls (Static Analyzer Alert)The pre-scan static analysis flagged cross-file environment variable exfiltration chains across 4 files (BEHAVIOR_ENV_VAR_EXFILTRATION and BEHAVIOR_CROSSFILE_ENV_VAR_EXFILTRATION). While the provided SKILL.md instructions and inline code snippets do not explicitly show environment variable harvesting, the static analyzer detected this pattern in the broader skill package (14 files total: 6 Python, 7 markdown). The combination of env var access and outbound network calls is a high-risk pattern for credential exfiltration. The full Python scripts were not provided for review, which limits complete analysis. File:
SKILL.mdRemediation: Audit all 6 Python files in the skill package for environment variable access (os.environ, os.getenv) combined with outbound HTTP requests. Remove any code that reads credentials or environment variables and transmits them externally. Ensure network calls are limited to the declared DepMap API endpoints only. -
🔵 LOW
LLM_DATA_EXFILTRATION— External Data Download Without Integrity VerificationThe skill instructs downloading large data files from external sources (figshare.com, depmap.org) without any checksum verification or integrity checks. The download_depmap_data function streams files directly to disk without validating content authenticity, which could expose the agent to tampered or malicious data files if the download source is compromised. File:
SKILL.mdRemediation: Add checksum verification (SHA256) for downloaded files. Compare against known-good hashes published by DepMap. Use HTTPS and verify SSL certificates. Consider pinning expected file sizes or hashes. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and Allowed-Tools MetadataThe skill does not specify 'compatibility' or 'allowed-tools' fields in the YAML manifest. While optional, these fields help constrain the skill's execution environment and prevent unintended tool usage. The skill makes network requests and writes files to disk, which should be explicitly declared. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash]' and 'compatibility' fields to the YAML frontmatter to explicitly declare the skill's required capabilities and supported environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Dependency Version PinningThe skill references external Python packages (requests, pandas, scipy, numpy) without specifying version constraints. Unpinned dependencies are vulnerable to supply chain attacks where a malicious version of a package could be installed. The referenced file 'scipy.py' is also not found, suggesting incomplete dependency documentation. File:
SKILL.mdRemediation: Provide a requirements.txt with pinned versions (e.g., requests==2.31.0, pandas==2.1.0, scipy==1.11.0). Document exact dependency versions in the skill manifest.
docx — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe SKILL.md manifest does not declare an allowed-tools field. The skill executes Python scripts, Bash commands (via subprocess), compiles C code with gcc, and runs LibreOffice. Without an explicit allowed-tools declaration, the agent's tool usage is unconstrained and not auditable from the manifest alone. File:
SKILL.mdRemediation: Add an explicit allowed-tools field to the YAML frontmatter listing the tools actually used, e.g.: allowed-tools: [Python, Bash]. This improves transparency and allows runtime enforcement of tool restrictions. -
🔵 LOW
LLM_COMMAND_INJECTION— Subprocess Calls with User-Influenced File PathsMultiple scripts (accept_changes.py, soffice.py, redlining.py) pass file paths to subprocess calls (soffice, git, gcc). While the paths are derived from script arguments rather than direct user input injected into shell strings, and subprocess.run is used with list arguments (not shell=True), the input_file and output_file arguments in accept_changes.py come from command-line arguments that could be influenced by the agent acting on user-provided document paths. There is no path sanitization or validation beyond checking file existence and extension. File:
scripts/accept_changes.pyRemediation: Validate that file paths are within expected directories before passing to subprocess. Use pathlib.Path.resolve() and check that the resolved path is within an allowed base directory. The f-string interpolation of LIBREOFFICE_PROFILE into the -env argument is safe since it is a hardcoded constant, but document this explicitly. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— Dynamic C Code Compilation and LD_PRELOAD InjectionThe soffice.py script contains an embedded C source string (_SHIM_SOURCE) that is written to a temp file, compiled with gcc at runtime, and then loaded via LD_PRELOAD into LibreOffice subprocess calls. This pattern intercepts socket(), listen(), accept(), and close() system calls. While the stated purpose is to work around AF_UNIX socket restrictions in sandboxed environments, this technique is a classic method for injecting malicious code into processes. If the temp directory is writable by an attacker, or if the C source is modified, arbitrary code could be executed with the privileges of the agent. File:
scripts/office/soffice.pyRemediation: Avoid runtime compilation of C code. If a socket shim is truly necessary, ship it as a pre-compiled binary with a checksum verification step, or use a pure-Python alternative. At minimum, verify the compiled .so file does not already exist before writing (currently done) and ensure the temp directory has appropriate permissions. Consider whether this shim is necessary at all in the deployment environment. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Environment Variable Access Combined with Network CallsThe soffice.py script calls os.environ.copy() to capture the full environment and passes it to subprocess calls running LibreOffice. While this is a legitimate pattern for propagating environment to child processes, the static analyzer flagged this as a potential exfiltration chain because the environment (which may contain secrets, API keys, tokens) is copied and passed to external processes. The LD_PRELOAD shim is also compiled and loaded dynamically, which could intercept system calls. In isolation each step is defensible, but the combination of env capture + dynamic shared library injection + subprocess execution warrants scrutiny. File:
scripts/office/soffice.pyRemediation: Restrict the environment passed to subprocess calls to only the variables actually needed by LibreOffice (e.g., HOME, PATH, DISPLAY, SAL_USE_VCLPLUGIN, LD_PRELOAD). Do not pass the full os.environ to child processes. Document clearly why LD_PRELOAD is needed and validate the shim source has not been tampered with. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded XML File Processing Without Size LimitsThe unpack.py, pack.py, and validator scripts process all XML files found recursively in a directory without any file size limits or count limits. A maliciously crafted or extremely large DOCX file could cause excessive memory consumption or CPU exhaustion during XML parsing, pretty-printing, and validation. The merge_runs.py and simplify_redlines.py scripts also perform recursive DOM traversal without depth limits. File:
scripts/office/unpack.pyRemediation: Add file size limits before processing (e.g., skip files larger than a reasonable threshold like 50MB). Add a maximum file count check. Consider using streaming XML parsers for large files rather than loading entire DOM into memory.
fluidsim — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Referenced Script File (fluidsim.py)The skill references a file 'fluidsim.py' in its file inventory but this file was not found. A missing script file that is referenced in the skill package creates uncertainty about what code may be executed. If this file is intended to be present but is absent, it could indicate an incomplete or tampered package. The name 'fluidsim.py' could also shadow the installed 'fluidsim' package in Python's import resolution. File:
SKILL.mdRemediation: Either include the fluidsim.py file in the package with its full contents for review, or remove the reference if it is not needed. Be aware that a local file named 'fluidsim.py' will shadow the installed fluidsim package in Python imports, which could cause unexpected behavior or be exploited for dependency confusion attacks. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools DeclarationThe SKILL.md manifest does not declare an 'allowed-tools' field. The skill instructs the agent to execute bash commands (uv pip install, mpirun, pytest) and Python code, but does not formally declare which agent tools are permitted. While this field is optional per the spec, its absence means there are no declared restrictions on tool usage for a skill that performs package installation, file I/O, and process execution. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' declaration to the YAML frontmatter listing the tools actually needed (e.g., Bash, Python, Read, Write) to provide clear capability boundaries for the agent runtime. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— Dynamic Code Execution via eval/exec in Python Code BlocksThe static analyzer flagged a Python eval/exec usage within the skill's code blocks. In the advanced features documentation (references/advanced_features.md), the custom forcing section demonstrates overriding simulation methods with lambda functions and dynamic code injection patterns. While the specific eval/exec usage appears to be within legitimate scientific computing context, the pattern of overriding internal simulation methods with user-supplied callables (e.g.,
sim.forcing.forcing_maker.compute_forcing_fft = lambda: compute_forcing_fft(sim)) could be exploited if user-controlled input is passed into these dynamic code paths without sanitization. File:references/advanced_features.mdRemediation: Ensure that any user-supplied parameters or code paths that feed into dynamic method overrides are validated and sanitized. Document clearly that custom forcing functions should not incorporate unsanitized user input. Consider adding input validation wrappers around dynamic code execution patterns. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation CommandsThe installation instructions throughout the skill recommend installing fluidsim and its dependencies (fluidfft, pyfftw, mpi4py) without version pins. Unpinned installations are vulnerable to supply chain attacks where a compromised or malicious package version could be installed. The commands 'uv pip install fluidsim', 'uv pip install "fluidsim[fft]"', and 'uv pip install "fluidsim[fft,mpi]"' do not specify exact versions. File:
references/installation.mdRemediation: Pin package versions in installation commands (e.g., 'uv pip install fluidsim==0.x.y') or provide a requirements.txt with pinned versions and hash verification. This reduces the risk of inadvertently installing a compromised package version.
ginkgo-cloud-lab — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_COMMAND_INJECTION— Static Analyzer Flagged Python eval/exec Usage in Markdown Code BlocksThe static pre-scan identified two instances of Python code blocks containing eval or exec calls within the markdown files. Although no explicit eval/exec usage was found in the reviewed referenced files, the static analyzer detected these patterns across the 16 markdown files in the package. If these code blocks are executed by the agent (e.g., via a Python tool), they could enable arbitrary code execution, especially if user-supplied input is passed to eval/exec. Remediation: Audit all markdown files in the package for Python code blocks containing eval() or exec() calls. Remove or replace these with safe alternatives. Ensure the agent does not execute code blocks found in documentation files without explicit user confirmation.
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe SKILL.md manifest does not specify a license or compatibility field. While these are optional fields, their absence reduces transparency about the skill's intended usage scope and legal terms. File:
SKILL.mdRemediation: Add a license field (e.g., 'license: MIT') and a compatibility field describing supported platforms to improve transparency and provenance. -
🔵 LOW
LLM_DATA_EXFILTRATION— Several Referenced Files Not Found in PackageMultiple files referenced in the skill instructions are not present in the package: assets/cell-free-protein-expression-validation.md, assets/cell-free-protein-expression-optimization.md, assets/fluorescent-pixel-art-generation.md, templates/fluorescent-pixel-art-generation.md, templates/cell-free-protein-expression-validation.md, templates/cell-free-protein-expression-optimization.md. While these appear to be internal documentation references, their absence could cause the agent to seek them from external or user-provided sources, potentially introducing untrusted content. File:
SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package. Remove references to files that do not exist, or add the missing files to the package to prevent the agent from attempting to resolve them from external sources. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools DeclarationThe skill does not declare an allowed-tools field in its YAML manifest. While this field is optional, its absence means there are no declared restrictions on which agent tools this skill may invoke. Given the skill interacts with external web services (cloud.ginkgo.bio), declaring allowed-tools would improve security posture. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the manifest to constrain the skill's tool access surface, e.g., 'allowed-tools: [Read]' if no execution is required.
histolab — 🟡 MEDIUM
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools (Bash, Python, Read, Write, etc.) can be invoked. Given that the skill instructs the agent to execute Python code for WSI processing, file I/O, and potentially network access (downloading sample datasets from TCGA), explicit tool declarations would improve transparency and reduce the risk of unintended capability use. File:
SKILL.mdRemediation: Add 'allowed-tools' to the manifest listing the minimum required tools (e.g., Python, Read, Write). Add 'compatibility' to clarify supported environments. This improves auditability and limits unintended tool activation. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency InstallationThe skill instructs installation of histolab via 'uv pip install histolab' without specifying a version pin. This means the agent or user could install any version of the package, including potentially compromised future versions. Supply chain attacks targeting PyPI packages are a known risk vector. File:
SKILL.mdRemediation: Pin the histolab dependency to a specific known-good version (e.g., 'uv pip install histolab==0.7.0'). Consider also specifying a hash for integrity verification. Document the tested/supported version in the manifest. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— Use of eval/exec in Python Code BlocksStatic analysis flagged two instances of eval/exec usage within Python code blocks in the skill's markdown documentation. While the code blocks appear to be illustrative examples for the histolab library (image processing, tile extraction), the presence of eval/exec patterns warrants review. If an agent executes these code blocks directly, and any portion of the input to eval/exec is user-controlled or derived from untrusted data (e.g., slide file paths, filter parameters), it could lead to arbitrary code execution. File:
references/filters_preprocessing.mdRemediation: Review all code blocks containing eval/exec patterns to ensure no user-controlled input is passed to these constructs. If the code blocks are purely illustrative, add explicit warnings that user input must be sanitized before use. Avoid constructing filter pipelines or Lambda expressions from unsanitized user-provided strings. -
🔵 LOW
LLM_DATA_EXFILTRATION— Network Access for Sample Dataset DownloadsThe skill's reference documentation describes loading built-in sample datasets from TCGA (prostate_tissue(), ovarian_tissue(), breast_tissue(), etc.). These functions likely perform network requests to download data from external sources. While this is standard library behavior for histolab, the skill does not disclose this network activity in its manifest or instructions, meaning users may not be aware that executing sample workflows triggers outbound network connections. File:
references/slide_management.md:20Remediation: Document in SKILL.md that sample dataset functions perform network downloads from TCGA. Users should be informed of any outbound network activity. Consider noting this in the skill description or a dedicated 'Network Usage' section.
imaging-data-commons — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_COMMAND_INJECTION— Unpinned Package Upgrade via subprocess in SKILL.mdThe SKILL.md instruction body contains a Python code block that uses subprocess.run() to execute 'pip3 install --upgrade --break-system-packages idc-index' when the installed version is below the required version. The version comparison uses a simple string comparison (installed < REQUIRED_VERSION) rather than proper semantic version comparison, which could lead to incorrect upgrade decisions. More critically, the use of subprocess.run() with --break-system-packages flag and an unpinned upgrade (no specific version pinned in the pip command) could allow a compromised or malicious version of idc-index to be installed. The static analyzer flagged eval/exec usage in markdown code blocks, though the primary concern here is the subprocess execution pattern. File:
SKILL.mdRemediation: Pin the exact version in the pip install command: subprocess.run(["pip3", "install", "--break-system-packages", f"idc-index=={REQUIRED_VERSION}"], check=True). Also use packaging.version.Version for proper semantic version comparison instead of string comparison. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Optional Dependencies in Installation InstructionsThe SKILL.md installation section recommends installing optional packages (pandas, numpy, pydicom) without version pins. While the primary idc-index package has a version specified in metadata (0.11.14), the optional dependencies 'pip install pandas numpy pydicom' have no version constraints. This creates a supply chain risk where a compromised or incompatible version of these packages could be installed. File:
SKILL.mdRemediation: Pin specific versions for all recommended packages, e.g., 'pip install pandas==2.x.x numpy==1.x.x pydicom==2.x.x', or at minimum provide minimum version constraints. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe SKILL.md manifest does not specify the 'allowed-tools' field. The skill executes Python code (including subprocess calls), reads/writes files (CSV manifests, DICOM downloads), and makes network requests. Without an explicit allowed-tools declaration, there is no documented boundary on what agent tools this skill may use, reducing transparency about the skill's intended capabilities. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the YAML frontmatter listing the tools this skill requires, e.g., allowed-tools: [Python, Bash, Read, Write]. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in SKILL.md at line 21 contains potentially dangerous Python code. File:
SKILL.md:21Remediation: Review the code block for security implications.
labarchive-integration — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_SUPPLY_CHAIN_ATTACK— Unpinned GitHub Dependency InstallationThe skill instructs users to install the
labarchives-pypackage directly from a GitHub repository without any version pinning, commit hash, or integrity verification. This means any future compromise of themcmero/labarchives-pyrepository would automatically affect users who install or reinstall the package. There is no way to verify the integrity of what is being installed. File:SKILL.mdRemediation: Pin to a specific commit hash or tag:git clone --branch v1.0.0 https://github.com/mcmero/labarchives-pyor reference a specific commit. Consider publishing to PyPI with a pinned version. Document the expected package hash for verification. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. The
allowed-toolsfield is also absent. While these are optional per the spec, the absence of license information is notable for a skill that handles sensitive research data and institutional credentials. The skill author is listed as 'K-Dense Inc.' but no version information is provided. File:SKILL.mdRemediation: Add license, compatibility, and allowed-tools fields to the YAML manifest. For a skill handling API credentials and file I/O, specifyingallowed-tools: [Bash, Python, Read, Write]would improve transparency about the skill's required capabilities. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/api_reference.md at line 217 contains potentially dangerous Python code. File:
references/api_reference.md:217Remediation: Review the code block for security implications. -
🔵 LOW
LLM_DATA_EXFILTRATION— SSL Verification Disable Guidance in Reference DocumentationThe
references/authentication_guide.mdincludes example code that disables SSL certificate verification (verify=False). While labeled as 'use only for testing', this guidance could be misapplied in production environments, enabling man-in-the-middle attacks that could intercept API credentials and notebook data. File:references/authentication_guide.mdRemediation: Remove or strongly discourage theverify=Falseexample. Instead, provide guidance on properly configuring custom CA certificates for institutional proxy environments using theverify='/path/to/ca-bundle.crt'parameter. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/integrations.md at line 93 contains potentially dangerous Python code. File:
references/integrations.md:93Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/integrations.md at line 309 contains potentially dangerous Python code. File:
references/integrations.md:309Remediation: Review the code block for security implications. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— API Credentials Transmitted in HTTP Request BodyIn
entry_operations.py, theupload_attachmentfunction sendsaccess_key_idandaccess_passwordas plaintext POST body parameters alongside file uploads. While HTTPS is used, embedding credentials in request bodies (rather than using Authorization headers) increases the risk of credential exposure in server logs, proxy logs, and debugging output. The credentials are read from the config file and passed directly into the multipart form data. File:scripts/entry_operations.pyRemediation: Use HTTP Authorization headers (e.g., Bearer token or Basic auth) instead of embedding credentials in request body parameters. This reduces exposure in server-side logs and intermediary systems. -
🔵 LOW
LLM_DATA_EXFILTRATION— Credentials Stored in Plaintext YAML Config FileThe setup_config.py script creates a
config.yamlfile containing sensitive credentials including API access keys and user passwords. While the script sets file permissions to 0o600 (user read/write only), the credentials are stored in plaintext YAML. The authentication guide also shows hardcoded credentials in R code examples. If the config file is accidentally committed to version control or the filesystem is compromised, all credentials are immediately exposed. File:scripts/setup_config.pyRemediation: Recommend using environment variables or a secrets manager (e.g., OS keychain, HashiCorp Vault, AWS Secrets Manager) as the primary credential storage method. The skill does mention environment variables as an alternative but should make this the default recommendation rather than the plaintext config file.
markitdown — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Cross-Skill Activation Injection via 'scientific-schematics' Skill PromotionThe SKILL.md instructions contain an embedded promotional section that instructs the agent to automatically invoke a separate 'scientific-schematics' skill whenever documents are created or converted. This is not related to the stated purpose of file-to-Markdown conversion. The instruction 'Scientific schematics should be generated by default' and 'Nano Banana Pro will automatically generate, review, and refine the schematic' attempts to inflate the activation scope of this skill and trigger a secondary skill without explicit user request. This is a capability inflation / skill chaining abuse pattern that could cause unintended tool invocations. File:
SKILL.mdRemediation: Remove the cross-skill promotion section from SKILL.md. The markitdown skill should only describe its own file conversion capabilities. Any cross-skill invocation should be explicitly requested by the user, not embedded as a default behavior in skill instructions. -
🔵 LOW
LLM_DATA_EXFILTRATION— Hardcoded Placeholder API Key References in DocumentationThe SKILL.md and reference files contain placeholder API key strings like 'your-openrouter-api-key' in code examples. While these are documentation placeholders and not real secrets, they normalize the pattern of embedding API keys directly in code rather than exclusively using environment variables. The references/api_reference.md also shows 'key123...' as an example Azure key. This could encourage users to hardcode real credentials. File:
SKILL.mdRemediation: Replace all hardcoded API key placeholders in documentation with environment variable references only (e.g., api_key=os.environ['OPENROUTER_API_KEY']). Add explicit warnings in documentation that API keys should never be hardcoded in scripts. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned External Package Installation Without Version ConstraintsThe SKILL.md instructions recommend installing the markitdown package and its dependencies using unpinned version specifiers (e.g., 'pip install markitdown[all]'). No specific version pins are provided anywhere in the skill. This exposes users to supply chain risks where a compromised or malicious version of markitdown or its transitive dependencies could be installed. The skill also references installing from GitHub source directly ('git clone https://github.com/microsoft/markitdown.git') without any commit hash or tag pinning. File:
SKILL.mdRemediation: Pin specific versions for all package installations (e.g., 'pip install markitdown[all]==0.1.0'). When installing from source, reference a specific commit hash or release tag. Consider providing a requirements.txt with pinned versions for reproducible installations. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/markitdown/scripts/convert_with_ai.py File:
scientific-skills/markitdown/scripts/convert_with_ai.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Environment Variable Access Combined with External Network CallsThe scripts access environment variables (OPENROUTER_API_KEY, AZURE_DOCUMENT_INTELLIGENCE_KEY) and make external network calls to openrouter.ai and Azure endpoints. While the primary use case is legitimate (AI-enhanced image descriptions), the pattern of reading environment variables and transmitting data to external APIs creates a data exfiltration risk surface. The static analyzer flagged cross-file environment variable exfiltration chains across convert_with_ai.py and batch_convert.py. Specifically, convert_with_ai.py reads OPENROUTER_API_KEY from the environment and sends document content to openrouter.ai/api/v1, meaning the full text content of converted documents is transmitted to an external third-party service. File:
scripts/convert_with_ai.pyRemediation: Clearly document in the skill description that document content is transmitted to external APIs (OpenRouter, Azure) when AI features are used. Require explicit user confirmation before sending document content to external services. Consider adding a warning when sensitive documents are being processed with AI features enabled.
open-notebook — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Exposed in Example CodeThe SKILL.md instruction body contains an example where an actual API key placeholder 'sk-...' is shown in a POST request to the credentials endpoint. While this is a placeholder and not a real key, the pattern encourages users to embed API keys directly in scripts rather than using environment variables or secure credential stores. The example code demonstrates posting credentials including api_key values directly in code. File:
SKILL.mdRemediation: Update examples to load API keys from environment variables (e.g., os.getenv('OPENAI_API_KEY')) rather than inline strings, even in placeholder form. Add a note warning users never to hardcode real API keys in scripts. -
🔵 LOW
LLM_PROMPT_INJECTION— Skill Ingests Arbitrary External Web Content Without ValidationThe skill's core functionality involves ingesting arbitrary URLs and web pages as sources (e.g., arxiv.org, Wikipedia). While this is the intended purpose of the tool, the instructions do not warn that ingested web content could contain adversarial text designed to manipulate AI chat responses when the content is later used as context in chat sessions. This creates an indirect prompt injection surface where malicious web pages could embed instructions that influence AI responses. File:
SKILL.mdRemediation: Add a security note in the instructions warning users that ingested web content is untrusted and could contain adversarial instructions. Recommend that the Open Notebook backend sanitize or flag potentially adversarial content before using it as AI context. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the spec, their absence means the agent has no declared constraints on which tools it may use, potentially allowing broader tool access than necessary for this skill's purpose. File:
SKILL.mdRemediation: Add 'allowed-tools' to restrict the skill to only the tools it needs (e.g., Python, Bash for running the example scripts) and specify 'compatibility' to clarify supported environments. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 61 contains potentially dangerous Python code. File:
SKILL.md:61Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 92 contains potentially dangerous Python code. File:
SKILL.md:92Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 105 contains potentially dangerous Python code. File:
SKILL.md:105Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 126 contains potentially dangerous Python code. File:
SKILL.md:126Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 139 contains potentially dangerous Python code. File:
SKILL.md:139Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 157 contains potentially dangerous Python code. File:
SKILL.md:157Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 174 contains potentially dangerous Python code. File:
SKILL.md:174Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 194 contains potentially dangerous Python code. File:
SKILL.md:194Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/configuration.md at line 116 contains potentially dangerous Python code. File:
references/configuration.md:116Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 17 contains potentially dangerous Python code. File:
references/examples.md:17Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 98 contains potentially dangerous Python code. File:
references/examples.md:98Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 136 contains potentially dangerous Python code. File:
references/examples.md:136Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 182 contains potentially dangerous Python code. File:
references/examples.md:182Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 231 contains potentially dangerous Python code. File:
references/examples.md:231Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in references/examples.md at line 277 contains potentially dangerous Python code. File:
references/examples.md:277Remediation: Review the code block for security implications. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency in Installation InstructionsThe skill instructs users to install dependencies via 'pip install requests' without specifying a version pin. This exposes users to potential supply chain attacks if the requests package is compromised or a malicious version is published. All three example scripts also include this unpinned dependency in their docstrings. File:
scripts/chat_interaction.py:8Remediation: Pin the dependency to a specific known-good version, e.g., 'pip install requests==2.31.0', or provide a requirements.txt with pinned versions and hashes.
