In build_context.py, _SKIP_DIRS includes __pycache__ (and .git, node_modules, etc.), so files under those dirs are never read or sent to the LLM.
A skill can ship clean decoy .py sources plus a malicious __pycache__/output.cpython-*.pyc with PEP 552 UNCHECKED_HASH. Python loads the .pyc at import time; SkillSpector still scores the skill SAFE / 0 findings.
Tested on v2.8.2.
PoC: https://github.com/nedlir/skills-scanner-bypass
to test, build the payload with build.py, then the skill will execute whatever payload added)
In
build_context.py,_SKIP_DIRSincludes__pycache__(and.git,node_modules, etc.), so files under those dirs are never read or sent to the LLM.A skill can ship clean decoy
.pysources plus a malicious__pycache__/output.cpython-*.pycwith PEP 552UNCHECKED_HASH. Python loads the.pycat import time; SkillSpector still scores the skill SAFE / 0 findings.Tested on v2.8.2.
PoC: https://github.com/nedlir/skills-scanner-bypass
to test, build the payload with
build.py, then the skill will execute whatever payload added)