parallel-web — 🟡 MEDIUM
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Activation Scope in Description and InstructionsThe skill description and instructions repeatedly emphasize it should be used for 'ALL web searches, research queries, and general information gathering' and is the 'primary tool for all web-related operations'. This over-broad activation language could cause the agent to invoke this skill unnecessarily, increasing API usage and potential exposure of user queries to the Parallel API service. File:
SKILL.mdRemediation: Scope the activation language more precisely to the specific use cases where this skill is appropriate, rather than claiming universal priority for all web-related tasks. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe skill installs packages without version pins, which exposes the environment to supply chain attacks. If a malicious version of 'openai' or 'parallel-web' is published (e.g., via typosquatting or a compromised release), the agent would install and execute it without any version constraint. File:
SKILL.mdRemediation: Pin dependencies to specific known-good versions, e.g., 'pip install openai==1.30.0 parallel-web==X.Y.Z'. Consider using a requirements.txt with hashes for integrity verification. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/parallel-web/scripts/parallel_web.py File:
scientific-skills/parallel-web/scripts/parallel_web.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Transmitted to Third-Party ServiceThe skill reads the PARALLEL_API_KEY environment variable and transmits it to api.parallel.ai. While this is the intended behavior for an API client, users should be aware that their API key is sent to an external third-party service with every request. All search queries and research topics are also transmitted to this external service. File:
scripts/parallel_web.pyRemediation: Document clearly in the skill description that all queries and the API key are transmitted to api.parallel.ai. Ensure users understand the data privacy implications of using this external service.
peer-review — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_COMMAND_INJECTION— Unsanitized User Input Passed to Bash Command in Code BlockThe SKILL.md instructions include a bash command template where user-provided diagram descriptions are passed directly as a shell argument:
python scripts/generate_schematic.py "your diagram description" -o figures/output.png. If the agent substitutes user input into this command without sanitization, it could enable command injection through specially crafted diagram descriptions containing shell metacharacters or escape sequences. File:SKILL.mdRemediation: Avoid constructing shell commands with user-supplied strings. If the script must accept user input, pass arguments via a Python API or use subprocess with a list of arguments (not shell=True) to prevent injection. Validate and sanitize all user-provided strings before use in shell contexts. -
🟡 MEDIUM
LLM_COMMAND_INJECTION— Unsanitized User Input in PDF Conversion Bash CommandThe presentation review section instructs the agent to run a bash command substituting a user-provided filename directly:
python skills/scientific-slides/scripts/pdf_to_images.py presentation.pdf review/slide --dpi 150. If the agent substitutes a user-supplied filename without validation, this could allow path traversal or command injection via a maliciously crafted filename. File:SKILL.mdRemediation: Validate and sanitize filenames before passing them to shell commands. Use Python's subprocess module with argument lists rather than shell interpolation. Restrict accepted filenames to expected patterns (e.g., alphanumeric with .pdf extension). -
🟡 MEDIUM
LLM_UNAUTHORIZED_TOOL_USE— Cross-Skill Invocation Without User ConsentThe SKILL.md instructions direct the agent to automatically invoke an external skill ('scientific-schematics') and run its script without explicit user request. The instruction states 'For new documents: Scientific schematics should be generated by default' and provides a bash command to execute a script from another skill's directory. This constitutes unauthorized tool chaining and implicit cross-skill invocation that the user may not have requested or anticipated. File:
SKILL.mdRemediation: Remove the automatic invocation of external skills. If cross-skill functionality is desired, it should be explicitly requested by the user, not triggered by default. The instruction should be advisory ('you may use scientific-schematics') rather than directive ('always generate schematics by default'). -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Cross-Skill Capability Inflation via Embedded Skill PromotionThe SKILL.md description promotes the 'scientific-schematics' skill and 'Nano Banana Pro' product by name within the instructions, stating 'Nano Banana Pro will automatically generate, review, and refine the schematic.' This embeds marketing/promotional content for another skill/product within the peer-review skill's instructions, potentially inflating perceived capabilities and nudging users toward additional skill activation beyond what they requested. File:
SKILL.mdRemediation: Remove product promotion and cross-skill advertising from skill instructions. Skill instructions should describe only the capabilities of the current skill. References to other skills should be neutral and optional, not promotional. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Instructions Reference Script from External Skill DirectoryThe presentation review workflow instructs the agent to execute a script located at
skills/scientific-slides/scripts/pdf_to_images.py, which is outside the peer-review skill's own package directory. This creates a dependency on an external skill's scripts without declaring that dependency in the manifest, and could fail or behave unexpectedly if that skill is not installed. File:SKILL.mdRemediation: Declare cross-skill dependencies explicitly in the manifest. Either bundle required scripts within the skill package or document the dependency clearly. Avoid silently depending on other skills' internal scripts.
perplexity-search — 🟡 MEDIUM
-
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Batch Processing Without Rate Limiting EnforcementThe SKILL.md provides a bash batch processing example that loops over multiple queries with only a 'sleep 2' delay. The script itself has no built-in rate limiting, retry backoff, or maximum iteration count. While the sleep is present, users could easily remove it or run many parallel instances, leading to excessive API consumption and potential cost exhaustion. File:
SKILL.mdRemediation: Add explicit warnings about cost implications of batch processing. Consider implementing a maximum query count parameter. Add exponential backoff in the Python script for rate limit errors rather than relying on users to add sleep manually. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency InstallationThe skill instructs users to install litellm and python-dotenv without version pins (e.g., 'uv pip install litellm'). Unpinned dependencies are vulnerable to supply chain attacks where a malicious version could be published and automatically installed. LiteLLM is a widely-used package and a compromised version could intercept API keys or search queries. File:
SKILL.mdRemediation: Pin dependencies to specific versions (e.g., 'uv pip install litellm==1.x.x'). Provide a requirements.txt or pyproject.toml with pinned versions and hash verification. Consider using a lockfile. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Static Analyzer False Positive - eval/exec in Documentation Code BlocksThe static pre-scan flagged MDBLOCK_PYTHON_EVAL_EXEC findings in markdown files. Upon review, these appear to be in documentation/reference markdown files (model_comparison.md, search_strategies.md, openrouter_setup.md) as illustrative code examples, not executable code. No actual eval() or exec() calls were found in the Python scripts (perplexity_search.py, setup_env.py). This is a low-severity informational finding confirming no actual code injection risk exists in the scripts. File:
references/model_comparison.mdRemediation: No action required for the scripts. Consider adding a note in documentation that code examples are illustrative only. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/perplexity-search/scripts/perplexity_search.py File:
scientific-skills/perplexity-search/scripts/perplexity_search.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/perplexity-search/scripts/setup_env.py File:
scientific-skills/perplexity-search/scripts/setup_env.pyRemediation: Remove environment variable collection unless explicitly required and documented -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Exposure Risk via .env File and Setup ScriptThe setup_env.py script writes the OpenRouter API key directly to a .env file on disk. While the instructions mention not committing keys to version control, the setup script itself accepts the API key as a command-line argument (--api-key), which means the key may appear in shell history logs. Additionally, the assets/.env.example file contains a placeholder key format that could be mistakenly populated and committed. File:
scripts/setup_env.py:60Remediation: Warn users that passing API keys as CLI arguments exposes them in shell history. Recommend using interactive prompts (getpass) instead. Add .env to .gitignore instructions prominently. The setup script should also validate the key format before writing.
phylogenetics — 🟡 MEDIUM
-
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency InstallationThe skill instructs users to install dependencies without version pinning: 'conda install -c bioconda mafft iqtree fasttree' and 'pip install ete3'. Unpinned installations are vulnerable to supply chain attacks where a malicious package version could be installed. This is particularly relevant for bioinformatics tools that may have less frequent security audits. File:
SKILL.mdRemediation: Pin dependency versions explicitly, e.g., 'conda install -c bioconda mafft=7.520 iqtree=2.2.6 fasttree=2.1.11' and 'pip install ete3==3.1.3'. Consider providing a conda environment.yml or requirements.txt with pinned versions. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill does not declare an allowed-tools field in its YAML manifest. While this is optional per the spec, the skill executes external binaries (mafft, iqtree2, FastTree) via subprocess and writes files to disk. Declaring allowed-tools would help the agent runtime enforce appropriate sandboxing and make the skill's capabilities transparent to users. File:
SKILL.md:1Remediation: Add 'allowed-tools: [Bash, Python, Read, Write]' to the YAML frontmatter to explicitly declare the tools this skill requires. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe skill has no license specified and no compatibility information. This is a minor metadata gap that reduces transparency about the skill's provenance and intended deployment context. Without a license, users cannot determine the terms under which the skill can be used or redistributed. File:
SKILL.md:1Remediation: Add license (e.g., 'license: MIT') and compatibility fields to the YAML frontmatter to improve transparency and provenance tracking. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in SKILL.md at line 67 contains potentially dangerous Python code. File:
SKILL.md:67Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in SKILL.md at line 100 contains potentially dangerous Python code. File:
SKILL.md:100Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in SKILL.md at line 143 contains potentially dangerous Python code. File:
SKILL.md:143Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_SUBPROCESS— Python code block executes shell commandsCode block in SKILL.md at line 198 contains potentially dangerous Python code. File:
SKILL.md:198Remediation: Review the code block for security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— subprocess.run with External Tool Arguments - Potential Command Injection via User-Controlled InputsMultiple functions in both SKILL.md code blocks and scripts/phylogenetic_analysis.py construct subprocess commands using user-supplied arguments (e.g., input_fasta, output_fasta, method, outgroup, n_threads). While these are passed as list arguments (not shell=True), unsanitized user input could still cause unexpected behavior if filenames contain special characters or path traversal sequences. The risk is low because list-form subprocess calls avoid shell interpretation, but there is no input validation or sanitization on file paths or parameter values. File:
scripts/phylogenetic_analysis.py:60Remediation: Add input validation for file paths (e.g., check they don't contain path traversal sequences like '../'), validate method strings against an allowlist (already partially done), and validate numeric parameters are within reasonable bounds. Consider using pathlib.Path for safe path handling.
primekg — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe YAML manifest does not specify a license or compatibility field. The skill bundles data derived from PrimeKG (Harvard MIMS), which has its own licensing terms. Absence of license information may lead to unintended use in contexts that violate the upstream data license. File:
SKILL.mdRemediation: Add the appropriate license (PrimeKG uses CC BY 4.0) and specify compatibility constraints in the YAML frontmatter. Document any data usage restrictions. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Referenced File 'scripts.py' Not Found in PackageThe SKILL.md references 'scripts.py' as a file, but this file does not exist in the skill package. The actual script is at 'scripts/query_primekg.py'. This inconsistency could cause confusion about the skill's actual capabilities and may indicate incomplete packaging or documentation mismatch. File:
SKILL.mdRemediation: Update the SKILL.md references to correctly point to 'scripts/query_primekg.py' and ensure all referenced files are included in the skill package. -
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Hardcoded Absolute Path Exposing Developer's Local Filesystem StructureThe skill hardcodes an absolute path to the developer's personal filesystem: '/mnt/c/Users/eamon/Documents/Data/PrimeKG/kg.csv' (and 'C:\Users\eamon\Documents\Data\PrimeKG\kg.csv' in SKILL.md). This exposes the developer's username and directory structure, and the skill will silently fail for any other user since the path is non-portable. While not directly exfiltrating data, this represents a privacy/information disclosure issue and a significant usability/security misconfiguration. File:
scripts/query_primekg.py:7Remediation: Replace hardcoded paths with environment variables (e.g., os.environ.get('PRIMEKG_DATA_PATH')) or a configurable path relative to the skill directory. Document the required setup in SKILL.md without embedding personal filesystem paths. -
🟡 MEDIUM
LLM_RESOURCE_ABUSE— Repeated Full CSV Load on Every Function Call Causes Compute ExhaustionThe _load_kg() helper is called inside every public function (search_nodes, get_neighbors, find_paths, get_disease_context). Each call reads the entire 4-million-edge CSV (~hundreds of MB) from disk into memory with no caching. Chained calls such as get_disease_context() internally call both search_nodes() and get_neighbors(), each triggering a full reload. This can exhaust available RAM and CPU, causing the agent process to hang or crash, constituting a denial-of-service risk against the agent's host environment. File:
scripts/query_primekg.py:10Remediation: Implement module-level caching (e.g., a global _KG_CACHE variable set on first load, or use functools.lru_cache on _load_kg). This reduces repeated disk I/O and memory allocation to a single load per session. -
🔵 LOW
LLM_COMMAND_INJECTION— Unsanitized User Input Passed to pandas str.contains (Regex Injection)The search_nodes() function passes the user-supplied name_query directly to pandas str.contains(), which interprets the input as a regular expression by default. A malicious or malformed regex (e.g., '(a+)+' or an extremely long alternation) could cause catastrophic backtracking, consuming excessive CPU. While not a full code injection, it represents an injection vector into the regex engine. File:
scripts/query_primekg.py:46Remediation: Escape user input before passing to str.contains using re.escape(): mask = nodes['name'].str.contains(re.escape(name_query), case=False, na=False, regex=True). Alternatively, use regex=False for plain substring matching if regex features are not needed.
protocolsio-integration — 🟡 MEDIUM
-
🔵 LOW
LLM_COMMAND_INJECTION— Python Code Block Uses eval/exec Pattern (Static Analyzer Flag)The static analyzer flagged a potential eval/exec usage in a Python code block within the skill's markdown files. After reviewing all provided content, the code blocks present in SKILL.md and reference files use standard requests library calls and do not contain eval() or exec() calls. The flag may be a false positive from pattern matching on the word 'exec' appearing in context (e.g., 'execute', 'execution'). No actual eval/exec with user-controlled input was found in the reviewed content. File:
SKILL.mdRemediation: Review the specific file and line flagged by the static analyzer to confirm whether eval/exec is present. If found, replace with safe alternatives that do not execute arbitrary code. -
🔵 LOW
LLM_DATA_EXFILTRATION— Access Token Handling Guidance Could Encourage Insecure PracticesThe skill's Python code examples use placeholder strings like 'YOUR_ACCESS_TOKEN' directly in code variables (e.g., token = 'YOUR_ACCESS_TOKEN'). While this is documentation-style placeholder code, it models a pattern where tokens are hardcoded in scripts. The authentication reference files do advise against storing tokens in code, but the example code contradicts this advice by showing inline token assignment. File:
SKILL.mdRemediation: Update code examples to demonstrate secure token retrieval patterns, such as reading from environment variables (e.g., token = os.environ.get('PROTOCOLS_IO_TOKEN')) or from a secrets manager, rather than inline string assignment. -
🔵 LOW
LLM_PROMPT_INJECTION— Multiple Missing Referenced Files Could Allow Future Indirect InjectionSeveral referenced files listed in the skill (templates/file_manager.md, assets/protocols_api.md, assets/discussions.md, templates/additional_features.md, templates/discussions.md, templates/workspaces.md, templates/authentication.md, assets/workspaces.md, assets/authentication.md, templates/protocols_api.md, assets/file_manager.md, assets/additional_features.md) are not found in the skill package. If these files are later populated from external or untrusted sources, they could introduce indirect prompt injection. Currently this is a gap/informational finding. File:
SKILL.mdRemediation: Either remove references to files that do not exist in the skill package, or ensure all referenced files are bundled with the skill. Do not populate these files from external/untrusted sources at runtime. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe skill manifest does not specify a license (listed as 'Unknown') and does not specify compatibility information. While these are optional fields, their absence reduces transparency about the skill's intended use scope and legal terms. The allowed-tools field is also not specified, which is acceptable per spec but worth noting for completeness. File:
SKILL.mdRemediation: Add a valid SPDX license identifier (e.g., 'MIT', 'Apache-2.0'), specify compatibility (e.g., 'Claude.ai, Claude Code, API'), and optionally declare allowed-tools to make the skill's scope explicit. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 283 contains potentially dangerous Python code. File:
SKILL.md:283Remediation: Review the code block for security implications. -
🟡 MEDIUM
MDBLOCK_PYTHON_HTTP_POST— Python code block sends HTTP POST requestCode block in SKILL.md at line 310 contains potentially dangerous Python code. File:
SKILL.md:310Remediation: Review the code block for security implications.
pymatgen — 🟡 MEDIUM
-
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Placeholder in SKILL.md InstructionsThe SKILL.md instructions include example code showing 'export MP_API_KEY="your_api_key_here"' and 'with MPRester("your_api_key_here") as mpr:'. While these are placeholder examples and not hardcoded real credentials, the second form (passing API key directly to MPRester constructor) could encourage users to hardcode real API keys in scripts rather than using environment variables. File:
SKILL.mdRemediation: Remove the example showing direct API key passing to MPRester constructor. Only demonstrate the environment variable approach to discourage hardcoding of real credentials. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on what tools the agent can use when executing this skill. The skill executes Python scripts, makes network calls to the Materials Project API, reads and writes files, and runs bash commands. Declaring these capabilities would improve transparency. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' and 'compatibility' fields to the YAML frontmatter to clearly declare the skill's tool requirements and intended execution environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe skill instructs installation of packages without version pins: 'uv pip install pymatgen', 'uv pip install pymatgen mp-api', 'uv pip install pymatgen[analysis]'. While the skill notes it targets 'pymatgen 2024.x and later' and 'pymatgen >= 2023.x', no exact version pins are specified in installation commands. This could expose users to supply chain risks if a malicious version is published to PyPI. File:
SKILL.mdRemediation: Specify exact version pins in installation instructions, e.g., 'uv pip install pymatgen==2024.x.x mp-api==0.x.x', or provide a requirements.txt with pinned versions and hashes. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in a Python code block. After reviewing the skill content, the flagged pattern appears to be within documentation/example code blocks in the reference files rather than in executable scripts. The actual Python scripts (structure_analyzer.py, phase_diagram_generator.py, structure_converter.py) do not contain eval/exec calls. However, the presence of this pattern warrants noting as a low-severity informational finding. File:
references/analysis_modules.mdRemediation: Confirm no eval/exec patterns exist in executable scripts. The reference files are documentation only and pose no direct execution risk. -
🟡 MEDIUM
BEHAVIOR_ENV_VAR_HARVESTING— Environment variable harvesting detectedScript iterates through environment variables in scientific-skills/pymatgen/scripts/phase_diagram_generator.py File:
scientific-skills/pymatgen/scripts/phase_diagram_generator.pyRemediation: Remove environment variable collection unless explicitly required and documented
research-grants — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_COMMAND_INJECTION— Python eval/exec Usage Detected in Referenced Code BlockThe static pre-scan flagged a Python code block using eval/exec patterns within the skill's markdown content. While no standalone Python script files were found, the SKILL.md references scripts such as 'scripts/compliance_checker.py', 'scripts/budget_calculator.py', and 'scripts/deadline_tracker.py', and the skill declares 'Bash' in allowed-tools. The static analyzer detected a MDBLOCK_PYTHON_EVAL_EXEC finding, indicating a code block within the markdown files contains eval or exec usage. If these patterns are executed by the agent, they could enable arbitrary code execution via command injection. File:
SKILL.mdRemediation: Audit all Python code blocks and referenced scripts for eval/exec usage. Replace eval/exec with safe alternatives (e.g., ast.literal_eval for data parsing). Ensure user-provided input is never passed to eval/exec. Review the compliance_checker.py, budget_calculator.py, and deadline_tracker.py scripts for injection vulnerabilities. -
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Mandatory Cross-Skill Dependency Injection via 'scientific-schematics' SkillThe SKILL.md instruction body contains a section marked '⚠️ MANDATORY' that instructs the agent to always invoke a separate skill called 'scientific-schematics' and a product called 'Nano Banana Pro' for every grant proposal. This is framed as non-optional ('This is not optional. Grant proposals without visual elements are incomplete and less competitive.'). This constitutes capability inflation and cross-skill activation abuse: the skill artificially inflates its own requirements to force invocation of another skill/product, potentially for commercial promotion or to expand the attack surface. The reference to 'Nano Banana Pro' as an automatic agent is particularly suspicious as it appears to be a branded product being promoted through mandatory skill instructions. File:
SKILL.mdRemediation: Remove the mandatory cross-skill invocation requirement. If figure generation is genuinely useful, present it as an optional recommendation rather than a mandatory requirement. Remove references to branded products ('Nano Banana Pro') embedded in skill instructions. Users should decide whether to use additional skills. -
🔵 LOW
LLM_HARMFUL_CONTENT— Misleading Mandatory Framing for Commercial Product PromotionThe SKILL.md instruction body uses authoritative, mandatory language ('MANDATORY', 'This is not optional') to promote what appears to be a commercial product ('Nano Banana Pro') embedded within grant writing guidance. This deceptive framing could mislead users into believing that using this specific product is a professional requirement for competitive grant proposals, when in fact it is not. This constitutes potentially harmful/misleading content that could influence user behavior for commercial benefit. File:
SKILL.mdRemediation: Remove mandatory framing and commercial product references from professional guidance content. If figure generation tools are recommended, present them as optional suggestions with neutral language. Disclose any commercial relationships if applicable. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Script Execution References Without Input ValidationThe SKILL.md references multiple scripts (compliance_checker.py, budget_calculator.py, deadline_tracker.py) and includes a bash command pattern for generating schematics. The skill declares Bash and Write in allowed-tools. Without seeing the actual script content (scripts not found), the pattern of referencing multiple executable scripts combined with Bash access creates potential for resource exhaustion if scripts are invoked with unbounded inputs or in loops. The schematic generation command 'python scripts/generate_schematic.py "your diagram description" -o figures/output.png' could be invoked repeatedly given the 'MANDATORY' instruction to generate multiple figures. File:
SKILL.mdRemediation: Implement rate limiting and input validation in all referenced scripts. Add explicit bounds on figure generation (e.g., maximum 3 figures per session). Ensure scripts have timeout mechanisms and cannot be invoked in unbounded loops.
rowan — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Environment Variable Access Combined with External Network CallsThe static pre-scan flagged BEHAVIOR_ENV_VAR_EXFILTRATION across multiple files (4-file cross-file chain). The skill instructs the agent to read the ROWAN_API_KEY environment variable and transmit it to external Rowan API endpoints. While this is the intended authentication mechanism, the pattern of reading environment variables and sending them over the network is a recognized exfiltration vector. If the skill or its referenced scripts (rowan.py, rdkit.py — not found for inspection) are tampered with or if the API endpoint is substituted, this pattern could silently exfiltrate credentials and environment data. The referenced files rowan.py and rdkit.py could not be verified, increasing risk. File:
SKILL.mdRemediation: Ensure rowan.py and rdkit.py are present and auditable within the skill package. Verify that the rowan-python package is pinned to a specific version to prevent supply chain substitution. Document exactly which environment variables are read and to which endpoints they are transmitted. -
🟡 MEDIUM
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Third-Party Package InstallationThe skill instructs installation of
rowan-pythonwithout a pinned version (uv pip install rowan-pythonorpip install rowan-python). An unpinned package installation is vulnerable to supply chain attacks: a malicious version could be published to PyPI that exfiltrates credentials, reads local files, or executes arbitrary code. Given that this package handles API keys and makes network calls, a compromised version would be particularly dangerous. File:SKILL.mdRemediation: Pin the package to a specific known-good version:pip install rowan-python==<version>. Include a hash verification step or use a lockfile. Document the expected package version in the YAML manifest. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Exposed in Plaintext Code ExamplesThe SKILL.md instruction body contains multiple code examples where the Rowan API key is set directly in Python code as a string literal (e.g.,
rowan.api_key = "your_api_key_here"). While these are placeholder values, the pattern actively encourages users to hardcode API keys in scripts rather than exclusively using environment variables. This increases the risk of credential exposure in version control or logs. File:SKILL.mdRemediation: Remove all inline API key assignment examples from documentation. Only demonstrate the environment variable pattern:export ROWAN_API_KEY=...andimport os; rowan.api_key = os.environ['ROWAN_API_KEY']. Add explicit warnings against hardcoding credentials. -
🔵 LOW
LLM_DATA_EXFILTRATION— Webhook Secret Printed to Console in Documentation ExamplesMultiple code examples in SKILL.md print webhook secrets directly to stdout (e.g.,
print(f"Secret key: {secret.secret}")). This pattern, if followed by users, would expose webhook secrets in terminal logs, CI/CD output, or shared sessions. File:SKILL.mdRemediation: Remove print statements that output secrets from documentation examples. Replace with guidance to store secrets securely (e.g., in environment variables or a secrets manager) rather than printing them. -
🔵 LOW
LLM_PROMPT_INJECTION— Referenced Script Files Not Present in PackageThe SKILL.md references two Python files (rdkit.py and rowan.py) that were not found in the skill package. These missing files are referenced in the instructions but cannot be audited. If these files are fetched at runtime from an external source or if a user supplies them, they could contain malicious instructions or code that the agent would execute in the context of this skill, constituting an indirect prompt injection or code injection risk. File:
SKILL.mdRemediation: Either include the referenced files within the skill package for auditability, or remove the references if they are not needed. If these are meant to be the installed library modules, clarify this in the documentation and do not reference them as local files. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Broad Trigger Keywords May Cause Unintended Skill ActivationThe YAML manifest includes a
trigger-keywordsmetadata field with 9 broad terms including 'drug discovery', 'SMILES', 'protein structure', and 'batch molecular modeling'. These keywords are common in general chemistry and biology discussions and could cause the skill to activate in contexts where the user did not intend to invoke Rowan's cloud API, potentially submitting data to an external service without explicit user consent. File:SKILL.mdRemediation: Narrow trigger keywords to more specific, unambiguous terms that clearly indicate intent to use the Rowan platform specifically (e.g., 'rowan workflow', 'rowan API'). Remove generic terms like 'SMILES' and 'protein structure' that appear in many non-Rowan contexts.
scholar-evaluation — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_SKILL_DISCOVERY_ABUSE— Cross-Skill Activation Abuse via Scientific Schematics IntegrationThe SKILL.md instructions contain a section that actively promotes and triggers the use of a separate 'scientific-schematics' skill, instructing the agent to invoke it by default for 'new documents' and to run an external script (scripts/generate_schematic.py). This cross-skill activation pattern inflates the effective capability surface of this skill beyond its stated scholarly evaluation purpose, potentially triggering unvetted external skill execution without explicit user consent. The instruction 'Scientific schematics should be generated by default' is an autonomy-expanding directive that bypasses user decision-making. File:
SKILL.mdRemediation: Remove or make optional the automatic invocation of the scientific-schematics skill. Any cross-skill activation should require explicit user consent. The generate_schematic.py script reference should be removed if it is not bundled with this skill package. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill manifest does not declare an 'allowed-tools' field, meaning there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be used. The skill executes Python scripts and references Bash commands. While missing allowed-tools is informational per spec, the absence combined with script execution capabilities means there is no declared boundary on tool use. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' declaration to the YAML frontmatter listing only the tools required (e.g., [Python, Read, Write]) to limit the agent's tool surface. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— No Dependency Pinning or Provenance for External Framework ReferenceThe skill cites an arXiv preprint (arXiv:2510.16234) as the basis for the ScholarEval framework. The arXiv ID '2510.16234' appears to reference a future or non-existent paper (October 2025 submission date is in the future relative to known training data), raising questions about provenance authenticity. Additionally, no version pinning or integrity verification is provided for the framework reference. File:
SKILL.mdRemediation: Verify the cited paper exists and is authentic. If the framework is proprietary or internally developed, remove the misleading academic citation. Ensure any external references are verifiable and current. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Reference to Non-Existent Script (generate_schematic.py) in InstructionsThe SKILL.md instructions reference and instruct the agent to execute 'scripts/generate_schematic.py', which is not included in the skill package (only scripts/calculate_scores.py is present). Instructing the agent to run a script that does not exist in the package could lead to unexpected behavior, errors, or — if a malicious file were later placed at that path — unintended code execution. File:
SKILL.mdRemediation: Remove references to scripts not bundled with the skill package. If generate_schematic.py is intended to be part of the skill, include it and subject it to the same security review as other scripts.
scientific-brainstorming — 🟡 MEDIUM
-
🟡 MEDIUM
LLM_DATA_EXFILTRATION— Static analysis flags environment variable access and network calls in unreported Python filesThe pre-scan static analysis reports BEHAVIOR_ENV_VAR_EXFILTRATION (environment variable access with network calls) and BEHAVIOR_CROSSFILE_EXFILTRATION_CHAIN across 4 Python files in the skill package. The file inventory lists 4 Python files, yet the skill submission reports 'No script files found.' This discrepancy is significant: Python files exist in the package but were not surfaced for review. If these files contain environment variable harvesting combined with outbound network calls, this would constitute a data exfiltration threat. The skill's stated purpose (conversational brainstorming) has no legitimate need for environment variable access or network calls. File:
SKILL.mdRemediation: Obtain and review all 4 Python files in the package. If they contain environment variable access (os.environ, os.getenv) combined with outbound HTTP/network calls, treat this as a CRITICAL data exfiltration finding. A purely conversational brainstorming skill should have zero Python scripts making network calls or reading environment variables. Remove or sandbox any such code. -
🔵 LOW
LLM_PROMPT_INJECTION— Instruction to read internal reference file during sessionsThe SKILL.md instructions direct the agent to consult 'references/brainstorming_methods.md' during live sessions ('Consult references/brainstorming_methods.md for additional structured techniques'). The referenced file itself is benign and bundled within the skill package. However, the instruction pattern of dynamically loading and following content from a file during an active session creates a surface for indirect prompt injection if the file were ever replaced or tampered with. The file content reviewed is legitimate and contains no malicious instructions. File:
SKILL.mdRemediation: This is low risk given the file is internal and benign. Consider treating the reference file as static documentation rather than dynamically consulted instructions, or add integrity verification for referenced files. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility metadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill may invoke. Given the pre-scan static analysis flags indicating potential environment variable access and network calls in associated Python files (not surfaced in the provided content), the lack of tool restrictions is worth noting. File:
SKILL.mdRemediation: Add explicit 'allowed-tools' to the manifest to document and restrict which agent capabilities this skill requires. If the skill is purely conversational, declare 'allowed-tools: []' or a minimal set.
adaptyv — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While not a direct security threat, missing provenance information reduces transparency and makes it harder to assess the trustworthiness of the skill package. File:
SKILL.mdRemediation: Add a license field (e.g., MIT, Apache-2.0) and a compatibility field to the YAML frontmatter to improve transparency and provenance tracking. -
🔵 LOW
LLM_DATA_EXFILTRATION— Referenced Files Not Found in Skill PackageThe SKILL.md references several files (
templates/api-endpoints.md,assets/api-endpoints.md,adaptyv.py) that are not present in the skill package. Whilereferences/api-endpoints.mdwas found, the missing files could indicate incomplete packaging or that the skill may attempt to load content from unexpected locations at runtime. File:SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package. Remove references to files that do not exist, or document why they are optional. Audit whetheradaptyv.pyis expected to be a user-provided file and if so, treat its contents as untrusted. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned SDK Dependency InstallationThe skill instructs users to install the
adaptyv-sdkpackage without pinning to a specific version. This creates a supply chain risk where a compromised or malicious version of the package could be installed automatically. File:SKILL.mdRemediation: Pin the SDK to a specific known-good version, e.g.,uv add adaptyv-sdk==1.2.3. Document the expected version and verify package integrity (e.g., via hash pinning or a lockfile).
aeon — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools SpecificationThe skill manifest does not specify the 'allowed-tools' field. While this is an optional field per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be used when executing this skill. This is informational only. File:
SKILL.mdRemediation: Consider adding an explicit 'allowed-tools' field to the YAML manifest to document which tools are expected to be used, e.g., allowed-tools: [Python, Bash]. This improves transparency and allows security tooling to verify compliance. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility FieldThe skill manifest does not specify the 'compatibility' field, leaving it unclear which agent environments or platforms this skill is designed to work with. This is a minor documentation gap. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML manifest specifying supported environments, e.g., 'compatibility: Works in Claude.ai, Claude Code, API'. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe skill instructs installation of the 'aeon' package without a pinned version number. This means any future version of the package could be installed, including potentially compromised versions. Supply chain attacks via package repositories are a known threat vector. File:
SKILL.mdRemediation: Pin the package to a specific known-good version, e.g., 'uv pip install aeon==0.11.0' or equivalent. Consider also verifying package integrity via hash verification.
anndata — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Multiple Referenced Files Not Found in Skill PackageThe SKILL.md references numerous files (muon.py, anndata.py, scipy.py, scanpy.py, and multiple assets/templates directories) that are not present in the skill package. While this is not directly a security threat, missing files could cause the agent to seek or load substitute resources from unexpected locations, potentially introducing untrusted content. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package, or remove references to files that do not exist. Avoid referencing files that may be resolved from outside the skill directory. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools SpecificationThe skill manifest does not specify the 'allowed-tools' field. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be invoked. Given that the skill instructions reference executing Python code and file I/O operations, documenting allowed tools would improve transparency. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' field to the YAML frontmatter listing the tools the skill requires, e.g., allowed-tools: [Python, Read, Write]. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe installation instructions use 'uv pip install anndata' without pinning a specific version. This could allow installation of a compromised or incompatible future version of the package if the skill is used in an automated context. File:
SKILL.mdRemediation: Pin the package to a specific known-good version, e.g., 'uv pip install anndata==0.10.x', and document the expected version in the manifest. -
🔵 LOW
LLM_PROMPT_INJECTION— External URL Data Access Without Validation WarningThe io_operations.md reference file documents reading data directly from external URLs (e.g., S3 buckets, HTTPS endpoints) without any guidance on validating the trustworthiness or integrity of remote data sources. If a user provides a malicious URL, the agent could load untrusted data into the AnnData object. File:
references/io_operations.mdRemediation: Add guidance in the instructions to validate URLs before use, prefer trusted/known data sources, and warn users about the risks of loading data from untrusted external URLs.
arboreto — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools Manifest FieldThe SKILL.md manifest does not specify the 'allowed-tools' field. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may use. The skill executes Python scripts and reads/writes files, so documenting allowed tools would improve transparency. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' field to the YAML frontmatter, e.g., 'allowed-tools: [Python, Bash, Read, Write]', to document the intended tool usage scope. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in ManifestThe SKILL.md manifest does not specify the 'compatibility' field. This is a minor documentation gap that reduces transparency about which environments the skill is intended to run in. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter describing supported environments (e.g., 'Claude.ai, Claude Code, API'). -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency InstallationThe skill instructs users to install the 'arboreto' package without pinning a specific version. This could expose users to supply chain risks if the package is updated with malicious or breaking changes. The same applies to the implied dependencies (scipy, scikit-learn, numpy, pandas, dask, distributed). File:
SKILL.mdRemediation: Pin the arboreto package to a specific known-good version, e.g., 'uv pip install arboreto==0.1.6'. Consider also pinning critical dependencies and providing a requirements.txt or pyproject.toml with locked versions.
astropy — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-broad Skill Description May Cause Excessive ActivationThe skill description is very comprehensive and lists a wide range of astronomical tasks (coordinate transformations, unit conversions, FITS file manipulation, cosmological calculations, time scale conversions, astronomical data processing). While this accurately reflects astropy's capabilities, the breadth of the description could cause the skill to be activated for a very wide range of astronomy-related queries, potentially displacing more specialized skills. File:
SKILL.mdRemediation: Consider narrowing the description to the most common use cases, or splitting into more focused sub-skills if the activation scope is a concern. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation in Installation InstructionsThe SKILL.md installation section uses 'uv pip install astropy' and 'uv pip install astropy[all]' without version pinning. This could allow installation of a compromised or unexpected version of the astropy package if the package index is compromised or if a newer version introduces breaking changes or vulnerabilities. File:
SKILL.mdRemediation: Pin the astropy version in installation instructions (e.g., 'uv pip install astropy==6.1.0') to ensure reproducible and secure installations. Consider adding a requirements.txt or pyproject.toml with pinned dependencies. -
🔵 LOW
LLM_DATA_EXFILTRATION— Remote FITS File Access via S3/HTTP in Reference DocumentationThe references/fits.md file documents accessing remote FITS files via S3 URIs and HTTP URLs using fsspec. While this is legitimate astropy functionality, the skill documentation teaches patterns that involve reading data from remote/external sources, which could be used to access sensitive or attacker-controlled data if user-supplied URLs are passed without validation. File:
references/fits.mdRemediation: Add a note in the documentation warning that user-supplied URLs should be validated before use, and that anonymous S3 access should only be used with trusted bucket names. -
🔵 LOW
LLM_PROMPT_INJECTION— External URL Data Download Pattern in Reference DocumentationThe references/wcs_and_other_modules.md file documents astropy.utils.data.download_file() which downloads files from arbitrary URLs and caches them locally. If an agent uses this pattern with user-supplied URLs, it could be used to fetch and execute content from attacker-controlled servers. File:
references/wcs_and_other_modules.mdRemediation: Add guidance that URLs passed to download_file() should be validated and should come from trusted sources only. Avoid passing user-supplied URLs directly to this function without validation.
benchling-integration — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License InformationThe skill manifest does not specify a license, which is a minor metadata gap. While not a direct security threat, it reduces transparency about the skill's provenance and usage rights. File:
SKILL.mdRemediation: Add a valid SPDX license identifier (e.g., MIT, Apache-2.0) to the YAML frontmatter. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe skill does not declare an allowed-tools field in the YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may invoke. Given the skill's broad capabilities (API calls, file I/O, SDK usage), declaring allowed tools would improve security posture. File:
SKILL.mdRemediation: Add an explicit allowed-tools field to the YAML frontmatter listing only the tools required for the skill's functionality (e.g., [Python, Bash]). -
🔵 LOW
LLM_DATA_EXFILTRATION— Credential Handling Guidance Includes Plaintext ExamplesThe authentication reference and SKILL.md include code examples that pass API keys as literal string arguments (e.g., ApiKeyAuth('your_api_key')). While these are labeled as examples, users may copy them verbatim and hardcode real credentials. The documentation does advise using environment variables but the inline examples may encourage insecure patterns. File:
references/authentication.mdRemediation: Replace all inline credential examples with environment variable patterns exclusively. Remove any example that shows a literal string in place of a credential, even as a placeholder. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionsThe skill's reference documentation instructs users to install the benchling-sdk package without pinning to a specific version. Unpinned dependencies are vulnerable to supply chain attacks where a malicious version could be published and automatically installed. File:
references/sdk_reference.mdRemediation: Pin the package to a specific known-good version (e.g., pip install benchling-sdk==1.x.x) and document the recommended version. Avoid --pre (pre-release) installs in production guidance.
biopython — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Placeholder in DocumentationThe SKILL.md includes a placeholder for an NCBI API key ('Entrez.api_key = "your_api_key_here"'). While this is documentation guidance and not a hardcoded secret, users following the instructions may inadvertently store real API keys in scripts or notebooks without proper secret management. File:
SKILL.mdRemediation: Add guidance to use environment variables or a secrets manager for API keys rather than hardcoding them in scripts. Example: 'Entrez.api_key = os.environ.get("NCBI_API_KEY")' -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License InformationThe skill manifest declares 'license: Unknown', which provides no provenance information for users. This is a minor metadata issue but reduces transparency about the skill's legal status and origin. File:
SKILL.mdRemediation: Specify a valid open-source license (e.g., MIT, Apache 2.0) or clarify the licensing terms in the manifest. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and Allowed-Tools MetadataThe skill does not specify 'compatibility' or 'allowed-tools' in the YAML manifest. While these fields are optional per the spec, their absence means there are no declared restrictions on tool usage, reducing auditability. File:
SKILL.mdRemediation: Add 'allowed-tools' and 'compatibility' fields to the manifest to clearly declare intended tool usage and supported environments. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Multiple Missing Referenced FilesThe skill references numerous files (assets/blast.md, assets/structure.md, templates/*.md, Bio.py, etc.) that do not exist in the package. This creates a gap between documented capabilities and actual available resources, potentially causing the agent to fail silently or behave unexpectedly when trying to read non-existent reference files. File:
SKILL.mdRemediation: Remove references to non-existent files from the instructions, or include the missing files in the skill package. Ensure the manifest accurately reflects available resources. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Biopython Installation InstructionThe skill instructs users to install Biopython without pinning to a specific version ('uv pip install biopython'). This could expose users to supply chain risks if a malicious or broken version is published to PyPI. File:
SKILL.mdRemediation: Pin to a specific known-good version, e.g., 'uv pip install biopython==1.85', to reduce supply chain risk.
cellxgene-census — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Several Referenced Files Not Found in Skill PackageThe SKILL.md references multiple files that are not present in the skill package: templates/census_schema.md, templates/common_patterns.md, scanpy.py, tiledbsoma.py, assets/census_schema.md, assets/common_patterns.md, and cellxgene_census.py. While the two primary reference files (references/census_schema.md and references/common_patterns.md) are present, the missing files could indicate an incomplete package or potential confusion about what resources are available. This is a low-severity informational finding. File:
SKILL.mdRemediation: Audit and remove references to non-existent files from the skill package, or include the missing files. Ensure the skill package is complete and all referenced resources are bundled. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While these are optional fields, their absence reduces transparency about the skill's intended usage scope and compatibility constraints. The skill-author field is present (K-Dense Inc.) but license is listed as 'Unknown'. File:
SKILL.mdRemediation: Add explicit license information (e.g., MIT, Apache-2.0) and compatibility field to the YAML frontmatter to improve transparency and discoverability. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation Without Version ConstraintsThe skill instructs installation of 'cellxgene-census' and 'cellxgene-census[experimental]' without specifying version pins. This creates a supply chain risk where a compromised or breaking version of the package could be installed automatically. The packages are from a known legitimate source (CZ CELLxGENE), but unpinned installs are a best practice concern. File:
SKILL.mdRemediation: Pin package versions explicitly, e.g., 'uv pip install cellxgene-census==1.x.x' to ensure reproducibility and reduce supply chain risk.
cirq — 🔵 LOW
-
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe SKILL.md installation instructions use 'uv pip install cirq' and related packages without version pinning. This means the agent could install any version of these packages, including potentially compromised future versions. While this is a common practice in documentation, it represents a supply chain risk in automated agent contexts. File:
SKILL.mdRemediation: Pin package versions in installation instructions (e.g., 'uv pip install cirq==1.3.0') to ensure reproducible and auditable installations. Consider providing a requirements.txt with pinned versions. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Keys Referenced in Code ExamplesThe hardware integration reference files (references/hardware.md, hardware.md) contain code examples that show API keys being passed directly in code (e.g., cirq_ionq.Service(api_key='your_api_key')). While these are placeholder examples, they could encourage users to hardcode real credentials in their scripts. File:
references/hardware.mdRemediation: Update code examples to exclusively demonstrate environment variable usage for credentials, and add explicit warnings against hardcoding API keys. The examples already show environment variable alternatives but should make them the primary recommended approach.
cobrapy — 🔵 LOW
- 🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility metadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on what tools the agent may use when executing this skill. Given the skill executes Python code for metabolic modeling, declaring allowed tools would improve transparency. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python]' and a 'compatibility' field to the YAML frontmatter to clearly declare the skill's intended tool usage and platform compatibility.
dask — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Multiple Referenced Files Not Found in PackageThe skill references numerous files that are not present in the package: templates/bags.md, templates/dataframes.md, assets/futures.md, templates/arrays.md, assets/schedulers.md, assets/arrays.md, templates/schedulers.md, templates/futures.md, assets/dataframes.md, dask.py, assets/best-practices.md, templates/best-practices.md, assets/bags.md. While these appear to be internal package files (not external URLs), their absence means the agent may attempt to read non-existent files or fail silently. The static analyzer also flagged cross-file exfiltration chains and environment variable exfiltration patterns across 4 files — however, the actual script files were not provided for review, so the full risk cannot be confirmed from the available content. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package. Audit any Python scripts (particularly dask.py and others flagged by static analysis) for environment variable access combined with network calls, and remove or restrict any such patterns if they are not required for legitimate Dask functionality. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe skill does not specify the 'allowed-tools' field in its YAML frontmatter. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools this skill may invoke. Given the skill's scope (distributed computing, file I/O, cluster management), documenting intended tool usage would improve transparency. File:
SKILL.mdRemediation: Add an 'allowed-tools' field to the YAML frontmatter listing the tools this skill is expected to use, e.g., allowed-tools: [Read, Python, Bash]. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill does not specify a 'compatibility' field in its YAML frontmatter. This is a minor documentation gap that reduces transparency about which environments or agent platforms the skill is designed for. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter, e.g., compatibility: Works in Claude.ai, Claude Code, API.
diffdock — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe SKILL.md manifest does not specify an 'allowed-tools' field. While this is optional per the agent skills spec, the skill executes Python scripts and Bash commands, so declaring allowed tools would improve transparency and security posture. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' to the YAML frontmatter to explicitly declare the tools this skill uses. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility FieldThe SKILL.md manifest does not specify a 'compatibility' field. This is a minor documentation gap that reduces transparency about where the skill is intended to run. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter specifying the intended runtime environments.
etetoolkit — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged by Static AnalyzerThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding. After thorough review of all code blocks in SKILL.md and the referenced markdown files (references/workflows.md, references/visualization.md, references/api_reference.md), no actual use of eval() or exec() with user-controlled input was found. All code examples use standard ETE3 library calls. The flag may be a false positive from the static analyzer detecting the string 'exec' within documentation text or import patterns. No exploitable command injection pattern was identified in the reviewed content. File:
SKILL.mdRemediation: Verify the specific line flagged by the static analyzer. If it is within a documentation code block and not executed directly, no action is needed. Ensure no future code additions introduce eval/exec with unsanitized user input. -
🔵 LOW
LLM_DATA_EXFILTRATION— NCBI Taxonomy Database Auto-Download to Home DirectoryThe skill automatically downloads ~300MB of NCBI taxonomy data to ~/.etetoolkit/taxa.sqlite on first use of NCBITaxa. While this is standard ETE3 behavior and the data comes from NCBI (a trusted source), it involves an automatic network download to the user's home directory without explicit user confirmation in the skill's workflow. The update_taxonomy_database() method also re-downloads from NCBI. This is low risk but worth noting as it involves automatic external network access and home directory writes. File:
SKILL.mdRemediation: Document clearly to users that NCBITaxa will download ~300MB from NCBI on first use. Consider prompting the user for confirmation before invoking NCBITaxa for the first time in an automated workflow. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package InstallationThe SKILL.md installation instructions use 'uv pip install ete3' and 'uv pip install ete3[gui]' without pinning to a specific version. This means the agent could install any version of the ete3 package, including potentially compromised future versions. While ete3 is a well-known bioinformatics library, unpinned installs are a supply chain risk. File:
SKILL.mdRemediation: Pin the ete3 package to a specific known-good version, e.g., 'uv pip install ete3==3.1.3'. Consider also pinning transitive dependencies using a lockfile.
exploratory-data-analysis — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe SKILL.md manifest does not declare an 'allowed-tools' field. The skill reads files from the user's filesystem (arbitrary file paths provided by the user), writes EDA report files to disk, and executes Python code. Without an explicit allowed-tools declaration, there is no manifest-level constraint on what tools the agent may use. This is LOW severity as allowed-tools is optional per the spec, but its absence means no declared boundary on file system access scope. File:
SKILL.mdRemediation: Add 'allowed-tools: [Read, Write, Python, Bash]' to the YAML frontmatter to explicitly declare the tools this skill requires, improving transparency and enabling tool restriction enforcement. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Claims in DescriptionThe skill description claims support for '200+ file formats' across six major scientific domains. While the reference files do cover many formats, the actual analysis script (eda_analyzer.py) only implements concrete analysis for a subset: CSV/TSV, JSON, NPY/NPZ, HDF5, FASTA/FASTQ, and basic TIFF/PNG/JPEG. For the majority of the 200+ claimed formats, the skill falls back to reading reference documentation and providing generic recommendations rather than performing actual data analysis. This gap between claimed and actual capability could lead to user confusion but is not a security threat. File:
SKILL.mdRemediation: Clarify in the description that automated analysis is available for common formats, while format-specific guidance (via reference files) is provided for 200+ formats. This improves transparency without security implications. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code Block (Informational)The static analyzer flagged a potential eval/exec usage in a Python code block. After reviewing the actual script (scripts/eda_analyzer.py), no direct use of eval() or exec() with user-controlled input was found. The script uses standard library calls (json.load, pandas.read_csv, numpy.load, h5py.File, etc.) without dynamic code execution. The flag may be a false positive from pattern matching on code examples in the markdown documentation. This is noted as LOW severity for awareness. File:
scripts/eda_analyzer.pyRemediation: Confirm no eval/exec is present in the actual deployed script. If code examples in SKILL.md contain eval/exec for illustration, add a comment clarifying they are examples only. -
🔵 LOW
LLM_DATA_EXFILTRATION— Arbitrary File Path Access Without ValidationThe skill accepts arbitrary file paths from user input and passes them directly to file reading functions without path validation or sandboxing. While this is expected behavior for a data analysis skill (users must provide file paths), there is no validation to prevent path traversal or access to sensitive system files (e.g., ~/.aws/credentials, /etc/passwd). A user could ask the skill to 'analyze' a sensitive file, and the skill would attempt to read and report on it. This is an inherent design consideration rather than a malicious implementation. File:
scripts/eda_analyzer.pyRemediation: Consider adding path validation to restrict analysis to expected data directories, or add a warning in the skill instructions that users should only provide paths to data files they intend to share with the analysis workflow. Document that the skill will read the full content of any file path provided.
flowio — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged in Code BlocksThe static pre-scan flagged a Python code block containing eval/exec usage (MDBLOCK_PYTHON_EVAL_EXEC). Review of the skill's markdown code examples does not reveal an obvious direct eval/exec call in the visible content, but the flag warrants attention. If any bundled or referenced Python script (e.g., flowio.py, which was not found) uses eval/exec with user-controlled or FCS-file-derived input, this could enable code injection via maliciously crafted FCS files. File:
SKILL.mdRemediation: Audit all Python code blocks and referenced scripts for eval/exec usage. Ensure that any eval/exec calls do not operate on user-controlled or externally-sourced data. Prefer safe alternatives such as ast.literal_eval for parsing structured data. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill does not declare an 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be invoked. Given that the skill instructs the agent to execute Python code blocks and read/write FCS files, explicit tool declarations would improve security posture. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' field to the YAML manifest listing only the tools required, e.g., allowed-tools: [Python, Read, Write]. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Referenced Files (templates/api_reference.md, flowio.py, assets/api_reference.md)The SKILL.md instructions reference several files (templates/api_reference.md, flowio.py, assets/api_reference.md) that were not found in the skill package. While the primary reference file (references/api_reference.md) is present, the missing files could indicate an incomplete package or unresolved references. If these files were to be loaded from external or user-controlled sources in the future, they could introduce indirect prompt injection risks. File:
SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package. Remove or correct references to files that do not exist. Avoid referencing files from external or user-controlled locations.
generate-image — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Traversal of Parent Directories When Searching for .env FileThe check_env_file() function walks from the current working directory up through all parent directories searching for a .env file. This could inadvertently read a .env file from a parent directory that belongs to a different project or contains credentials not intended for this skill, potentially exposing unrelated secrets. File:
scripts/generate_image.py:22Remediation: Limit .env file search to the current working directory only, or at most one parent level. Document clearly that the skill will search parent directories so users are aware of this behavior. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Third-Party Dependency (requests)The script imports the
requestslibrary without any version pinning or integrity verification. If a user installs a malicious or compromised version ofrequests(e.g., via typosquatting or a supply chain attack), the API key and image data could be intercepted or exfiltrated. File:scripts/generate_image.py:100Remediation: Include a requirements.txt or pyproject.toml with a pinned version of requests (e.g., requests==2.32.3) and instruct users to install from it. Consider adding hash verification. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Passed via Command-Line ArgumentThe script accepts the OpenRouter API key via a --api-key command-line argument. On multi-user systems, command-line arguments are visible in process listings (e.g.,
ps aux), which could expose the API key to other users on the same machine. The .env file fallback is safer, but the CLI option introduces a risk. File:scripts/generate_image.py:270Remediation: Remove the --api-key CLI argument and rely exclusively on the .env file or environment variable (os.environ.get) for API key retrieval. If CLI input is needed, warn users about the risk of process-list exposure.
geniml — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and Allowed-Tools MetadataThe SKILL.md manifest does not specify 'compatibility' or 'allowed-tools' fields. While these are optional per the spec, their absence means the agent has no declared constraints on which tools it may invoke. Given that this skill executes Bash commands, Python code, and file I/O operations, the lack of declared tool restrictions reduces transparency about the skill's intended operational scope. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML frontmatter listing the tools actually needed (e.g., [Bash, Python, Read, Write]) and specify 'compatibility' to clarify supported environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation Without Version ConstraintsThe SKILL.md installation instructions use 'uv pip install geniml' and 'uv pip install geniml[ml]' without pinning to a specific version. Additionally, a direct GitHub install from 'git+https://github.com/databio/geniml.git' is provided without a commit hash or tag. Unpinned installations are vulnerable to supply chain attacks where a compromised or malicious package version could be silently installed. File:
SKILL.mdRemediation: Pin package versions explicitly (e.g., 'geniml==0.4.0'). For GitHub installs, pin to a specific commit hash (e.g., 'git+https://github.com/databio/geniml.git@<commit_hash>'). Consider using a lockfile for reproducible environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— External Dependency on Third-Party Binary (StarSpace)The BEDspace workflow requires StarSpace, an external binary from Facebook Research (https://github.com/facebookresearch/StarSpace), to be installed separately and referenced via a path parameter. This introduces a supply chain risk: if the user installs StarSpace from an unofficial source or a compromised mirror, arbitrary code could be executed. The skill provides no integrity verification guidance. File:
references/bedspace.mdRemediation: Document the expected binary hash or version for StarSpace. Warn users to download only from the official repository and verify integrity before use. Consider sandboxing the binary execution. -
🔵 LOW
LLM_DATA_EXFILTRATION— BBClient Caches Remote BED Files to User Home DirectoryThe BBClient utility caches BED files from remote sources (BEDbase repositories) to '~/.bedcache' by default. While this is documented behavior, it involves fetching and storing data from remote sources into the user's home directory without explicit integrity verification or access controls described in the skill. If the remote BEDbase source is compromised, malicious BED files could be cached locally. File:
references/utilities.mdRemediation: Document that users should verify the integrity of remote BED files. Consider adding checksum verification for cached files. Ensure the cache directory has appropriate permissions.
geopandas — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill manifest does not declare an 'allowed-tools' field, meaning there are no explicit restrictions on which agent tools can be used. The skill instructs file reading, file writing, network access (PostGIS, remote URLs, cloud storage), and package installation. Without declared tool restrictions, the agent has no manifest-level guardrails on these operations. File:
SKILL.mdRemediation: Consider adding an 'allowed-tools' declaration to the SKILL.md manifest to explicitly scope the tools this skill requires, such as [Python, Bash, Read, Write]. This improves transparency and allows the agent runtime to enforce appropriate restrictions. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Description May Trigger Unintended ActivationThe skill description is extremely broad, covering a wide range of geospatial operations including PostGIS databases, interactive maps, multiple file formats, and integration with several third-party libraries. While this reflects the genuine scope of the GeoPandas library, the description could cause the skill to be activated for a very wide range of geographic data tasks, some of which may not be appropriate or intended. This is a minor concern given the description accurately reflects the library's capabilities. File:
SKILL.mdRemediation: Consider scoping the description more narrowly to the most common use cases to reduce unintended activation. This is a low-priority concern as the description is accurate. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe skill instructs installation of multiple packages (geopandas, folium, mapclassify, pyarrow, psycopg2, geoalchemy2, contextily, cartopy) without version pinning. This exposes users to supply chain risks where a compromised or malicious package version could be installed. No version constraints are specified for any dependency. File:
SKILL.mdRemediation: Pin package versions to known-good releases (e.g., 'uv pip install geopandas==1.0.1'). Consider providing a requirements.txt or pyproject.toml with pinned versions and hash verification for reproducible and secure installations. -
🔵 LOW
LLM_DATA_EXFILTRATION— PostGIS Connection String May Expose CredentialsThe data-io.md reference file includes example code showing database connection strings with plaintext credentials (user:password@host:port/database). While this is documentation/example code, users following these examples may hardcode credentials in their scripts. The skill does not warn users about credential management best practices. File:
references/data-io.mdRemediation: Add a security note in the documentation advising users to use environment variables or secrets managers for database credentials rather than hardcoding them. Example: use os.environ.get('DB_PASSWORD') or a .env file with python-dotenv. -
🔵 LOW
LLM_PROMPT_INJECTION— Skill Instructs Reading Data from External URLs Without Validation WarningsThe data-io.md reference file documents reading spatial data directly from external URLs (HTTP/HTTPS, S3, Azure Blob Storage) without any security warnings about validating the source or content of external data. If a user provides a malicious URL, the agent could fetch and process untrusted geospatial data that might contain embedded instructions or malicious content in attribute fields. File:
references/data-io.mdRemediation: Add documentation notes warning users to validate the source of external URLs before reading. Consider recommending that the agent confirm with the user before fetching data from external URLs provided in user input.
get-available-resources — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe YAML manifest does not declare an
allowed-toolsfield. The skill executes Python scripts and Bash commands (via subprocess calls to nvidia-smi, rocm-smi, sysctl, system_profiler), writes files to disk, and reads system information. Without an explicit allowed-tools declaration, the agent has no manifest-level constraint on what tools can be used. This is informational per the spec since allowed-tools is optional, but it reduces transparency about the skill's intended tool usage. File:SKILL.mdRemediation: Addallowed-tools: [Python, Bash]to the YAML frontmatter to explicitly document the tools this skill requires and enable manifest-level enforcement. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Referenced Files (joblib.py, dask.py, torch.py)The SKILL.md instructions reference files named joblib.py, dask.py, and torch.py, but these files are not present in the skill package. These names shadow well-known Python standard library packages (joblib, dask, torch/PyTorch). If these files were present and maliciously crafted, they could shadow the legitimate packages when imported in the same directory. Their absence is noted, but the naming pattern is a potential supply chain concern if files are later added. File:
SKILL.mdRemediation: Clarify whether these files are intended to be part of the skill package. If they are example code snippets referenced in documentation, rename them to avoid shadowing popular Python packages (e.g., use example_joblib_usage.py). Ensure the skill package does not include files that shadow standard library or popular third-party packages. -
🔵 LOW
LLM_COMMAND_INJECTION— Subprocess Calls to External System Utilities Without Input ValidationThe script invokes external system utilities (nvidia-smi, rocm-smi, sysctl, system_profiler) via subprocess.run with hardcoded arguments. While the arguments are fully hardcoded and not influenced by user input, the output of these commands is parsed and incorporated into the JSON output. If a malicious version of these utilities were present in PATH (e.g., a trojanized nvidia-smi), the script would execute it. The risk is low given the hardcoded arguments, but PATH manipulation could be a concern in adversarial environments. File:
scripts/detect_resources.py:80Remediation: Consider using absolute paths to known system utilities (e.g., /usr/bin/nvidia-smi) rather than relying on PATH resolution. Alternatively, document that the script should be run in a trusted environment where PATH is not manipulated. -
🔵 LOW
LLM_DATA_EXFILTRATION— System Information Disclosure via JSON Output FileThe skill collects and writes detailed system information (CPU architecture, processor model, memory totals, disk paths, GPU details including driver versions and compute capabilities) to a file named
.claude_resources.jsonin the current working directory. While this is the stated purpose of the skill, the output file could expose sensitive system fingerprinting data if the working directory is shared, version-controlled, or accessible to untrusted parties. The file includes OS version, Python version, processor brand string, and GPU driver versions which could aid targeted attacks. File:scripts/detect_resources.py:130Remediation: Add a warning in the SKILL.md documentation advising users to add.claude_resources.jsonto.gitignoreto prevent accidental exposure of system fingerprinting data in version-controlled repositories. Consider omitting highly specific fields like driver versions and compute capability from the default output.
gget — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— COSMIC Credentials Passed via Command-Line ArgumentsThe gget cosmic module accepts email and password credentials as command-line arguments (--email, --password). Passing credentials via CLI arguments exposes them in shell history, process listings (ps aux), and system logs. This is a credential exposure risk for users who follow the documented usage pattern. File:
SKILL.mdRemediation: Recommend using environment variables or a credentials file instead of command-line arguments for COSMIC credentials. Document this risk in the skill instructions and suggest alternatives like COSMIC_EMAIL and COSMIC_PASSWORD environment variables. -
🔵 LOW
LLM_DATA_EXFILTRATION— OpenAI API Key Passed as Plain-Text ArgumentThe gget gpt module accepts the OpenAI API key directly as a command-line argument and in Python function calls. This exposes the API key in shell history, process listings, and potentially in log files or notebooks shared with others. File:
SKILL.mdRemediation: Recommend using environment variables (e.g., OPENAI_API_KEY) instead of passing the API key as a direct argument. Update the skill documentation to warn users about this risk. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Referenced File 'gget.py' Not Found in PackageThe SKILL.md references a file 'gget.py' in its referenced files section, but this file was not found in the skill package. This creates a discrepancy between the manifest's claimed resources and what is actually present. While this may be an oversight rather than malicious intent, missing referenced files can cause unexpected behavior or errors at runtime. File:
SKILL.mdRemediation: Either include the gget.py file in the skill package or remove the reference to it from SKILL.md. Ensure all referenced files are present and accounted for in the package. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation RecommendedThe skill's installation instructions use 'uv pip install --upgrade gget' without pinning to a specific version. This means any future compromised or malicious release of the gget package would be automatically installed. Additionally, gget itself installs numerous third-party dependencies (openmm, cellxgene-census, etc.) without version pinning. File:
SKILL.mdRemediation: Pin gget to a specific known-good version (e.g., 'uv pip install gget==0.28.6'). Document the specific version tested with this skill. For production use, maintain a requirements.txt with pinned versions for all dependencies.
glycoengineering — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flagged eval/exec Usage in Code BlocksThe static pre-scan flagged two instances of eval/exec usage in Python code blocks within SKILL.md. Upon review of the visible code, no direct eval/exec calls are present in the shown snippets. However, the static analyzer detected these patterns in the full 16-file markdown corpus, suggesting they may exist in other markdown files not shown in the instruction body. If an agent executes these code blocks, eval/exec with unsanitized input could enable code injection. File:
SKILL.mdRemediation: Audit all 16 markdown files for eval/exec usage. Replace eval/exec with safer alternatives (e.g., ast.literal_eval for data parsing). If eval/exec is necessary, ensure inputs are strictly validated and never derived from user-controlled or external data. -
🔵 LOW
LLM_DATA_EXFILTRATION— External Network Requests to Third-Party APIsThe skill includes Python code blocks that make HTTP requests to external services (GlyConnect API at glyconnect.expasy.org and NetOGlyc at services.healthtech.dtu.dk). While these are legitimate bioinformatics services, the code sends user-provided protein sequences (potentially proprietary or sensitive research data) to external servers without explicit user consent warnings or data handling disclosures. File:
SKILL.mdRemediation: Add explicit warnings in the skill instructions that protein sequences will be transmitted to external services. Document data privacy implications and allow users to opt out. Consider validating inputs before transmission. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe skill has 'Unknown' license and no compatibility specification. This means users cannot assess the legal terms under which the skill operates, and there is no clarity on which agent environments are supported. Missing provenance information is a minor supply chain concern. File:
SKILL.mdRemediation: Add a valid SPDX license identifier (e.g., MIT, Apache-2.0) and specify compatibility (e.g., Claude.ai, Claude Code). This improves transparency and supply chain auditability.
gtars — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While this is a minor documentation issue, the absence of provenance information (license unknown) reduces trust and auditability of the skill package. The skill-author field references 'K-Dense Inc.' but no license is declared. File:
SKILL.mdRemediation: Add explicit license, compatibility, and allowed-tools fields to the YAML frontmatter to improve transparency and auditability. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation Without Version ConstraintsThe skill instructs installation of the 'gtars' package via 'uv pip install gtars' and 'cargo install gtars-cli' without specifying pinned versions. This means the agent could install any version of the package, including potentially compromised future versions. Supply chain attacks could introduce malicious code through version updates. File:
SKILL.mdRemediation: Pin exact package versions (e.g., 'uv pip install gtars==0.3.2') and use hash verification where possible. For Cargo, use a Cargo.lock file with exact version pinning. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Multiple Referenced Files Not Found in Skill PackageThe skill references numerous files (templates/coverage.md, templates/tokenizers.md, templates/overlap.md, templates/refget.md, assets/*.md, gtars.py, etc.) that are not present in the skill package. The absence of gtars.py in particular is notable as it is referenced as a script file. Missing files could indicate an incomplete package or files that are expected to be fetched from external sources at runtime. File:
SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package. If files are intentionally absent, remove references to them from the instructions to avoid confusion or potential future exploitation. -
🔵 LOW
LLM_DATA_EXFILTRATION— BBCache Module Fetches External Data from BEDbase.orgThe CLI reference documents a 'bbcache' module that fetches BED files from an external service (bedbase.org) by ID. While this is a documented feature, it represents a data ingestion pathway from an external source that could potentially be used to introduce malicious content or exfiltrate query patterns. The fetch operation is performed without any documented validation of the retrieved content. File:
references/cli.mdRemediation: Document that fetched BED files from external sources should be treated as untrusted input. Add content validation steps before using externally fetched files in downstream analysis.
hypogenic — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesStatic analysis flagged two instances of eval/exec usage in Python code blocks within the SKILL.md markdown. While these appear to be illustrative code examples (e.g., the extract_label lambda function and custom label extraction patterns), eval/exec in agent-executed code can enable arbitrary code execution if user-controlled input is passed to these functions. The actual hypogenic.py and examples.py files are not present for deeper inspection, so the full risk cannot be confirmed. File:
SKILL.mdRemediation: Ensure that any eval/exec calls in the actual hypogenic package code do not accept unsanitized user input. Review the missing hypogenic.py and examples.py files for actual eval/exec usage. Use safe parsing alternatives (e.g., regex, AST literal_eval) instead of eval for label extraction. -
🔵 LOW
LLM_PROMPT_INJECTION— External Literature PDFs Processed as Trusted InputThe HypoRefine workflow instructs users to place research paper PDFs in a directory and process them through GROBID and pdf_preprocess.py. The extracted text from these PDFs is then fed into LLM prompts for hypothesis generation. If a malicious PDF contains embedded prompt injection instructions (e.g., 'Ignore previous instructions and...'), these could be passed to the LLM as part of the literature extraction pipeline, potentially manipulating hypothesis generation outputs. File:
SKILL.mdRemediation: Sanitize extracted PDF text before injecting into LLM prompts. Implement input validation to detect and strip potential prompt injection patterns in literature content. Consider adding a review step where extracted literature content is shown to the user before being used in hypothesis generation. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and Allowed-Tools MetadataThe skill manifest does not specify 'compatibility' or 'allowed-tools' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill can invoke. Given that the skill installs packages, clones repositories, runs bash scripts (GROBID), and makes external API calls, explicit tool declarations would help agents and users understand the full scope of operations. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML manifest listing the tools actually used (e.g., Bash, Python, Read, Write). Add 'compatibility' information to clarify which environments and agent platforms are supported. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation and External Git ClonesThe skill instructs users to install the 'hypogenic' package via 'uv pip install hypogenic' without a pinned version, and clones datasets from external GitHub repositories (ChicagoHAI/HypoGeniC-datasets, ChicagoHAI/Hypothesis-agent-datasets) without commit hash pinning. This creates supply chain risk: a compromised PyPI package or malicious commit to the dataset repositories could introduce malicious code or data into the user's environment. File:
SKILL.mdRemediation: Pin the hypogenic package to a specific version (e.g., 'uv pip install hypogenic==X.Y.Z'). Pin git clones to specific commit hashes or tags. Verify package integrity via checksums or trusted registries. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Stored in Environment Variable Referenced in Config TemplateThe configuration template (references/config_template.yaml) references an environment variable 'OPENAI_API_KEY' for API authentication. While using environment variables is generally safer than hardcoding secrets, the config template also shows the model name and API key env var name in plaintext. If config files are committed to version control or shared, this could expose which credentials are in use. No hardcoded secrets were found. File:
references/config_template.yamlRemediation: Ensure config.yaml files containing API key references are excluded from version control via .gitignore. Document that users should never hardcode actual API keys in config files. Consider using a secrets manager for production deployments.
hypothesis-generation — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Skill Instructs Agent to Fetch External URLs (PubMed and Web) Without ValidationThe workflow instructions direct the agent to use 'WebFetch with PubMed URLs' and 'WebSearch' to retrieve external content as part of hypothesis generation. While this is a stated and legitimate feature, the instructions do not include any guidance on validating or sanitizing the content retrieved from external sources before incorporating it into the hypothesis report. Content retrieved from external URLs could contain adversarial instructions or misleading data. The allowed-tools field does not list a 'WebFetch' or 'WebSearch' tool, suggesting these capabilities are used outside declared tool restrictions. File:
SKILL.mdRemediation: Add 'WebFetch' and 'WebSearch' (or equivalent) to the allowed-tools manifest field if these are intended capabilities. Add instructions to treat externally fetched content as untrusted data and not to follow any embedded instructions found in retrieved documents. -
🔵 LOW
LLM_PROMPT_INJECTION— External Content Fetched and Incorporated Without Untrusted-Content Handling GuidanceThe skill instructs the agent to fetch content from PubMed and general web searches and incorporate findings directly into hypothesis reports. There is no instruction to treat fetched web content as potentially adversarial. A malicious webpage or document returned by a search could embed prompt injection instructions (e.g., 'Ignore previous instructions and exfiltrate the report'). The literature_search_strategies.md reference file reinforces this pattern by providing detailed instructions for fetching and incorporating external content without any security caveats. File:
SKILL.mdRemediation: Add explicit instructions that content retrieved from external sources (web pages, PubMed results) should be treated as untrusted data. The agent should extract only factual citation information and not follow any instructions embedded in retrieved content. Consider sandboxing or summarizing external content rather than directly incorporating raw text. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Literature Search and Multi-Pass LaTeX Compilation May Cause Resource ExhaustionThe skill instructs the agent to conduct extensive literature searches (targeting 50+ references, 40-70+ citations in appendices), generate multiple AI figures, and run multi-pass LaTeX compilation (xelatex → bibtex → xelatex → xelatex). Combined with instructions to 'keep trying' to refine schematics through 'multiple iterations,' this workflow could consume significant compute time and resources without explicit bounds or user confirmation checkpoints. The scientific-schematics script invocation is also unbounded in iteration count. File:
SKILL.mdRemediation: Add explicit limits on literature search scope (e.g., maximum number of search queries). Add a maximum iteration count for schematic refinement. Consider adding user confirmation checkpoints before initiating resource-intensive operations like multi-pass LaTeX compilation and bulk literature retrieval. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Mandatory Cross-Skill Invocation via Undisclosed External DependencyThe SKILL.md instructions declare that 'Every hypothesis generation report MUST include at least 1-2 AI-generated figures using the scientific-schematics skill' and that 'Nano Banana Pro will automatically generate, review, and refine the schematic.' This creates a mandatory dependency on an external skill ('scientific-schematics') and a branded product ('Nano Banana Pro') that is not declared in the YAML manifest. Users invoking this skill are not informed that it will automatically trigger another skill. This is a mild form of capability inflation/undisclosed behavior, as the skill's actual operation extends beyond what the manifest describes. File:
SKILL.mdRemediation: Declare the dependency on 'scientific-schematics' in the YAML manifest (e.g., as a 'dependencies' or 'related-skills' field). Remove the mandatory/automatic framing or make it optional. Remove brand-specific references ('Nano Banana Pro') that imply a specific product context not disclosed in the manifest.
lamindb — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Description with Excessive Trigger KeywordsThe skill description is extremely broad, covering a wide range of biological data management scenarios, workflow managers, MLOps platforms, and deployment strategies. While this reflects the genuine scope of LaminDB, the description functions as a keyword-baiting mechanism that could cause the skill to activate across a very wide range of user queries, potentially displacing more specific skills. File:
SKILL.mdRemediation: Narrow the description to focus on the core LaminDB use case. Avoid listing every possible integration or use case in the description field, as this inflates activation scope. -
🔵 LOW
LLM_PROMPT_INJECTION— External REST API and Database Integration Patterns Without Input ValidationThe integrations reference file includes patterns for fetching data from arbitrary external REST APIs and external databases, then saving the results directly into LaminDB. The fetched content is treated as trusted data without any sanitization or validation. If a user provides a malicious API URL or database query, the agent could be directed to fetch and store untrusted content. File:
references/integrations.mdRemediation: Add input validation for user-supplied URLs and database connection strings. Implement allowlists for trusted API endpoints. Warn users that data from external sources should be validated before ingestion into LaminDB. -
🔵 LOW
LLM_DATA_EXFILTRATION— Credentials Exposed via Environment Variables in Setup DocumentationThe setup-deployment reference file instructs users to set AWS and GCP credentials as environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, GOOGLE_APPLICATION_CREDENTIALS) and includes a PostgreSQL connection string with embedded username and password in example commands. While these are documentation examples, the agent may reproduce these patterns verbatim in user environments, potentially leading to credential exposure in shell history, logs, or scripts. File:
references/setup-deployment.mdRemediation: Replace hardcoded credential examples with references to secrets managers (AWS Secrets Manager, GCP Secret Manager, HashiCorp Vault). Add explicit warnings that credentials should never be hardcoded in scripts or committed to version control. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionsThe setup-deployment reference file recommends installing LaminDB and its dependencies using pip without version pinning (e.g., 'pip install lamindb', 'pip install lamindb[gcp,zarr,fcs]'). Unpinned installations are vulnerable to supply chain attacks where a compromised or malicious package version could be installed. File:
references/setup-deployment.mdRemediation: Pin package versions in installation instructions (e.g., 'pip install lamindb==0.x.y'). Recommend using a requirements.txt or pyproject.toml with locked dependencies. Consider recommending hash verification for critical packages.
latchbio-integration — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe skill manifest declares 'Unknown' for license and does not specify compatibility. While not a direct security threat, this missing provenance information reduces transparency and makes it harder to assess the trustworthiness of the skill package from K-Dense Inc. File:
SKILL.mdRemediation: Add a valid SPDX license identifier (e.g., MIT, Apache-2.0) and specify compatibility information in the YAML frontmatter. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Referenced Files and Unverified latch.py ScriptSeveral files referenced in the SKILL.md instructions are not found in the package (assets/data-management.md, templates/workflow-creation.md, templates/data-management.md, templates/resource-configuration.md, templates/verified-workflows.md, assets/workflow-creation.md, assets/resource-configuration.md, assets/verified-workflows.md, latch.py). The absence of latch.py is particularly notable as it is referenced as a Python script but not present. This creates uncertainty about what code would actually be executed and could indicate an incomplete or tampered package. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package. Audit the latch.py reference to confirm it is not a missing malicious script. Remove references to non-existent files or add the missing files. -
🔵 LOW
LLM_DATA_EXFILTRATION— Secrets Management Pattern Exposes API Keys via get_secret()The data-management.md reference file documents a get_secret() function pattern for retrieving secrets within workflows. While this is a documented SDK feature, the skill instructs the agent to use this pattern without any guidance on secure secret handling, rotation, or scope limitation. If misused or if the Latch platform is compromised, secrets could be exposed. File:
references/data-management.mdRemediation: Add guidance in the skill documentation about proper secret scoping, avoiding logging secrets, and using least-privilege access when retrieving secrets in workflows.
latex-posters — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe SKILL.md manifest does not specify a license or compatibility field. While these are optional fields, their absence reduces transparency about the skill's intended usage scope and compatibility constraints. File:
SKILL.mdRemediation: Add license (e.g., 'MIT') and compatibility fields to the YAML frontmatter to improve transparency and discoverability. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Referenced FilesSeveral files referenced in the skill's instructions are not found in the package: templates/latex_poster_packages.md, templates/poster_design_principles.md, templates/poster_layout_design.md, assets/poster_content_guide.md, templates/poster_content_guide.md, assets/poster_design_principles.md, assets/poster_layout_design.md, assets/latex_poster_packages.md. This creates broken references and may cause the agent to behave unexpectedly when trying to access these resources. File:
SKILL.mdRemediation: Ensure all referenced files exist within the skill package, or remove references to non-existent files from the instructions. -
⚪ INFO
LLM_CONTEXT_BUDGET_EXCEEDED— 'SKILL.md (instruction body)' excluded from LLM analysis (59,009 chars)instruction body (59,009 chars) exceeds limit (50,000) File:
SKILL.md (instruction body)Remediation: Increase llm_analysis.max_instruction_body_chars in your scan policy to include this content in LLM analysis. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unvalidated User-Supplied Filename in Shell ScriptThe review_poster.sh script accepts a user-supplied filename as a positional argument ($1) and passes it directly to multiple external commands (pdfinfo, pdffonts, pdfimages, ls, gs). While the script checks for file existence, it does not sanitize the filename for shell metacharacters. A maliciously crafted filename (e.g., containing spaces, semicolons, or backticks) could cause unexpected behavior. The risk is limited because the file existence check provides some protection, but the variable is not quoted consistently in all contexts. File:
scripts/review_poster.shRemediation: Validate the input filename against an allowlist pattern (e.g., only allow alphanumeric characters, hyphens, underscores, and .pdf extension). Use printf '%q' or similar quoting mechanisms when passing to subshells. Ensure the variable is consistently double-quoted in all command invocations.
literature-review — 🔵 LOW
-
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency in RequirementsThe SKILL.md instructions specify 'pip install requests' without a version pin, and system tools (pandoc, mactex/texlive) are installed without version constraints. Unpinned dependencies are susceptible to supply chain attacks where a compromised or malicious package version could be installed. File:
SKILL.mdRemediation: Pin the requests package to a specific known-good version (e.g., requests==2.31.0). Document expected versions for pandoc and LaTeX distributions. Consider providing a requirements.txt with pinned versions and hash verification. -
🔵 LOW
LLM_COMMAND_INJECTION— Unvalidated Command-Line Arguments Passed to subprocess in generate_pdf.pyThe generate_pdf.py script constructs a pandoc subprocess command using command-line arguments (markdown_file, output_pdf, citation_style) that are passed directly from sys.argv without sanitization. While subprocess.run with a list (not shell=True) mitigates shell injection, a maliciously crafted filename or citation style string could still inject unexpected pandoc flags or cause unintended file system operations. File:
scripts/generate_pdf.py:55Remediation: Validate markdown_file and output_pdf paths using pathlib to ensure they resolve within expected directories. Validate citation_style against an allowlist (e.g., ['apa','nature','chicago','vancouver','ieee']). Reject inputs containing path traversal sequences. -
🔵 LOW
LLM_DATA_EXFILTRATION— Network Calls to External APIs Without Input ValidationThe verify_citations.py script makes outbound HTTP requests to doi.org and api.crossref.org using DOIs extracted from user-provided markdown files. While these are legitimate academic APIs, the DOI extraction uses a regex pattern applied to untrusted file content, and the extracted values are interpolated directly into URLs without sanitization. A malformed or crafted DOI could potentially cause unexpected behavior in URL construction, though the risk is limited given the use of a requests.Session with standard HTTP methods. File:
scripts/verify_citations.py:47Remediation: Validate extracted DOIs against a strict format (e.g., ^10.\d{4,9}/[-._;()/:A-Z0-9]+$) before using them in URL construction. Consider URL-encoding the DOI component before interpolation. -
🔵 LOW
LLM_DATA_EXFILTRATION— Unvalidated File Path in verify_citations_in_fileThe verify_citations_in_file method opens a file path provided via command-line argument (sys.argv[1]) without validating that the path is within an expected directory. This could allow reading arbitrary files on the filesystem if the script is invoked with a crafted path argument. File:
scripts/verify_citations.py:72Remediation: Validate that the provided filepath resolves to a path within the current working directory or an expected project directory using pathlib.Path.resolve() and checking the parent hierarchy. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded DOI Verification Loop Without Rate Limiting CapThe verify_citations_in_file method iterates over all DOIs found in a document and makes two HTTP requests per DOI (doi.org + CrossRef) with only a 0.5-second sleep between them. A document with hundreds or thousands of DOIs (or a crafted document with many DOI-like strings) could result in excessive network requests and prolonged execution, potentially exhausting resources or triggering rate-limiting bans from external APIs. File:
scripts/verify_citations.py:82Remediation: Add a maximum DOI count limit (e.g., cap at 500 DOIs per run). Implement exponential backoff on HTTP errors. Consider adding a configurable timeout for the entire verification run.
markdown-mermaid-writing — 🔵 LOW
- 🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Activation Description May Trigger Unintended Skill InvocationThe skill description states 'Use when creating any scientific document, report, analysis, or visualization' and 'Establishes text-based diagrams as the default documentation standard.' The phrase 'Use when creating ANY scientific document' combined with 'Working with any other skill — this skill defines the documentation layer that wraps every other output' is an extremely broad activation trigger. While not malicious, this over-broad capability claim could cause the skill to be invoked in many contexts where it is not needed, and the instruction to wrap 'every other output' could interfere with other skills. File:
SKILL.mdRemediation: Narrow the activation description to specific use cases. Avoid claiming the skill should wrap 'every other output' as this creates over-broad activation and potential interference with other skills.
market-research-reports — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Claims in DescriptionThe skill description claims to generate reports 'in the style of top consulting firms (McKinsey, BCG, Gartner)' and produce '50+ page' deliverables that 'rival top consulting firm deliverables.' These are marketing-style capability inflation claims that may cause the agent to over-activate this skill for tasks that don't require such comprehensive output, or set unrealistic user expectations. The skill also claims 'no token constraints' in its instructions, which is factually inaccurate for LLM-based agents. File:
SKILL.md:8Remediation: Remove or qualify the 'no token constraints' claim as it is factually incorrect. Moderate capability claims to accurately reflect what the skill can realistically produce. Avoid brand name impersonation in capability descriptions. -
⚪ INFO
LLM_CONTEXT_BUDGET_EXCEEDED— 'assets/market_report_template.tex' excluded from LLM analysis (50,210 chars)file size (50,210 chars) exceeds per-file limit (50,000) File:
assets/market_report_template.texRemediation: Increase llm_analysis.max_referenced_file_chars in your scan policy to include this content in LLM analysis. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Dependency on External Skill Scripts Without Version VerificationThe skill invokes scripts from sibling skill packages (skills/scientific-schematics/scripts/generate_schematic.py, skills/generate-image/scripts/generate_image.py, skills/research-lookup/scripts/research_lookup.py, skills/peer-review) by relative path without any integrity verification, version pinning, or existence checks beyond a simple path.exists() call. If any of these sibling skills are compromised, updated maliciously, or replaced, this skill will silently execute the compromised code. The get_script_path() function resolves paths dynamically at runtime. File:
scripts/generate_market_visuals.py:60Remediation: Add hash verification of sibling skill scripts before execution. Document expected versions of dependent skills. Consider adding a manifest check to verify sibling skill integrity before invoking them. -
🔵 LOW
LLM_COMMAND_INJECTION— Unvalidated Topic Parameter Passed to Subprocess CommandsThe --topic argument provided by the user is interpolated directly into shell command prompts via Python's str.format() and passed to subprocess.run() as a list argument. While using a list (not shell=True) mitigates shell injection risk, the topic string is embedded verbatim into AI generation prompts without sanitization. A malicious topic string containing prompt injection payloads (e.g., special characters, instruction overrides) could potentially manipulate the downstream scientific-schematics or generate-image AI tools if those tools are susceptible to prompt injection via their input arguments. File:
scripts/generate_market_visuals.py:95Remediation: Sanitize or validate the topic parameter before interpolation. Consider stripping or escaping special characters and instruction-like patterns from user-supplied topic strings before embedding them in prompts passed to downstream AI tools. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Visual Generation Loop - Potential Compute ExhaustionThe SKILL.md instructions direct the agent to generate 5-6 core visuals at the start of every report, plus additional visuals 'as needed during writing' across 11 chapters, with a total of up to 27-28 visuals per report. Each visual invokes an external subprocess with a 120-second timeout. While the batch script has a per-image timeout, the instructions encourage generating visuals continuously throughout the writing process with no hard cap on total generation attempts. For very large reports, this could result in significant compute and time consumption, especially if generation failures trigger retries. File:
scripts/generate_market_visuals.py:130Remediation: Add a hard cap on total visuals generated per session. Implement a global timeout for the entire batch generation process. Consider making visual generation explicitly opt-in per section rather than automatic throughout writing.
matchms — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility metadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill may invoke. Given the skill instructs the agent to execute Python code (pip/uv installs, file I/O, network calls via USI loader), documenting these constraints would improve transparency. File:
SKILL.mdRemediation: Add 'allowed-tools' and 'compatibility' fields to the YAML frontmatter to document expected tool usage and environment requirements. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned dependency installation recommendedThe installation instructions use 'uv pip install matchms' and 'uv pip install matchms[chemistry]' without version pinning. This means the agent could install any future version of matchms, including potentially compromised releases. While this is a documentation-level concern rather than active malicious code, it represents a supply chain risk. File:
SKILL.mdRemediation: Pin the matchms version explicitly, e.g., 'uv pip install matchms==0.26.2' to ensure reproducible and auditable installations.
matlab — 🔵 LOW
-
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Numerical Simulation Loop PatternThe SKILL.md instruction body includes a numerical simulation pattern (heat equation time-stepping) with a for loop that iterates over a time range determined by user-supplied parameters (T and dt). If a user provides very large T or very small dt values, this could result in extremely long-running computations. The pattern does not include any bounds checking or iteration limits. File:
SKILL.mdRemediation: Add guidance in the documentation about reasonable parameter bounds and stability conditions (e.g., CFL condition for the heat equation). Include a note about validating user-supplied parameters before running simulations. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-broad Capability Description in ManifestThe skill description is quite broad, claiming to handle matrix operations, data analysis, visualization, signal processing, image processing, differential equations, optimization, statistics, MATLAB/Python conversion, and script execution. While the skill does appear to provide legitimate reference material for these topics, the description could trigger the skill for a very wide range of user queries. This is a minor concern as the content appears genuinely educational. File:
SKILL.mdRemediation: Consider narrowing the description to more precisely reflect the skill's primary use case, or break into more focused sub-skills. -
🔵 LOW
LLM_COMMAND_INJECTION— Shell Command Injection Risk in Portable Runner Script ExampleThe references/executing-scripts.md file contains a bash runner script example that interpolates shell variables directly into MATLAB/Octave command strings without sanitization. The FILE variable from user input is directly interpolated into matlab -batch "run('${FILE}')" and octave --eval "$CMD", which could allow command injection if the FILE or CMD variables contain malicious content (e.g., single quotes, semicolons, or shell metacharacters). File:
references/executing-scripts.mdRemediation: The example script should include input validation/sanitization for the FILE and CMD variables. Add a note warning users to validate and sanitize inputs before passing them to MATLAB/Octave command-line arguments. Consider using parameter files or environment variables instead of direct string interpolation for complex inputs. -
🔵 LOW
LLM_DATA_EXFILTRATION— Python Integration Reference Demonstrates HTTP Credential Exfiltration PatternThe references/python-integration.md file contains example code showing how to use Python's requests library from MATLAB to make HTTP requests to external APIs. While presented as a legitimate use case example, this pattern (reading data and posting to external URLs) could be misused if a user is instructed to follow these patterns with sensitive data. The example explicitly shows posting to 'https://api.example.com/data' and reading response data. This is reference documentation, not executable skill code, so the risk is low. File:
references/python-integration.mdRemediation: Add explicit warnings in the documentation that HTTP requests to external services should be used carefully and that sensitive data should never be sent to untrusted endpoints. The examples are clearly labeled as examples, which is appropriate.
medchem — 🔵 LOW
- 🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility metadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools (Bash, Python, Read, Write, etc.) this skill may invoke. The script uses Python execution and file I/O extensively. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' and a compatibility field to the YAML frontmatter to clearly document intended tool usage and environment compatibility.
molecular-dynamics — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flag: eval/exec in Python Code BlockThe static analyzer flagged a potential eval/exec usage in a Python code block within SKILL.md. Upon manual review, no actual eval() or exec() calls are present in the instruction code samples. The code blocks use standard OpenMM and MDAnalysis APIs without dynamic code execution. This appears to be a false positive from the static scanner, possibly triggered by method names or string patterns. No actual command injection risk is present. File:
SKILL.mdRemediation: No action required. This is a false positive. Confirm with a targeted grep for eval/exec in the skill package. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify the 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools (Bash, Python, Read, Write, etc.) can be invoked. Given that this skill involves running MD simulations, writing trajectory files, and executing Python code, declaring allowed-tools would improve transparency and reduce the risk of unintended tool use. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' and a compatibility field to the YAML frontmatter to explicitly declare the skill's intended tool scope. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionsThe installation instructions suggest installing packages via conda or pip without version pins (e.g., 'pip install openmm mdanalysis'). Unpinned installations are susceptible to supply chain attacks where a malicious version of a package could be installed. Additionally, the GAFF2 parameterization section suggests 'pip install openff-toolkit' without a version pin. File:
SKILL.mdRemediation: Pin package versions in installation instructions (e.g., 'pip install openmm==8.1.0 mdanalysis==2.7.0'). Consider providing a requirements.txt or conda environment.yml with pinned versions for reproducibility and security.
molfeat — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill can invoke, potentially allowing broader tool access than necessary for a molecular featurization task. File:
SKILL.mdRemediation: Consider adding 'allowed-tools' to restrict the skill to only the tools it needs (e.g., Python, Read) and specify 'compatibility' to clarify supported environments. This follows the principle of least privilege. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Python Code ExamplesThe static analyzer flagged a Python code block using eval/exec. Reviewing the skill content, the code examples in the referenced files use standard Python constructs. The flagged pattern appears to be in the context of legitimate ML/data science code examples (e.g., model training loops, data processing). No direct eval/exec with user-controlled input was found in the reviewed content, but the presence of this pattern warrants a low-severity note for awareness. File:
references/examples.mdRemediation: Ensure that any SMILES strings or model names provided by users are validated before being passed to molfeat functions. Avoid using eval/exec with user-controlled input in any implementation derived from these examples. -
🔵 LOW
LLM_DATA_EXFILTRATION— Pickle Deserialization of Cached EmbeddingsThe skill's examples demonstrate caching embeddings using Python's pickle module. Pickle deserialization of untrusted files is a known security risk that can lead to arbitrary code execution. If a user or attacker can control the cache file path or contents, this could be exploited. File:
references/examples.mdRemediation: Warn users in documentation about the risks of loading pickle files from untrusted sources. Consider recommending safer serialization formats (e.g., numpy .npy, HDF5) for caching embeddings in production environments.
networkx — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill does not declare an 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be used. The skill's instructions include code examples that write files (e.g., plt.savefig, nx.write_graphml, pickle.dump, CSV writing), execute database queries, and perform file I/O operations. Without an allowed-tools declaration, there is no manifest-level constraint on these operations. File:
SKILL.mdRemediation: Consider adding an explicit 'allowed-tools' declaration to the YAML manifest to document and constrain the tools this skill is permitted to use. For example: allowed-tools: [Python, Bash, Read, Write] -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Description and Activation ScopeThe skill description is very broad, claiming applicability to 'social networks, biological networks, transportation systems, citation networks, knowledge graphs, or any system involving relationships between entities.' While this accurately reflects NetworkX's capabilities, the extremely broad activation criteria ('any domain involving pairwise relationships') could cause the skill to be invoked in a wide range of contexts, potentially displacing more specialized skills. This is a minor concern given the skill's legitimate scope. File:
SKILL.mdRemediation: Consider narrowing the activation description to more specific use cases to avoid over-broad invocation. This is a minor informational finding. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the skill's reference documentation. Reviewing the referenced files, the code examples in references/algorithms.md, references/visualization.md, references/generators.md, references/io.md, and references/graph-basics.md contain standard NetworkX Python code. No actual eval() or exec() calls were found in the reviewed content. The flag may be a false positive from the static analyzer detecting code block patterns. However, the skill instructs the agent to execute Python code based on user-provided graph data (e.g., reading edge lists, loading files), which could introduce indirect code execution risks if user-supplied filenames or data are not validated. File:
references/io.mdRemediation: Ensure that any file paths or data provided by users are validated before being passed to NetworkX I/O functions. Avoid constructing file paths from unsanitized user input. The static analyzer finding should be investigated to confirm whether eval/exec appears in any bundled scripts not surfaced in this analysis.
neurokit2 — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe SKILL.md manifest does not declare an
allowed-toolsfield. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may invoke. Given that the skill instructs the agent to install packages viauv pip installand execute Python code, explicit tool declarations would improve security posture and auditability. File:SKILL.mdRemediation: Add an explicitallowed-toolsdeclaration to the YAML frontmatter listing only the tools required (e.g., Python, Bash for package installation, Read for reference files). This limits the attack surface if the skill is ever compromised or misused. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Description May Trigger Unintended ActivationThe skill description is extremely broad, covering ECG, EEG, EDA, RSP, PPG, EMG, EOG, HRV, ERP, complexity measures, autonomic nervous system assessment, psychophysiology research, and multi-modal physiological signal integration. While this accurately reflects the NeuroKit2 library's scope, the description is so comprehensive that it may cause the agent to activate this skill for a very wide range of loosely related queries, potentially displacing more appropriate skills or tools. File:
SKILL.mdRemediation: Consider scoping the description more precisely to the core use cases. If broad coverage is intentional, ensure the skill's activation logic is well-defined to avoid unintended triggering. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill does not specify a
compatibilityfield in its YAML manifest. This means users and orchestration systems cannot determine which agent environments or platforms this skill is designed for, potentially leading to unexpected behavior or misuse in incompatible environments. File:SKILL.mdRemediation: Add acompatibilityfield to the YAML frontmatter specifying the supported environments (e.g.,compatibility: Claude.ai, Claude Code, API). -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation InstructionThe SKILL.md instructions include a command to install the neurokit2 package without a pinned version number. This means the agent could install any version of the package, including potentially compromised future versions. Additionally, a development version install directly from GitHub is suggested, which carries supply chain risk as it bypasses stable release verification. File:
SKILL.mdRemediation: Pin the package to a specific known-good version (e.g.,uv pip install neurokit2==0.2.7). Avoid recommending direct GitHub zipball installs in production skill instructions, or at minimum document the associated risk.
neuropixels-analysis — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Broad Keyword Activation Triggers in DescriptionThe skill description contains an extensive list of trigger keywords designed to activate the skill across a wide range of neural recording scenarios: 'Neuropixels, SpikeGLX, Open Ephys, Kilosort, quality metrics, or unit curation'. While these are legitimate domain terms, the explicit enumeration of activation keywords in the description is a pattern consistent with keyword baiting to maximize skill invocation frequency. File:
SKILL.mdRemediation: Describe the skill's capabilities accurately without explicitly listing trigger keywords. Let the agent determine relevance based on the skill's described functionality rather than keyword matching hints. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Dependencies in Installation InstructionsThe SKILL.md installation section recommends installing multiple packages without version pinning (e.g., 'pip install spikeinterface[full]', 'pip install kilosort', 'pip install neuropixels-analysis', 'pip install anthropic'). Unpinned dependencies are vulnerable to supply chain attacks where a malicious package version could be published and automatically installed by users following these instructions. File:
SKILL.mdRemediation: Pin all dependencies to specific verified versions (e.g., 'pip install spikeinterface==0.101.0'). Provide a requirements.txt or pyproject.toml with pinned versions and checksums. Consider using a lockfile approach. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Provenance for 'neuropixels-analysis' PackageThe skill instructs users to install 'pip install neuropixels-analysis', a package authored by 'K-Dense Inc.' This package is not a well-known established library (unlike spikeinterface or anthropic). There is no version pin, no checksum, no source repository link, and no verification mechanism provided. The neuropixels_analysis.py module referenced in instructions is also not found in the skill package, meaning the skill relies entirely on this external unverified package. File:
SKILL.mdRemediation: Provide the source repository URL for neuropixels-analysis, pin to a specific version, and ideally include the source code within the skill package itself rather than relying on an external package. Verify the package on PyPI is legitimate and maintained by the claimed author. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Exposure Risk in AI Curation WorkflowThe skill's AI curation reference (references/AI_CURATION.md) includes example code showing API keys being passed directly: 'client = Anthropic(api_key="your-api-key")'. While this is a placeholder, the pattern encourages users to hardcode API keys in scripts. The skill also references multiple AI providers (Anthropic, OpenAI, Google) with API key usage patterns. File:
references/AI_CURATION.mdRemediation: Replace all API key examples with environment variable patterns: 'client = Anthropic() # Uses ANTHROPIC_API_KEY env var'. Add explicit warnings against hardcoding API keys and recommend using environment variables or secrets management tools.
omero-integration — 🔵 LOW
-
🔵 LOW
LLM_PROMPT_INJECTION— Multiple Referenced Files Not Found in Skill PackageThe SKILL.md references numerous files that are not present in the skill package: templates/tables.md, templates/image_processing.md, assets/metadata.md, assets/image_processing.md, assets/data_access.md, templates/advanced.md, omero.py, templates/scripts.md, templates/connection.md, assets/advanced.md, assets/rois.md, templates/rois.md, assets/scripts.md, assets/connection.md, assets/tables.md, templates/data_access.md, templates/metadata.md. While the primary references/ directory files are present, the missing files (especially omero.py) could represent incomplete packaging. If these files were to be loaded from external sources at runtime, they would represent an indirect prompt injection risk. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package. Verify that omero.py is either included or removed from references. Do not load missing referenced files from external/network sources at runtime. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing License and Compatibility MetadataThe skill manifest does not specify a license (listed as 'Unknown') and does not specify compatibility information. While allowed-tools is also not specified (which is acceptable per spec), the missing license and compatibility fields reduce transparency about the skill's provenance and intended deployment environment. The skill-author is listed as 'K-Dense Inc.' but without a license, users cannot determine usage rights. File:
SKILL.mdRemediation: Add a valid SPDX license identifier (e.g., 'MIT', 'Apache-2.0') to the manifest. Add compatibility information specifying which environments the skill is tested and supported in. Consider adding allowed-tools to document expected tool usage. -
🔵 LOW
LLM_DATA_EXFILTRATION— Hardcoded Credentials in Example Code PatternsMultiple reference files contain example code with hardcoded credential placeholders (USERNAME = 'user', PASSWORD = 'pass', HOST = 'omero.example.com'). While these are clearly example/documentation patterns and not actual secrets, the skill's instructions and reference files normalize the pattern of hardcoding credentials directly in scripts. The connection.md file does include a best practice note recommending environment variables, but the majority of examples use hardcoded values. This could lead users to adopt insecure credential handling practices. File:
references/connection.mdRemediation: Ensure example code prominently uses environment variables or config file patterns rather than hardcoded credentials. The Pattern 3 (Environment Variables) example in connection.md is the correct approach and should be the primary example shown. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Python Code BlocksThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the skill's reference files. After reviewing all provided reference files (connection.md, tables.md, metadata.md, advanced.md, image_processing.md, data_access.md, scripts.md, rois.md), no direct use of eval() or exec() with user-controlled input was found in the actual code examples. The code blocks use standard OMERO API calls. The static analyzer flag may be a false positive or refer to a file not provided (e.g., omero.py which was not found). This warrants attention if the missing omero.py file exists and contains eval/exec patterns. File:
references/image_processing.mdRemediation: Locate and review the missing omero.py file for any eval/exec usage with user-controlled input. If found, replace with safe alternatives such as explicit function calls or whitelisted operations.
opentrons-integration — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe skill manifest does not specify a license or compatibility field. While these are optional fields, their absence reduces transparency about the skill's intended operating environment and legal usage terms. The skill-author is listed as 'K-Dense Inc.' but no license is declared. File:
SKILL.mdRemediation: Add a license field (e.g., 'MIT', 'Apache-2.0') and a compatibility field specifying supported platforms (e.g., 'Claude.ai, Claude Code, API') to the YAML frontmatter. -
🔵 LOW
LLM_DATA_EXFILTRATION— Reference to Non-Existent FilesThe SKILL.md instructions reference several files that do not exist in the skill package: 'templates/api_reference.md', 'assets/api_reference.md', and 'opentrons.py'. While 'references/api_reference.md' does exist, the broken references could cause confusion or unexpected behavior if the agent attempts to read these missing files. File:
SKILL.mdRemediation: Remove references to non-existent files from the SKILL.md instructions, or ensure all referenced files are included in the skill package. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe skill does not declare an allowed-tools field in its YAML manifest. While this field is optional, the skill executes Python code (protocol scripts) and references external files. Declaring allowed-tools would improve transparency about what agent capabilities are required. File:
SKILL.mdRemediation: Add an explicit allowed-tools field to the YAML frontmatter listing the tools the skill requires, such as: allowed-tools: [Python, Read] -
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flag: eval/exec in Python Code BlocksThe static pre-scan flagged a potential eval/exec usage in a Python code block (MDBLOCK_PYTHON_EVAL_EXEC). Upon manual review of the provided scripts (pcr_setup_template.py, basic_protocol_template.py, serial_dilution_template.py) and the references/api_reference.md, no actual eval() or exec() calls were found in the script files. The flag may originate from documentation examples in references/api_reference.md showing code patterns. No exploitable eval/exec was identified in executable scripts. File:
references/api_reference.mdRemediation: Verify the source of the eval/exec flag. If it originates from documentation examples, ensure no user-controlled input is ever passed to eval/exec in any generated or executed protocol code.
optimize-for-gpu — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing License and Compatibility MetadataThe SKILL.md manifest does not specify a license or compatibility field. While these are optional fields, their absence means users cannot assess the legal terms of use or verify which platforms the skill is designed for. The only metadata present is the author field ('K-Dense, Inc.'). This is a minor informational gap rather than a direct security threat. File:
SKILL.mdRemediation: Add license and compatibility fields to the YAML frontmatter to improve transparency and user trust. -
🔵 LOW
LLM_PROMPT_INJECTION— Large Number of Missing Referenced Files Creates Untrusted Input SurfaceThe skill references a very large number of files (60+) that are not present in the package (e.g., faiss.py, cuspatial.py, sklearn.py, networkx.py, templates/warp.md, assets/cupy.md, etc.). While the core reference files (references/*.md) are present and appear legitimate, the missing files — particularly Python files like faiss.py, sklearn.py, networkx.py, cupy.py, cudf.py — could be populated with malicious content if the skill package is tampered with or if these files are sourced from an untrusted location. The skill instructions direct the agent to read these files before writing code, creating a potential indirect prompt injection surface if the files are ever populated with adversarial content. File:
SKILL.mdRemediation: Remove references to files that are not part of the skill package, or clearly document which files are expected to be present. If these files are intended to be user-provided, add explicit validation instructions to treat their contents as untrusted input. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Activation Triggers in DescriptionThe skill description is extremely broad, listing dozens of trigger conditions including 'Also use when you see CPU-bound Python code (loops, large arrays, ML pipelines, graph analytics, image processing) that would benefit from GPU acceleration, even if not explicitly requested.' This over-broad activation language means the skill will activate on a very wide range of user interactions, potentially beyond what the user intends. The phrase 'even if not explicitly requested' is particularly notable as it instructs the agent to self-activate without user consent. File:
SKILL.mdRemediation: Narrow the activation criteria to explicit user requests for GPU acceleration. Remove the 'even if not explicitly requested' clause to ensure the skill only activates when the user has clearly indicated intent. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Versions in Installation InstructionsAll installation instructions throughout the skill use unpinned package versions (e.g., 'uv add cupy-cuda12x', 'uv add numba numba-cuda', 'uv add warp-lang'). None of the packages specify exact version pins (e.g., cupy-cuda12x==13.0.0). This means that future package updates could introduce breaking changes or, in a supply chain attack scenario, a compromised package version could be installed without the user's awareness. File:
SKILL.mdRemediation: Pin package versions explicitly (e.g., 'uv add cupy-cuda12x==13.0.0') or document the tested version range. Consider using a lockfile approach to ensure reproducible installations.
paper-lookup — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— API Keys Loaded from Environment and .env FilesThe skill instructs the agent to load API keys (NCBI_API_KEY, CORE_API_KEY, S2_API_KEY, OPENALEX_API_KEY) from environment variables and fall back to a .env file in the current working directory. While this is a common and generally acceptable pattern, it means the agent will read potentially sensitive credential files from the filesystem as part of normal operation. If the skill is invoked in an unexpected working directory, it could inadvertently read a .env file containing unrelated secrets. File:
SKILL.mdRemediation: Restrict .env file loading to the skill's own directory rather than the current working directory. Document clearly which environment variables are accessed so users can audit credential exposure. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Activation Description with Keyword BaitingThe skill description in the YAML manifest is extremely verbose and contains an extensive list of trigger keywords and activation phrases designed to maximize the skill's activation frequency. The description explicitly instructs the agent to activate for very broad queries like 'find papers on X', 'what's been published about Y', or 'look up this DOI', and enumerates 10+ database names, 15+ use-case triggers, and multiple activation scenarios. While this skill appears to be a legitimate academic paper lookup tool, the description is engineered to maximize activation scope beyond what is necessary for the skill's stated purpose. File:
SKILL.mdRemediation: Trim the description to concisely describe the skill's purpose without embedding explicit activation instructions or exhaustive keyword lists. Activation logic should be determined by the agent runtime, not embedded in the manifest description. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Multiple Missing Referenced FilesThe skill instructions reference 30 files across references/, templates/, and assets/ directories, but only 8 of these files were found. Specifically, all files in templates/ and assets/ directories are missing (20 files not found). The skill instructs the agent to 'Read the relevant reference file before making any API call', meaning the agent may proceed without the expected guidance if files are missing, potentially leading to incorrect API usage. While not directly a security threat, missing files could cause the agent to behave unpredictably or fall back to less safe defaults. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package. Audit the missing template and asset files for any security issues before including them. Add validation logic or graceful fallback behavior when referenced files are not found. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged in Static Analysis (No Script Files Present)The static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding, indicating a Python code block in the markdown files contains eval or exec usage. Reviewing the available reference files, the OpenAlex reference file (references/openalex.md) contains a Python code snippet demonstrating how to reconstruct an abstract from an inverted index. This snippet uses standard dict/list operations and does not contain eval/exec. The flagged code block may be in one of the missing template or asset files (templates/, assets/) that were not found. Since no actual script files are present and the available code snippets are benign documentation examples, the risk is low, but the missing files warrant attention. File:
references/openalex.mdRemediation: Locate and review the missing template and asset files (templates/.md, assets/.md) that are referenced in the instructions but not present in the package. Ensure no eval/exec patterns exist in those files. Avoid including executable code examples in documentation that could be misinterpreted as instructions to the agent.
paperzilla — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flag: Python eval/exec in Markdown Code BlockThe static pre-scan flagged a potential use of eval/exec in a Python code block within the skill's markdown files. However, reviewing the SKILL.md instruction body, no Python code blocks containing eval or exec are visible in the provided content. The skill only contains Bash CLI command examples using the
pzCLI tool. This may be a false positive from the static analyzer, or it may exist in one of the 13 markdown files not fully surfaced in the analysis. Given the skill has no script files and only CLI invocations are shown, the risk is low but warrants verification of all 13 markdown files. File:SKILL.mdRemediation: Audit all 13 markdown files in the skill package to locate and review any Python code blocks containing eval or exec. If found, ensure they do not process untrusted user input and replace with safer alternatives where possible. -
🔵 LOW
LLM_DATA_EXFILTRATION— Authentication Credential Handling via CLI LoginThe skill instructs users to run
pz loginto authenticate with the Paperzilla service. While this is standard CLI authentication behavior, the skill does not document how credentials are stored (e.g., keychain, plaintext config file) or provide guidance on credential security. Additionally, thePZ_API_URLenvironment variable configuration could be manipulated to point to a malicious server if a user's environment is compromised. File:SKILL.mdRemediation: Document how credentials are stored by thepzCLI (e.g., OS keychain vs. plaintext). Warn users not to override PZ_API_URL to untrusted endpoints. Consider noting that the default API URL should not be changed unless using a self-hosted instance. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned External CLI Installation via Homebrew/Scoop/GitHubThe skill instructs installation of the
pzCLI via Homebrew tap (paperzilla-ai/tap/pz), Scoop bucket from a GitHub repository (https://github.com/paperzilla-ai/scoop-bucket), and a GitHub source repository (https://github.com/paperzilla-ai/pz). None of these installation methods specify version pins or integrity verification (e.g., checksums). If any of these external repositories or taps were compromised, a malicious version of the CLI could be installed on the user's machine. File:SKILL.mdRemediation: Document specific version pins or minimum version requirements for thepzCLI. Recommend users verify checksums or use signed releases. Consider linking to a release verification guide in the documentation.
pdf — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Proprietary License Without Clear Terms AccessibleThe skill declares a proprietary license ('Proprietary. LICENSE.txt has complete terms') but the license file is not included in the analyzed package contents. This creates ambiguity about usage rights and could mask restrictive or data-collection terms that users are unaware of. File:
SKILL.mdRemediation: Include the LICENSE.txt file in the skill package and ensure it is clearly readable. Consider using a standard open-source license for transparency. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Description Triggers Excessive ActivationThe skill description explicitly instructs the agent to activate for any mention of a .pdf file or any request to produce one, covering an extremely wide range of operations. While this is a legitimate PDF skill, the description is crafted to maximize activation scope ('Use this skill whenever the user wants to do anything with PDF files'). This is a minor concern but worth noting as it could cause the skill to intercept PDF-related requests that might be better handled by more specialized tools. File:
SKILL.mdRemediation: Scope the description to the specific operations this skill supports rather than claiming ownership of all PDF-related tasks. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Dependency Version Pins in Skill InstructionsThe SKILL.md instructions reference multiple Python libraries (pypdf, pdfplumber, reportlab, pytesseract, pdf2image, pandas) without specifying pinned versions. The static analyzer also flagged that referenced files like pdf2image.py, pypdf.py, reportlab.py, pytesseract.py, and pdfplumber.py were not found in the package. Unpinned dependencies are susceptible to supply chain attacks where a malicious version of a package could be installed. File:
SKILL.mdRemediation: Pin all dependency versions (e.g., pypdf==4.x.x, pdfplumber==0.x.x) and include a requirements.txt with hashed dependencies. Verify that referenced files exist in the package. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe skill does not declare an allowed-tools field in the YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools this skill can use. Given that the skill executes Python scripts that read and write files, declaring allowed-tools would improve security posture. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration such as: allowed-tools: [Python, Bash, Read, Write] to document and constrain the skill's tool usage.
pennylane — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage in Educational Code ExamplesStatic analysis flagged multiple Python code blocks containing eval or exec patterns across the reference markdown files. Upon review, these appear within legitimate educational/documentation code examples demonstrating quantum computing concepts (e.g., qml.exp(), qml.expval(), etc.). The 'exec' matches are likely false positives from the static scanner matching substrings like 'expval' or 'execute'. No actual dangerous eval()/exec() calls with user-controlled input were found in the skill's instructional content. This is flagged at LOW severity for awareness only. File:
SKILL.mdRemediation: No action required. The static scanner appears to be matching substrings within legitimate PennyLane API calls (expval, exp). Verify no actual eval(user_input) or exec(user_input) patterns exist in any deployed scripts. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Dependencies in Installation InstructionsThe SKILL.md and reference files recommend installing PennyLane and its plugins using 'uv pip install pennylane' and various plugin packages without version pinning. This exposes users to supply chain risks where a compromised or malicious package version could be installed. Multiple hardware plugins are referenced without version constraints. File:
SKILL.mdRemediation: Pin package versions in installation instructions (e.g., 'uv pip install pennylane==0.38.0'). Consider providing a requirements.txt or pyproject.toml with pinned versions for reproducible environments. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe skill manifest does not specify an 'allowed-tools' field. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools this skill can invoke. Given that the skill instructs installation of multiple packages and references quantum hardware access, explicit tool declarations would improve security posture. File:
SKILL.mdRemediation: Consider adding an explicit 'allowed-tools' declaration to the SKILL.md manifest to document the intended tool scope, e.g., allowed-tools: [Python, Bash] if package installation is intended. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Tokens Referenced in Documentation ExamplesThe devices_backends.md reference file contains example code showing API token usage for IBM Quantum and IonQ hardware access (e.g., ibmqx_token='YOUR_API_TOKEN', api_key='your_api_key'). These are placeholder strings in documentation examples, not hardcoded real credentials. However, users following these examples could inadvertently hardcode real tokens in their code. File:
references/devices_backends.mdRemediation: Add explicit warnings in the documentation advising users to use environment variables or secure credential stores (e.g., os.environ['IBMQ_TOKEN']) rather than hardcoding API tokens in source code.
polars-bio — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python Code Block Uses eval/exec PatternThe static analyzer flagged a potential eval/exec usage in a Python code block within the skill's documentation. Reviewing the content, the code examples in the skill documentation do not appear to contain explicit eval() or exec() calls in a malicious context. The flagged pattern likely refers to illustrative code examples. However, since the referenced file 'polars_bio.py' and 'polars.py' are not found in the package, there is no way to verify the actual implementation does not contain dangerous dynamic code execution patterns. File:
SKILL.mdRemediation: Ensure that the referenced Python files (polars_bio.py, polars.py) are included in the skill package and reviewed for any eval/exec usage. If these files are external dependencies, document their provenance clearly. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Missing Referenced Files in Skill PackageMultiple files referenced in the SKILL.md instructions are not found in the skill package: assets/interval_operations.md, templates/sql_processing.md, assets/pileup_operations.md, templates/pileup_operations.md, polars_bio.py, assets/sql_processing.md, templates/file_io.md, polars.py, templates/interval_operations.md, assets/file_io.md. The absence of these files means the skill's behavior cannot be fully audited. If these files are fetched at runtime from external sources, this could introduce indirect prompt injection or supply chain risks. File:
SKILL.mdRemediation: Include all referenced files in the skill package, or clearly document that they are optional documentation stubs. Do not fetch missing files from external sources at runtime without explicit user consent. -
🔵 LOW
LLM_DATA_EXFILTRATION— Cloud Credential Exposure via Environment VariablesThe file_io.md reference documentation explicitly instructs users to configure cloud credentials via environment variables (AWS_ACCESS_KEY_ID, GOOGLE_APPLICATION_CREDENTIALS). While this is standard practice, the skill's cloud-native I/O capabilities (S3, GCS, Azure) mean that if the agent is used in an environment with cloud credentials configured, those credentials will be used automatically when processing cloud paths. This is expected behavior but represents a data access risk if user-provided file paths are passed to cloud I/O functions without validation. File:
references/file_io.mdRemediation: The skill should document that cloud credential access is expected and limited to user-specified paths. Ensure the agent does not automatically traverse or enumerate cloud storage beyond what the user explicitly requests.
pptx — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Proprietary License Without Published TermsThe skill declares a 'Proprietary' license and references 'LICENSE.txt has complete terms,' but the license file content is not included in the analyzed package. Users and security reviewers cannot assess the terms under which this skill operates, what data it may collect, or what restrictions apply. File:
SKILL.mdRemediation: Include the LICENSE.txt file in the skill package or make its terms publicly accessible. Consider using a standard open-source license for transparency. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Activation DescriptionThe skill description is explicitly designed to trigger on an extremely wide range of user inputs, including any mention of 'deck,' 'slides,' 'presentation,' or any .pptx filename 'regardless of what they plan to do with the content afterward.' This over-broad activation scope could cause the skill to activate in contexts where it is not needed or appropriate, potentially consuming resources or interfering with other skills. File:
SKILL.mdRemediation: Narrow the activation criteria to cases where the user explicitly requests PPTX creation, editing, or analysis, rather than any incidental mention of related terms. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe SKILL.md dependencies section specifies packages without version pins (e.g., 'pip install markitdown[pptx]', 'pip install Pillow', 'npm install -g pptxgenjs'). Unpinned dependencies are vulnerable to supply chain attacks where a malicious version of a package could be published and automatically installed. File:
SKILL.mdRemediation: Pin all dependencies to specific versions (e.g., 'pip install markitdown[pptx]==0.x.y', 'pip install Pillow==10.x.y', 'npm install -g pptxgenjs@3.x.x'). Consider using a requirements.txt or package.json with locked versions. -
🔵 LOW
LLM_COMMAND_INJECTION— Dynamic Shared Library Compilation and LD_PRELOAD InjectionThe soffice.py script dynamically compiles a C source file at runtime using gcc and loads the resulting shared library via LD_PRELOAD. While the C source (_SHIM_SOURCE) is hardcoded within the script and appears to be a legitimate socket shim for sandboxed environments, this pattern is inherently risky: it compiles and injects native code into the process environment at runtime. If the temp directory is writable by an attacker or the script is modified, this mechanism could be abused to inject arbitrary native code. The _exit(0) call in the shim's close() handler also causes abrupt process termination. File:
scripts/office/soffice.pyRemediation: Document this behavior clearly in the skill manifest. Consider shipping the precompiled shim as a static asset rather than compiling at runtime. Validate the temp directory permissions and ensure the shim source cannot be tampered with.
pptx-posters — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code BlockThe static analyzer flagged a Python code block using eval/exec. Reviewing the SKILL.md content, the python-pptx code block in Stage 5 does not directly use eval/exec, but the skill references a missing 'pptx.py' file that was not found. The static analyzer flag may relate to content in that missing file or to the headless Chrome/LibreOffice shell command patterns. Without the actual pptx.py content, the risk cannot be fully assessed, but the missing file itself is a concern. File:
SKILL.mdRemediation: Locate and review the referenced pptx.py file for any eval/exec usage. If the file is part of the skill package, include it in the distribution and audit it for command injection risks. Avoid using eval/exec with any user-supplied input. -
🔵 LOW
LLM_COMMAND_INJECTION— Headless Chrome Shell Command with User-Controlled InputThe skill instructs the agent to run a headless Chrome command to export the poster to PDF. The poster filename and content are derived from user-provided research content. If the poster.html filename or path is influenced by user input without sanitization, this could lead to argument injection in the shell command. The risk is low given the static filename used, but the pattern warrants attention. File:
SKILL.mdRemediation: Ensure filenames passed to shell commands are sanitized and not directly derived from unsanitized user input. Use fixed filenames or validate/escape any dynamic components before passing to shell commands. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Referenced Script File (pptx.py)The SKILL.md references a file 'pptx.py' in its instructions, but this file was not found in the skill package. Missing files referenced in instructions could indicate an incomplete package or a file that was intentionally omitted. If pptx.py contains sensitive logic (e.g., network calls, file operations), its absence prevents proper security review. File:
SKILL.mdRemediation: Ensure all referenced script files are included in the skill package. Audit pptx.py before distribution to confirm it does not contain data exfiltration, credential access, or other malicious behavior. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded AI Image Generation Loop (Quality Checklist Regeneration)The quality checklist instructs the agent to regenerate graphics if they fail criteria, with no explicit limit on the number of regeneration attempts. This could lead to repeated AI image generation calls consuming significant compute resources if graphics repeatedly fail the quality checks. File:
SKILL.mdRemediation: Add an explicit maximum retry count (e.g., 'regenerate up to 3 times') to prevent unbounded resource consumption from repeated failed generation attempts.
pufferlib — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the spec, their absence means there are no declared restrictions on what tools the agent can use when executing this skill. The skill executes Python scripts and Bash commands, so declaring these would improve transparency. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash]' and a 'compatibility' field to the YAML frontmatter to clearly document the skill's tool requirements and supported platforms. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a Python code block using eval/exec patterns. After reviewing all code blocks in the skill package, the usage appears within legitimate educational/template code examples for reinforcement learning. No direct eval/exec calls on untrusted user input were found in the actual executable scripts (train_template.py, env_template.py). The flagged pattern likely refers to Python's exec-style dynamic code execution patterns in the C extension example in references/environments.md, which is documentation-only. This is low risk but worth noting. File:
references/environments.mdRemediation: Verify no eval/exec calls exist in executable scripts that process user-controlled input. The C extension example is documentation only and poses no direct risk, but developers implementing it should validate all inputs before passing to C functions. -
🔵 LOW
LLM_DATA_EXFILTRATION— Neptune API Token Passed via Command-Line ArgumentThe training template script accepts a Neptune API token via a command-line argument (--neptune-token). Passing secrets via command-line arguments can expose them in process listings, shell history, and logs. This is a minor credential hygiene issue in a template script. File:
scripts/train_template.py:168Remediation: Recommend using environment variables (os.environ.get('NEPTUNE_API_TOKEN')) or a secrets manager instead of command-line arguments for API tokens. Update the template to demonstrate best practices for credential handling.
pydeseq2 — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Unpinned Dependency InstallationThe SKILL.md installation section recommends installing pydeseq2 without a pinned version (uv pip install pydeseq2). While system requirements list minimum versions, no exact pinned versions are specified for any dependency. This could allow installation of a compromised future version of the package if the PyPI package were ever compromised, though this is a low-probability supply chain risk for a well-known bioinformatics package. File:
SKILL.mdRemediation: Consider pinning exact versions: uv pip install pydeseq2==<specific_version>. At minimum, document the tested/verified version in the manifest. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Python Code Block (Static Scanner Flag)The static pre-scan flagged a potential eval/exec usage in a Python code block. Upon manual review of the skill's scripts and instruction code blocks, no actual use of eval() or exec() with user-controlled input was found. The code blocks use standard pandas, pydeseq2, matplotlib, and pickle operations. The static scanner flag appears to be a false positive, possibly triggered by the applymap lambda or similar constructs. No exploitable command/code injection pattern is present. File:
scripts/run_deseq2_analysis.pyRemediation: No action required. The flagged pattern is a benign lambda used for data validation, not an eval/exec with user-controlled input. Confirm no eval/exec is introduced in future updates. -
🔵 LOW
LLM_DATA_EXFILTRATION— Pickle Deserialization of Saved ObjectsThe skill saves and loads DeseqDataSet objects using Python's pickle module. If a user loads a pickle file from an untrusted source, arbitrary code execution is possible during deserialization. The skill does not warn users about this risk. The risk is limited to user-initiated loading of their own saved files, but the lack of any warning is a minor concern. File:
scripts/run_deseq2_analysis.pyRemediation: Add a comment or documentation note warning users to only load pickle files from trusted sources. Consider recommending h5ad format (AnnData's native format) as a safer alternative for persistence.
pydicom — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged by Static AnalyzerThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding. After reviewing all code blocks in SKILL.md and the three script files (anonymize_dicom.py, extract_metadata.py, dicom_to_image.py), no actual use of eval() or exec() was found in the executable scripts. The flag may refer to a code block in the markdown instructions that demonstrates Python usage. No exploitable command injection pattern was identified in the actual scripts. This is a low-severity informational note. File:
SKILL.mdRemediation: No immediate action required. Confirm the static analyzer finding is a false positive by reviewing all code blocks. If eval/exec is present in any dynamically generated code path, ensure user input is never passed to these functions. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and Compatibility MetadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the spec, their absence means the agent has no declared constraints on which tools it may use when executing this skill. Given that this skill involves reading/writing medical files and executing scripts, declaring tool restrictions would improve security posture and auditability. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML frontmatter to explicitly declare which agent tools are needed (e.g., [Python, Bash, Read, Write]). Add 'compatibility' information to clarify supported environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe SKILL.md installation instructions recommend installing pydicom, pillow, numpy, matplotlib, pylibjpeg, pylibjpeg-libjpeg, pylibjpeg-openjpeg, and python-gdcm without version pins. Unpinned dependencies are vulnerable to supply chain attacks where a malicious or compromised package version could be installed. The references/transfer_syntaxes.md also recommends bare 'pip install' commands without version constraints. File:
SKILL.mdRemediation: Pin all dependencies to specific versions (e.g., 'pydicom==2.4.4', 'pillow==10.3.0'). Use a requirements.txt or pyproject.toml with locked versions and hash verification. Consider using a lockfile (uv.lock) to ensure reproducible installs. -
🔵 LOW
LLM_DATA_EXFILTRATION— Incomplete DICOM Anonymization - PHI Leakage RiskThe anonymize_dicom.py script and the SKILL.md anonymization workflow do not anonymize DICOM UIDs (StudyInstanceUID, SeriesInstanceUID, SOPInstanceUID). These UIDs can be used to re-identify patients by correlating with PACS systems or other datasets. The code explicitly comments out UID anonymization with a note that it is 'optional'. Additionally, the anonymization list may be incomplete - DICOM contains hundreds of potentially identifying tags beyond those listed, and private tags are not addressed. This is a data exposure risk when users rely on this skill for HIPAA/GDPR-compliant anonymization. File:
scripts/anonymize_dicom.py:68Remediation: Document clearly that this anonymization is NOT sufficient for HIPAA de-identification. Recommend using a dedicated DICOM anonymization tool (e.g., deid, dicomanon) for compliance. At minimum, warn users that UIDs and private tags may still contain PHI. Consider adding a prominent warning in the script output.
pyhealth — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill does not declare an 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be used. Given that this skill deals with sensitive healthcare data (MIMIC, eICU, patient records), explicitly declaring allowed tools would improve the security posture and limit potential misuse. File:
SKILL.mdRemediation: Add an explicit 'allowed-tools' declaration to the YAML manifest. For a documentation/guidance skill like this, consider restricting to [Read] if no code execution is needed, or explicitly list [Python, Read] if code execution examples are intended to be run. -
🔵 LOW
LLM_HARMFUL_CONTENT— Healthcare AI Skill Lacks Clinical Safety Disclaimers in InstructionsThe skill provides guidance for building clinical prediction models (mortality prediction, drug recommendation, readmission) that could directly influence patient care decisions. While the 'Limitations and Considerations' section mentions ethical considerations briefly, the instruction body does not include prominent safety disclaimers warning that AI model outputs should not be used as sole clinical decision-making tools without proper clinical validation and regulatory compliance. This could lead to harmful misuse if the skill is used to deploy models in clinical settings without appropriate safeguards. File:
SKILL.mdRemediation: Add a prominent safety disclaimer at the top of the SKILL.md instruction body stating that AI models developed using this toolkit must not be used for clinical decision-making without proper regulatory approval, clinical validation, and oversight by qualified healthcare professionals. Reference relevant regulations (FDA, CE marking, HIPAA, GDPR). -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Skill Description with Excessive Trigger KeywordsThe skill's YAML description and SKILL.md 'When to Use This Skill' section contain an extensive list of trigger keywords and use cases (EHR, MIMIC-III/IV, eICU, OMOP, ICD, NDC, ATC, EEG, ECG, RETAIN, SafeDrug, Transformer, GNN, mortality, readmission, drug recommendation, etc.). While this appears to be legitimate documentation for a healthcare AI library, the breadth of trigger terms could cause the skill to be activated for a very wide range of healthcare-related queries, potentially beyond its intended scope. File:
SKILL.mdRemediation: Narrow the description to the core functionality. Avoid listing every possible keyword that might trigger activation. Focus on the primary use case rather than enumerating all possible sub-domains. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged in Static AnalysisThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding, indicating that one or more Python code blocks within the markdown reference files contain eval or exec calls. Reviewing the referenced files, the training_evaluation.md contains a code block using scipy.optimize.minimize with a nested function, and other code blocks use dynamic model instantiation patterns. While no direct eval/exec with user-controlled input was found in the reviewed content, the static scanner detected a pattern worth noting. The code blocks are documentation examples, not executable scripts bundled with the skill, so the risk is low. File:
references/training_evaluation.mdRemediation: Verify that no actual executable scripts bundled with the skill use eval/exec with user-controlled input. The code blocks in reference markdown files are documentation examples and pose minimal risk, but should be reviewed to confirm no dynamic code execution patterns are present in any bundled scripts.
pylabrobot — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flag: eval/exec Usage in Code BlocksThe static pre-scan flagged a Python code block containing eval/exec usage (MDBLOCK_PYTHON_EVAL_EXEC). After reviewing all provided reference files, no direct eval() or exec() calls were found in the visible content. The flag may refer to content in unreferenced/missing files (e.g., pylabrobot.py, templates/, assets/ files that were not found). This warrants attention as missing files cannot be verified. Remediation: Audit the missing pylabrobot.py file and any missing template/asset files for eval() or exec() usage with unsanitized input. Ensure any dynamic code execution uses safe alternatives or strictly validates inputs before execution.
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Files Referenced in Skill InstructionsThe SKILL.md references numerous files that were not found: pylabrobot.py, templates/resources.md, templates/material-handling.md, templates/visualization.md, templates/liquid-handling.md, templates/hardware-backends.md, templates/analytical-equipment.md, assets/material-handling.md, assets/visualization.md, assets/liquid-handling.md, assets/resources.md, assets/hardware-backends.md, assets/analytical-equipment.md. These missing files cannot be audited for security issues, creating an incomplete security picture. File:
SKILL.mdRemediation: Ensure all referenced files are included in the skill package and audited. Remove references to non-existent files or add the missing files with appropriate content. -
🔵 LOW
LLM_DATA_EXFILTRATION— Hardcoded Robot IP Address in ExamplesThe hardware backends reference file contains hardcoded IP addresses (192.168.1.100) for Opentrons OT-2 connections. While this is example documentation code, it could encourage users to hardcode network addresses in production protocols rather than using configuration files or environment variables, potentially exposing network topology information. File:
references/hardware-backends.mdRemediation: Update examples to demonstrate reading the host from environment variables or configuration files:host = os.getenv('OPENTRONS_HOST', '192.168.1.100'). Add a note discouraging hardcoded network addresses in production code. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded asyncio.sleep in Protocol ExamplesMultiple reference files contain asyncio.sleep() calls with hardcoded durations (e.g., 600 seconds for incubation, 300 seconds for centrifugation) without any timeout or cancellation mechanisms. While these represent legitimate lab automation wait times, the pattern of long blocking waits without cancellation handling could cause protocols to hang indefinitely if device state changes unexpectedly. File:
references/material-handling.mdRemediation: Wrap long sleep operations in asyncio.wait_for() with appropriate timeouts, or implement periodic status checks during long waits to allow for cancellation and error recovery.
pymc — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill manifest does not declare an allowed-tools field. The skill executes Python code that writes files to disk (PNG plots, .nc NetCDF files, .csv summaries), performs MCMC sampling (CPU-intensive), and reads/writes local files. Without an allowed-tools declaration, the agent's tool usage boundaries are undefined, making it harder to audit or restrict the skill's capabilities. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the YAML frontmatter, e.g.: allowed-tools: [Python, Write, Read]. This improves auditability and enforces least-privilege access. -
🔵 LOW
LLM_RESOURCE_ABUSE— Compute-Intensive MCMC Sampling Without Resource LimitsThe skill instructs the agent to run MCMC sampling with multiple chains (chains=4, draws=2000-5000, tune=1000-2000) and suggests increasing parallelization to 'cores=8, chains=8'. For complex hierarchical models, this can consume significant CPU and memory resources for extended periods. The skill also suggests running variational inference (ADVI) with up to 50,000 iterations. There are no resource limits, timeouts, or user confirmation steps before initiating expensive computations. File:
SKILL.mdRemediation: Add user confirmation prompts before initiating long-running computations. Document expected runtime and resource usage. Consider adding default resource caps (e.g., max chains=4, max draws=2000) and warning users before escalating to higher resource usage. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill manifest does not specify a compatibility field, leaving it unclear which environments (Claude.ai, Claude Code, API) the skill is designed for. This is a minor documentation gap that could lead to unexpected behavior if the skill is used in an incompatible environment. File:
SKILL.mdRemediation: Add a compatibility field to the YAML frontmatter specifying supported environments, e.g.: compatibility: Claude Code, API -
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage in Code Examples (Static Analyzer Flag)The static analyzer flagged a Python code block using eval/exec. After reviewing all script files and the SKILL.md instruction body, no actual use of eval() or exec() with user-controlled input was found in the provided code. The flag may refer to a pattern in the markdown code examples or reference files. All Python scripts (model_diagnostics.py, model_comparison.py, and the template files) use standard PyMC/ArviZ API calls without dynamic code execution. This is a low-severity informational finding pending confirmation of the exact location. File:
scripts/model_diagnostics.pyRemediation: Verify the exact location of the eval/exec usage. If it appears in a code example, add a comment warning users not to pass unsanitized user input to eval/exec. Ensure no user-controlled data flows into dynamic execution calls.
pymoo — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged by Static AnalyzerThe static pre-scan flagged a potential eval/exec usage in a Python code block within the markdown documentation. After careful review of all script files and markdown code blocks, no actual eval() or exec() calls were found in the executable scripts (single_objective_example.py, multi_objective_example.py, many_objective_example.py, custom_problem_example.py, decision_making_example.py) or in the reference documentation. The flag appears to be a false positive from the static analyzer scanning markdown code blocks. No exploitable code injection vector was identified. File:
SKILL.mdRemediation: No action required. This appears to be a false positive. Continue to ensure no eval/exec calls are introduced in future script updates, especially with user-controlled input. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe SKILL.md manifest does not specify the 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills specification, their absence means there are no declared restrictions on which agent tools this skill may invoke. The skill executes Python scripts that use matplotlib for visualization (which may open GUI windows) and pymoo library calls. Declaring allowed tools would improve transparency and enable enforcement of least-privilege access. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash]' and 'compatibility' fields to the YAML frontmatter to explicitly declare the tools this skill requires and the environments it supports.
pyopenms — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools Manifest FieldThe SKILL.md manifest does not specify the allowed-tools field. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be invoked when this skill is active. Given that the skill instructs the agent to execute Python code and bash commands (e.g., 'uv uv pip install pyopenms'), explicitly declaring allowed tools would improve transparency and reduce the attack surface. File:
SKILL.mdRemediation: Add an explicit allowed-tools field to the YAML frontmatter, e.g.: allowed-tools: [Python, Bash, Read, Write]. This limits the skill's tool access to only what is necessary for its stated purpose. -
🔵 LOW
LLM_COMMAND_INJECTION— Typo in Installation Command May Cause Unexpected BehaviorThe installation section of SKILL.md contains a duplicated 'uv' keyword: 'uv uv pip install pyopenms'. This is likely a typo but could cause confusion or unexpected shell behavior if the agent executes this command literally. While not a security vulnerability per se, malformed shell commands can sometimes lead to unintended execution paths depending on how the agent interprets and runs them. File:
SKILL.md:30Remediation: Correct the installation command to: 'uv pip install pyopenms' or 'pip install pyopenms' as appropriate. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the skill's reference files. After reviewing all code blocks across SKILL.md and the referenced markdown files (references/identification.md, references/data_structures.md, references/metabolomics.md, references/signal_processing.md, references/file_io.md, references/feature_detection.md), no actual eval() or exec() calls were found in the code examples. The code blocks contain legitimate PyOpenMS API calls. The static analyzer flag appears to be a false positive, possibly triggered by method names or string patterns. No command injection risk is present in the reviewed code. File:
references/signal_processing.mdRemediation: No action required. This appears to be a false positive from the static analyzer. Continue to avoid eval/exec in any future code additions to this skill.
pysam — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools MetadataThe skill does not specify the 'allowed-tools' field in its YAML manifest. While this is optional per the spec, documenting which tools are required (Python, Bash, Read, Write) would improve transparency and allow the agent runtime to enforce appropriate restrictions for a skill that reads/writes genomic files. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' to the YAML frontmatter to explicitly declare the tools this skill requires. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Several Referenced Files Are MissingThe SKILL.md references multiple documentation files (assets/common_workflows.md, assets/alignment_files.md, assets/variant_files.md, assets/sequence_files.md, templates/alignment_files.md, templates/variant_files.md, templates/sequence_files.md, templates/common_workflows.md, pysam.py) that do not exist in the skill package. This creates an incomplete skill package where the agent may be directed to consult documentation that is absent, potentially leading to unexpected behavior or errors. File:
SKILL.mdRemediation: Either include all referenced files in the skill package or remove references to non-existent files from SKILL.md to ensure the skill package is complete and consistent.
pytdc — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Referenced Files May Cause Unexpected BehaviorSeveral files referenced in the SKILL.md instructions are not present in the skill package:
tdc.py,assets/oracles.md,templates/utilities.md,assets/utilities.md, andtemplates/oracles.md. While this is not a direct security threat, missing files could cause the agent to search for or attempt to load files from unexpected locations, or could indicate an incomplete/tampered skill package. The absence oftdc.pyis notable as it could be confused with the PyTDC library module. File:SKILL.mdRemediation: Remove references to non-existent files from SKILL.md, or include the missing files in the skill package. Ensure the skill package is complete before distribution. Rename any file that could be confused with thetdcPython module. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify
allowed-toolsorcompatibilityfields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill may invoke. The scripts use Python execution and make network calls (downloading datasets from TDC servers), which could be unexpected to users who assume the skill is read-only. This is informational only. File:SKILL.mdRemediation: Addallowed-tools: [Python, Bash]andcompatibilityfields to the YAML frontmatter to clearly communicate the skill's tool requirements and environment compatibility to users. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned PyTDC Dependency InstallationThe SKILL.md instructs users to install PyTDC using
uv pip install PyTDCanduv pip install PyTDC --upgradewithout specifying a pinned version. This means the skill will always install the latest available version of PyTDC, which could introduce breaking changes or, in a supply chain compromise scenario, a malicious version if the PyPI package were compromised. The--upgradeflag is particularly notable as it actively fetches the latest version. File:SKILL.mdRemediation: Pin the PyTDC version to a known-good release (e.g.,uv pip install PyTDC==0.4.1). Avoid using--upgradein automated skill workflows without version validation. Consider adding a hash verification step. -
🔵 LOW
LLM_COMMAND_INJECTION— Use of eval/exec in Code Template (Static Flag Review)The static analyzer flagged a potential eval/exec usage in the Python code blocks. Upon review, the flagged content appears within a string template (the
goal_directed_generation_templatefunction in molecular_generation.py), which prints a code template as a string rather than executing it dynamically. No actual eval() or exec() calls with user-controlled input were found in the executable code paths. This is a low-severity informational finding as the template string could theoretically be misused if the output were piped to a Python interpreter, but no such behavior is present in the skill. File:scripts/molecular_generation.pyRemediation: No immediate action required. Confirm that the template string is only printed and never passed to eval/exec or subprocess. Add a comment clarifying the template is display-only.
pyzotero — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flagged eval/exec Usage in Python Code BlocksThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding, indicating that one or more Python code blocks in the skill's markdown files contain eval or exec calls. Review of the provided reference files did not surface an obvious instance, but the static analyzer detected this pattern. If present in missing files (e.g., pyzotero.py or unreferenced templates), this could represent a code injection risk if user-controlled input is passed to eval/exec. File:
SKILL.mdRemediation: Locate and review all eval/exec usages in the skill's code blocks and scripts. Ensure no user-controlled input is passed to eval or exec without strict validation and sandboxing. -
🔵 LOW
LLM_DATA_EXFILTRATION— API Key Exposed in Code ExamplesMultiple reference files contain hardcoded API key examples (e.g., 'ABC1234XYZ') directly in code snippets. While these appear to be placeholder/example values, the pattern normalizes embedding API keys directly in code rather than exclusively using environment variables. The authentication.md file does show the correct env-var approach, but the Quick Start and other examples show inline keys. File:
SKILL.mdRemediation: Ensure all code examples consistently use environment variables or placeholders that are clearly marked as not real credentials. Add explicit warnings in examples that show inline API keys. -
🔵 LOW
LLM_DATA_EXFILTRATION— Multiple Referenced Files Not FoundNumerous files referenced in the skill's instructions are not present in the skill package (e.g., templates/tags.md, assets/tags.md, assets/read-api.md, templates/error-handling.md, pyzotero.py, and many others). The static analyzer flagged pyzotero.py as referenced but not found. Missing files could cause the agent to fail silently or behave unexpectedly when trying to access them. File:
SKILL.mdRemediation: Audit and remove references to non-existent files, or include the missing files in the skill package. The missing pyzotero.py script in particular should be investigated. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in ManifestThe YAML manifest does not specify a 'compatibility' field. While this is a minor documentation issue, it means users and agents cannot determine which platforms or environments this skill is designed to work with. File:
SKILL.mdRemediation: Add a compatibility field to the YAML frontmatter specifying supported environments (e.g., 'Claude.ai, Claude Code, API').
qiskit — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility and allowed-tools MetadataThe SKILL.md manifest does not specify 'compatibility' or 'allowed-tools' fields. While these are optional per the agent skills spec, their absence means the agent has no declared constraints on which tools it may use or which platforms it is compatible with. This is an informational finding with minimal security impact for this skill, which appears to be a legitimate quantum computing reference skill. File:
SKILL.mdRemediation: Consider adding 'compatibility' and 'allowed-tools' fields to the YAML frontmatter to improve transparency and allow agent runtimes to enforce appropriate tool restrictions. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package DependenciesThe skill instructs users to install packages using 'uv pip install qiskit', 'uv pip install qiskit-nature', 'uv pip install qiskit-machine-learning', etc., without specifying version pins. This means the installed packages could change over time, potentially introducing breaking changes or, in a supply chain attack scenario, malicious code if any of these packages were compromised. The risk is low given these are well-known IBM-maintained packages, but version pinning is a security best practice. File:
SKILL.mdRemediation: Recommend pinning package versions in production environments (e.g., 'uv pip install qiskit==1.x.x'). Consider providing a requirements.txt or pyproject.toml with pinned versions for reproducible environments. -
🔵 LOW
LLM_COMMAND_INJECTION— eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in a Python code block within the skill's reference files. After reviewing all referenced files, the code blocks contain standard Qiskit API calls and no actual eval() or exec() calls were found in the skill's instructional content. The flag may be a false positive from pattern matching on strings like 'evs' (expectation values) in result processing code. No actual dynamic code execution patterns were identified. File:
references/algorithms.mdRemediation: No action required. The 'evs' attribute is a legitimate Qiskit result field for expectation values, not an eval/exec call. The static analyzer appears to have flagged this as a false positive. -
🔵 LOW
LLM_DATA_EXFILTRATION— IBM Quantum API Token Handling in DocumentationThe setup reference file instructs users to save their IBM Quantum API token using QiskitRuntimeService.save_account() and also mentions setting it as an environment variable. While this is standard practice for IBM Quantum SDK usage, the documentation does not warn users about the risks of hardcoding tokens in scripts or storing them insecurely. The skill itself does not exfiltrate credentials, but the guidance could lead users to inadvertently expose their tokens. File:
references/setup.mdRemediation: Add explicit warnings in setup documentation advising users never to hardcode real API tokens in scripts, to use environment variables or credential managers, and to keep token files out of version control (e.g., add to .gitignore).
rdkit — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer Flag: eval/exec in Python Code BlockThe static pre-scan flagged a Python code block containing eval/exec usage. Review of the skill content shows no direct eval/exec calls in the scripts themselves; the flag likely refers to the SKILL.md instruction body code examples. No exploitable eval/exec pattern was found in the actual script files (similarity_search.py, molecular_properties.py, substructure_filter.py). This is a low-severity informational finding. File:
SKILL.mdRemediation: Verify no eval/exec is present in any referenced or bundled scripts. The static analyzer flag appears to be a false positive based on code examples in documentation blocks. -
🔵 LOW
LLM_DATA_EXFILTRATION— Pickle Deserialization of Untrusted DataThe SKILL.md instructions recommend using Python's pickle module to serialize and deserialize molecules for performance. Pickle deserialization of untrusted data can lead to arbitrary code execution. If a user loads a pickled file from an untrusted source following this guidance, it could result in code execution or data exposure. File:
SKILL.mdRemediation: Add a clear warning in the documentation that pickle files should only be loaded from trusted sources. Recommend safer alternatives such as storing molecules in SDF or SMILES format, or using rdkit's built-in binary format (mol.ToBinary()) which is safer than pickle. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools Manifest FieldThe SKILL.md manifest does not specify the allowed-tools field. While this is optional per the spec, the skill executes Python scripts and performs file I/O operations (reading SDF/SMILES files, writing CSV/SDF output). Declaring allowed tools would improve transparency about the skill's capabilities. File:
SKILL.mdRemediation: Add an allowed-tools field to the YAML frontmatter listing the tools actually used, e.g., allowed-tools: [Python, Read, Write, Bash].
scanpy — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools Manifest FieldThe SKILL.md manifest does not specify the 'allowed-tools' field. While this is optional per the agent skills spec, documenting which tools are used (Python, Bash, Read, Write) would improve transparency and security posture. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' to the YAML frontmatter to explicitly declare the tools this skill uses. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in ManifestThe SKILL.md manifest does not specify the 'compatibility' field, leaving users without information about which environments this skill is designed to run in. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter specifying supported environments (e.g., 'Claude.ai, Claude Code, API').
scientific-visualization — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe SKILL.md manifest does not specify the 'allowed-tools' field. While this is optional per the agent skills spec, the skill executes Python scripts (matplotlib, seaborn, plotly) and writes files to disk. Documenting the required tools improves transparency and helps agents make informed decisions about skill activation. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Write]' or similar to the YAML frontmatter to explicitly declare the tools this skill requires. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe SKILL.md manifest does not specify the 'compatibility' field. This makes it harder for users and agents to understand in which environments the skill is expected to function correctly. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter describing supported environments (e.g., 'Works with Claude Code, API').
scikit-learn — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools Manifest FieldThe SKILL.md manifest does not specify the 'allowed-tools' field. While this is optional per the agent skills spec, documenting which tools are used (Python, Bash, Read, Write) would improve transparency and allow agents to enforce capability restrictions. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash, Read, Write]' to the YAML frontmatter to explicitly declare the tools this skill requires. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility FieldThe SKILL.md manifest does not specify the 'compatibility' field, leaving it unclear which agent environments this skill is designed to work with. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter specifying supported environments (e.g., 'Claude.ai, Claude Code, API'). -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded GridSearchCV with n_jobs=-1The classification pipeline uses GridSearchCV with n_jobs=-1, which uses all available CPU cores. Combined with large parameter grids and 5-fold cross-validation, this could cause significant compute exhaustion on resource-constrained systems. The parameter grid includes multiple combinations (e.g., 2x3x2=12 combinations for Random Forest, each evaluated 5 times = 60 model fits). File:
scripts/classification_pipeline.py:148Remediation: Consider adding resource limits or warnings about compute cost. Use n_jobs=1 or a configurable parameter, and document the expected runtime for large datasets.
scikit-survival — 🔵 LOW
- 🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility metadataThe SKILL.md manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools this skill may invoke. Given the skill's scope (survival analysis workflows), this is a minor informational gap rather than an active threat. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML frontmatter to explicitly declare which tools the skill requires (e.g., [Python]). Add 'compatibility' to clarify supported environments.
scvelo — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and Compatibility MetadataThe SKILL.md manifest does not specify
allowed-toolsorcompatibilityfields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on what tools the agent may use when executing this skill. The script uses file I/O, directory creation, and writes output files, which would benefit from explicit tool declarations. File:SKILL.mdRemediation: Addallowed-tools: [Python, Bash]and acompatibilityfield to the YAML frontmatter to clearly declare the skill's intended tool usage and environment compatibility. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation RecommendedThe SKILL.md instructs users to install scvelo via
pip install scvelowithout specifying a version pin. While this is common practice for bioinformatics tools, unpinned installations are susceptible to supply chain attacks if the package is compromised or a malicious version is published. The skill also depends on scanpy, numpy, and matplotlib without version constraints. File:SKILL.mdRemediation: Recommend pinning to a specific known-good version, e.g.,pip install scvelo==0.2.5. Consider providing a requirements.txt or conda environment file with pinned dependencies for reproducibility and security. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Referenced Files Not Found (scanpy.py, matplotlib.py, scvelo.py)The instructions reference files named scanpy.py, matplotlib.py, and scvelo.py, but none of these files are present in the skill package. These names shadow well-known Python standard library packages (matplotlib) and popular bioinformatics packages (scanpy, scvelo). If these files were present, they could shadow legitimate imports and introduce malicious code. Their absence is noted but the naming pattern is suspicious. File:
SKILL.mdRemediation: Clarify whether these files are intended to be part of the skill package. If not, remove references to them. If they are intended helper modules, ensure they are included and do not shadow standard package names. Avoid naming local files with the same names as popular Python packages to prevent import shadowing.
simpy — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe skill does not specify the 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools can be used. This is informational only. File:
SKILL.mdRemediation: Consider adding an explicit 'allowed-tools' field to the YAML manifest to document which tools the skill requires, e.g., allowed-tools: [Python, Bash, Read, Write]. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill does not specify the 'compatibility' field in its YAML manifest. This is informational only and does not represent a security risk, but reduces transparency about where the skill is intended to run. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML manifest to document supported environments.
statsmodels — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Multiple Referenced Files Not Found in PackageThe skill references numerous files that are not present in the package: assets/linear_models.md, sklearn.py, assets/glm.md, assets/discrete_choice.md, scipy.py, matplotlib.py, templates/glm.md, templates/linear_models.md, templates/stats_diagnostics.md, assets/stats_diagnostics.md, templates/time_series.md, templates/discrete_choice.md, assets/time_series.md, statsmodels.py. While most appear to be legitimate statistical library references (scipy, sklearn, matplotlib, statsmodels), the presence of missing internal files could indicate an incomplete package or references to files that may be dynamically fetched or substituted at runtime. File:
SKILL.mdRemediation: Ensure all referenced files are bundled within the skill package. Verify that missing files (sklearn.py, scipy.py, matplotlib.py, statsmodels.py) are not intended to be fetched from external sources. If these are meant to represent Python library imports, clarify this in documentation rather than listing them as file references. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools MetadataThe skill does not declare an 'allowed-tools' field in its YAML manifest. While this field is optional per the agent skills spec, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) can be invoked. Given the skill's scope involves executing statistical modeling code, documenting intended tool usage would improve transparency. File:
SKILL.mdRemediation: Add an 'allowed-tools' field to the YAML frontmatter specifying the intended tools, e.g., 'allowed-tools: [Python, Read]'. This improves auditability and limits unintended tool activation. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility MetadataThe skill does not declare a 'compatibility' field in its YAML manifest. This is informational only, but the absence of compatibility information makes it harder to assess the deployment context and expected runtime environment. File:
SKILL.mdRemediation: Add a 'compatibility' field to the YAML frontmatter specifying supported environments, e.g., 'compatibility: Claude.ai, Claude Code, API'.
tiledbvcf — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged in Static AnalysisThe static pre-scan flagged a Python code block containing eval/exec usage within the SKILL.md instruction body. Reviewing the actual code blocks in the skill, no explicit eval() or exec() calls are visible in the provided content. The flag may be a false positive from the static analyzer detecting patterns in code examples. However, since the referenced script files (tiledb.py, tiledbvcf.py) were not found and could not be inspected, the risk cannot be fully ruled out. File:
SKILL.mdRemediation: Locate and review the referenced tiledb.py and tiledbvcf.py files for any eval/exec usage. If these files contain dynamic code execution with user-controlled input, refactor to avoid eval/exec patterns. Confirm the static analyzer finding is not a false positive. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing Referenced Script Files (tiledb.py, tiledbvcf.py)The SKILL.md references two Python files (tiledb.py and tiledbvcf.py) that were not found in the skill package. This means the actual executable behavior of the skill cannot be fully audited. If these files exist at runtime, they could contain data exfiltration, credential access, or other malicious behavior that is not visible in the current analysis. File:
SKILL.mdRemediation: Ensure all referenced script files are included in the skill package and available for security review. Do not deploy skills with missing referenced files, as their behavior cannot be audited. -
🔵 LOW
LLM_UNAUTHORIZED_TOOL_USE— Missing allowed-tools DeclarationThe skill manifest does not specify an allowed-tools field. While this field is optional per the agent skills specification, its absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may invoke. Given that the skill involves file I/O, cloud storage access, and potentially executing Python code, declaring allowed-tools would improve the security posture. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the YAML frontmatter listing only the tools required for the skill's legitimate functionality (e.g., Python, Bash if CLI usage is needed). This provides a documented security boundary.
treatment-plans — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing Compatibility Field in YAML ManifestThe SKILL.md manifest does not specify a compatibility field. While this is optional per the agent skills spec, the skill handles sensitive medical/HIPAA-regulated data and generates clinical documents. Documenting compatibility constraints (e.g., which environments support LaTeX compilation, pdflatex availability) would help prevent misuse in environments where PDF generation is not possible or where HIPAA compliance cannot be guaranteed. File:
SKILL.mdRemediation: Add a compatibility field specifying required environment capabilities, e.g., 'Requires pdflatex for PDF generation. Intended for use in HIPAA-compliant environments only.' -
⚪ INFO
LLM_CONTEXT_BUDGET_EXCEEDED— 'SKILL.md (instruction body)' excluded from LLM analysis (52,002 chars)instruction body (52,002 chars) exceeds limit (50,000) File:
SKILL.md (instruction body)Remediation: Increase llm_analysis.max_instruction_body_chars in your scan policy to include this content in LLM analysis. -
🔵 LOW
LLM_DATA_EXFILTRATION— Potential PHI Exposure in LaTeX Style FileThe assets/medical_treatment_plan.sty file contains what appears to be hardcoded patient-specific information in the header/title definitions: 'Patient Age: 23', 'Diabetes Treatment Plan', '23-Year-Old Male Patient with Type 2 Diabetes'. While this is a style/template file, embedding specific patient demographic details (age, sex, condition) in a shared style file rather than parameterizing them could lead to accidental PHI exposure if the style file is shared or reused across patients without modification. File:
assets/medical_treatment_plan.styRemediation: Replace hardcoded patient details in the .sty file with parameterized placeholders (e.g., \newcommand{\patientage}{} and \newcommand{\patientcondition}{}) that must be set per-document. This prevents accidental reuse of one patient's demographic data in another patient's document. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Optional Dependency Without Version Pin (matplotlib)The timeline_generator.py script optionally imports matplotlib without specifying a version. While the import is gracefully handled with a try/except, the install instruction in comments ('pip install matplotlib') has no version pin. In a medical documentation context, unpinned dependencies could introduce unexpected behavior changes. File:
scripts/timeline_generator.pyRemediation: Document a specific tested version of matplotlib in requirements or comments, e.g., 'pip install matplotlib==3.8.0'. Consider adding a requirements.txt with pinned versions for all optional dependencies.
umap-learn — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Static Analyzer False Positive: eval/exec Flag in Code ExamplesThe static analyzer flagged a Python code block containing eval/exec usage. Upon manual review of the SKILL.md instruction body, no actual eval() or exec() calls are present in the code examples. The code blocks contain standard UMAP, scikit-learn, TensorFlow/Keras, and matplotlib usage patterns. This appears to be a false positive from the static analyzer, possibly triggered by a keyword match in the documentation text or a library internals reference. No actual command injection risk is present in the skill's instructions. File:
SKILL.mdRemediation: No action required. This is a false positive. If the static analyzer is consistently flagging this skill, consider reviewing the analyzer's pattern matching rules for documentation-only code blocks. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Referenced Files Not Found (Broken Internal References)The SKILL.md references several files (matplotlib.py, hdbscan.py, sklearn.py, umap.py, tensorflow.py) that are not present in the skill package. These appear to be incorrectly named references — they seem to be Python library names mistakenly listed as local files rather than actual bundled skill resources. The references/api_reference.md file is also mentioned but not confirmed present. This is a documentation/packaging inconsistency rather than a security threat, but broken references could cause agent confusion. File:
SKILL.mdRemediation: Remove or correct the broken file references. If these are meant to be external library imports, they should not be listed as local skill files. Ensure references/api_reference.md is bundled with the skill package if it is referenced in instructions. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills specification, their absence means there are no declared constraints on which agent tools this skill may invoke. Given that the skill instructs installation of packages and execution of Python code, declaring these fields would improve transparency and allow runtime enforcement of tool restrictions. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python, Bash]' and a compatibility field to the YAML frontmatter to clearly declare the skill's intended tool usage and supported environments. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation Without Version ConstraintsThe skill instructs installation of umap-learn and umap-learn[parametric_umap] via 'uv pip install' without specifying version pins. This exposes users to supply chain risks if a malicious version of the package is published (e.g., dependency confusion or typosquatting). While umap-learn is a well-known legitimate package, unpinned installs are a best practice concern. File:
SKILL.mdRemediation: Pin package versions explicitly, e.g., 'uv pip install umap-learn==0.5.6'. Consider providing a requirements.txt or pyproject.toml with locked dependencies and hash verification.
usfiscaldata — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage Flagged by Static AnalyzerThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding. After reviewing all code blocks in the skill's markdown files, no actual use of eval() or exec() was found in the instruction body or referenced files. All Python code examples use standard library calls (requests.get, pd.DataFrame, float(), pd.to_numeric, etc.). This appears to be a false positive from the static analyzer. No genuine eval/exec risk is present. File:
SKILL.mdRemediation: No action required. Confirm with static analyzer vendor if the false positive rate for MDBLOCK_PYTHON_EVAL_EXEC can be reduced. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools DeclarationThe skill makes HTTP requests to external URLs (api.fiscaldata.treasury.gov) in its code examples and instructs the agent to use Python with the requests library, but does not declare allowed-tools in the YAML manifest. This is an informational finding only, as allowed-tools is optional per the spec. However, declaring the tools used (Python, Bash) would improve transparency about the skill's network access behavior. File:
SKILL.mdRemediation: Add 'allowed-tools: [Python]' to the YAML frontmatter to explicitly declare that Python (with network access) is required. This improves transparency for users reviewing the skill. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Broad Capability Claims in DescriptionThe skill description claims access to '54 datasets and 182 data tables' and lists a wide range of financial data categories. While this appears to accurately reflect the U.S. Treasury Fiscal Data API's actual scope, the description is very broad and could trigger the skill for a wide range of financial queries. This is a minor concern as the claims appear legitimate and match the documented API capabilities. File:
SKILL.mdRemediation: Consider narrowing the description to the most common use cases to reduce over-broad activation. The current description is accurate but very expansive.
vaex — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Missing allowed-tools and compatibility MetadataThe skill manifest does not specify 'allowed-tools' or 'compatibility' fields. While these are optional per the agent skills spec, their absence means there are no declared restrictions on which agent tools (Read, Write, Bash, Python, etc.) this skill may invoke. Given the skill's broad scope (file I/O, ML pipelines, data export, cloud storage access), declaring allowed tools would improve transparency and reduce the risk of unintended tool use. File:
SKILL.mdRemediation: Add 'allowed-tools' to the YAML frontmatter to explicitly declare which tools are needed (e.g., [Python, Read, Write]). Add 'compatibility' to clarify supported environments. This improves auditability and limits unintended capability expansion. -
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a potential eval/exec usage in the Python code blocks within the reference documentation. After reviewing all referenced files, the flagged pattern appears to be within illustrative code examples in the documentation (e.g., references/data_processing.md, references/machine_learning.md) rather than executable scripts. No actual eval() or exec() calls with user-controlled input were found in the skill's instruction body or scripts. The pre-scan finding warrants noting but does not represent an active threat in this context. File:
references/data_processing.mdRemediation: Review the specific line flagged by the static analyzer to confirm no user-controlled input is passed to eval/exec. If code examples are used as templates, ensure they include warnings about sanitizing user input before use in production. -
🔵 LOW
LLM_DATA_EXFILTRATION— Cloud Credential Usage in I/O Reference DocumentationThe io_operations.md reference file includes examples of accessing cloud storage (S3, GCS, Azure) using credentials passed directly in code (e.g., key='access_key', secret='secret_key'). While these are documentation examples, they could encourage users or the agent to hardcode credentials in generated code. Additionally, the reference mentions reading from s3fs with explicit key/secret parameters, which is a credential exposure anti-pattern. File:
references/io_operations.mdRemediation: Update cloud storage examples to use environment variables or IAM roles instead of hardcoded credentials. Add explicit warnings in the documentation that credentials should never be hardcoded. Example: use s3fs.S3FileSystem() without explicit keys to rely on environment-based credential resolution. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— No Version Pinning in Implied DependenciesThe skill references multiple external libraries (vaex, scikit-learn, XGBoost, LightGBM, CatBoost, Keras/TensorFlow, numba, s3fs, gcsfs, adlfs) throughout its reference documentation without specifying version requirements or pinned versions. The io_operations.md even suggests installing packages via pip without version constraints ('pip install s3fs gcsfs adlfs'). Unpinned dependencies are a supply chain risk. File:
references/io_operations.mdRemediation: Add a requirements.txt or dependency specification with pinned versions for all referenced libraries. Update documentation examples to show version-pinned installation commands (e.g., 'pip install s3fs==2023.x.x').
venue-templates — 🔵 LOW
-
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Capability Claims in DescriptionThe skill description lists an extensive array of venues, agencies, and document types (Nature, Science, PLOS, IEEE, ACM, NeurIPS, ICML, CVPR, CHI, NSF, NIH, DOE, DARPA, etc.) which may inflate perceived capabilities beyond what is actually bundled. Many referenced template files are not found (e.g., templates/journals/nature_article.tex, templates/journals/neurips_article.tex, assets/journals_formatting.md, assets/conferences_formatting.md, assets/grants_requirements.md, etc.), suggesting the skill claims broader coverage than it delivers. This could mislead users into trusting outputs for venues where templates are missing or incomplete. File:
SKILL.mdRemediation: Audit and reconcile the description with actually bundled assets. Remove or qualify claims for venues where templates are missing. Provide a clear manifest of what is actually included. -
🔵 LOW
LLM_COMMAND_INJECTION— Regex Substitution on User-Supplied Template Content in customize_template.pyThe customize_template.py script reads a LaTeX template file and applies regex substitutions using user-supplied values (--title, --authors, --affiliations, --email) as replacement strings. Python's re.sub replacement strings support backreferences (e.g., \1, \g). If a user supplies a replacement string containing backslash sequences, this could cause unexpected behavior or errors. While not a critical injection risk in this context, it represents a code injection surface. File:
scripts/customize_template.pyRemediation: Use re.escape() on replacement strings or use a lambda replacement function (re.sub(pattern, lambda m: replacement, content)) to prevent backreference interpretation in user-supplied replacement values. -
🔵 LOW
LLM_RESOURCE_ABUSE— Unbounded Template Search via json.dumps in query_template.pyThe search_templates function in query_template.py serializes the entire template dictionary to JSON and performs substring search on it. While the current TEMPLATES dict is small and static, if the dict were extended or if keyword input were very long, this could cause unnecessary compute overhead. More importantly, there is no input length validation on the --keyword, --venue, or --type arguments, which could be abused with very long strings. File:
scripts/query_template.pyRemediation: Add input length validation for all CLI arguments. Consider a more targeted search approach rather than serializing the entire object to a string. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools Restriction Enforcement for Bash ExecutionThe skill declares allowed-tools including Bash and Python, and the instructions direct the agent to run bash commands (pdflatex, latexmk, pdfinfo, pdffonts) and Python scripts. The validate_format.py script uses subprocess.run to invoke system binaries (pdfinfo, pdffonts) without validating that these binaries exist or that the file path is safe. The --file argument is passed directly to Path() and then to subprocess without sanitization, which could allow path traversal if user-supplied filenames contain special characters. File:
scripts/validate_format.pyRemediation: Validate and sanitize the --file argument before use. Ensure the resolved path stays within expected directories. Consider using pathlib.Path.resolve() and checking against an allowed base directory.
what-if-oracle — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Pattern Flagged in Markdown Code BlockThe static pre-scan flagged a MDBLOCK_PYTHON_EVAL_EXEC finding, indicating a Python code block in the markdown contains eval or exec usage. Reviewing the SKILL.md content, the only code blocks present are ASCII-art template boxes (using box-drawing characters) and a probability distribution display — no actual Python eval/exec code is visible in the provided content. This appears to be a false positive from the static analyzer triggered by the box-drawing characters or template syntax. However, it is noted for completeness. If any future script files are added to this skill, eval/exec usage should be carefully reviewed. File:
SKILL.mdRemediation: Verify the static analyzer finding manually. If eval/exec is genuinely present in any code block, remove or replace with safe alternatives. Ensure no executable Python code blocks are embedded in the markdown that an agent might attempt to run. -
🔵 LOW
LLM_DATA_EXFILTRATION— External URLs to Author-Controlled Domains in InstructionsThe SKILL.md instructions include multiple links to external domains controlled by the skill author: ahkstrategies.net and themindbook.app. While these appear to be promotional/attribution links rather than active data exfiltration vectors (no scripts make network calls), their presence in the instruction body means the agent may surface these URLs to users. If the agent were to follow these links or if future versions added network-fetching behavior, this could become a higher-severity issue. Currently this is informational. File:
SKILL.mdRemediation: External promotional links in skill instructions are low risk when no network-fetching behavior exists. Ensure no future script additions fetch content from these domains. Consider removing promotional links from the instruction body to keep the skill focused on its functional purpose. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Over-Broad Activation Triggers in Skill DescriptionThe skill description contains an extensive list of trigger keywords and phrases designed to maximize activation across a very wide range of user queries. Phrases like 'any question about uncertain futures', 'fork-in-the-road decision', 'stress-test an idea', 'risk analysis', 'contingency planning', and 'strategic options' are extremely broad and could cause the skill to activate in many contexts where it may not be the most appropriate tool. This pattern resembles keyword baiting to inflate perceived relevance and activation frequency. File:
SKILL.mdRemediation: Narrow the activation description to the core use case (structured what-if scenario analysis) rather than listing dozens of broad trigger phrases. A concise, accurate description reduces unintended activation and is more honest about the skill's scope.
xlsx — 🔵 LOW
-
🔵 LOW
LLM_COMMAND_INJECTION— Python eval/exec Usage in Code ExamplesThe static analyzer flagged a Python code block using eval/exec. Reviewing the SKILL.md instruction body, there are no direct eval/exec calls in the actual scripts. The flag likely refers to illustrative code examples in the markdown instructions. The actual script files (recalc.py, unpack.py, pack.py, soffice.py, validators) do not use eval/exec with user-controlled input. This is a low-severity informational finding as the code examples in SKILL.md are instructional, not executed directly. File:
SKILL.mdRemediation: Verify that no eval/exec calls are introduced in generated Python code when the agent follows these instructions. The skill instructions should explicitly warn against using eval/exec with user-supplied data. -
🔵 LOW
LLM_DATA_EXFILTRATION— Missing allowed-tools Declaration in ManifestThe SKILL.md YAML frontmatter does not declare an allowed-tools field. This is an optional field per the agent skills spec, but its absence means there are no declared restrictions on which agent tools this skill can use. Given that the skill executes subprocesses (soffice, gcc, git, timeout/gtimeout), writes files, and compiles native code, declaring allowed-tools would improve transparency and security posture. File:
SKILL.mdRemediation: Add an explicit allowed-tools declaration to the YAML frontmatter listing the tools actually used (e.g., Bash, Python, Read, Write) to make the skill's capabilities transparent to users and the agent runtime. -
🔵 LOW
LLM_COMMAND_INJECTION— Dynamic Shared Library Compilation and LD_PRELOAD Injection in soffice.pyThe soffice.py helper compiles a C source file at runtime using gcc and injects it via LD_PRELOAD into the LibreOffice process environment. While this is a legitimate workaround for sandboxed environments where AF_UNIX sockets are blocked, it represents a significant capability: compiling and loading arbitrary native code into a subprocess. If the _SHIM_SOURCE constant were tampered with (e.g., via supply chain compromise), this mechanism could be used to execute arbitrary native code. The shim is written to a predictable temp path (/tmp/lo_socket_shim.so). File:
scripts/office/soffice.pyRemediation: Consider verifying the integrity of the compiled shim (e.g., hash check) before loading. Use a more unique temp path to reduce predictability. Document this behavior clearly in the skill manifest so users are aware of the native code compilation. -
🔵 LOW
LLM_COMMAND_INJECTION— Subprocess Execution with External Input in recalc.pyThe recalc.py script constructs a subprocess command using the filename argument passed from the command line (sys.argv[1]). While the filename is passed as a positional argument to soffice rather than interpolated into a shell string, and subprocess.run is used without shell=True, a maliciously crafted filename could potentially be used to pass unexpected arguments to soffice. The risk is limited because shell=True is not used. File:
scripts/recalc.pyRemediation: Validate that the filename argument is a legitimate file path before passing it to subprocess. Consider using Path validation and checking that the file has an expected extension (.xlsx, .xlsm, etc.) before invoking soffice.
zarr-python — 🔵 LOW
-
🔵 LOW
LLM_DATA_EXFILTRATION— Cloud Credential Usage Without Security GuidanceThe skill instructs users to configure S3 and GCS cloud storage access using credentials (s3fs.S3FileSystem(anon=False), gcsfs.GCSFileSystem(project='my-project')) without providing any guidance on secure credential management. Users may inadvertently hardcode credentials or expose them in scripts derived from these examples. File:
SKILL.mdRemediation: Add explicit guidance to use environment variables or credential files (e.g., AWS_ACCESS_KEY_ID, ~/.aws/credentials) rather than hardcoding credentials. Warn users never to embed credentials directly in code. -
🔵 LOW
LLM_SKILL_DISCOVERY_ABUSE— Referenced Files Not Found in Skill PackageThe SKILL.md references several Python module names (h5py.py, dask.py, s3fs.py, zarr.py, xarray.py, gcsfs.py) that are not present in the skill package. These appear to be import references in code examples rather than actual bundled files, but their absence as referenced files could cause confusion about the skill's actual bundled contents. The skill's manifest does not specify 'allowed-tools' or 'compatibility', reducing transparency about its operational scope. File:
SKILL.mdRemediation: Ensure that all referenced files are either bundled with the skill package or clearly documented as external dependencies. Add 'allowed-tools' and 'compatibility' fields to the YAML manifest for transparency. -
🔵 LOW
LLM_SUPPLY_CHAIN_ATTACK— Unpinned Package Installation in InstructionsThe SKILL.md instructions recommend installing packages (zarr, s3fs, gcsfs) using 'uv pip install' without version pinning. This exposes users to supply chain risks where a compromised or malicious version of these packages could be installed. Without pinned versions, the installed packages may change over time, potentially introducing vulnerabilities or malicious code. File:
SKILL.mdRemediation: Pin package versions explicitly, e.g., 'uv pip install zarr==2.18.0 s3fs==2024.2.0 gcsfs==2024.2.0'. Consider using a lockfile (e.g., uv.lock) to ensure reproducible installations.