Is NumPy safe?
- Python shell/command execution
- Python dynamic code execution
- Possible command injection (shell + dynamic command)
numpy is an AI python_package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 7 risky constructs are reported for review. It can: dynamic code execution, filesystem read, filesystem write, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 40/100 (medium).
numpy 2.5.3
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of NumPy's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (7)
The code builds an OS command out of values that can change at runtime, then runs it through a shell.
rc = subprocess.check_call("./scripts/bench-compare.sh '%s' '%s' '%d'" % (baseline, contender, repeatnum), shell=True)rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%d'" % (branch, repeatnum), shell=True)rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%s' '%d'" % (branch, args.filter, repeatnum), shell=True)os.system(f"cp {notes} {target_rst}")Why it matters: If any of those values come from untrusted input, an attacker can run their own commands on the machine.
Fix: Pass arguments as a list without shell=True (e.g. subprocess.run(['git', 'checkout', branch])); never build a shell string from external input. If a shell is unavoidable, quote with shlex.quote.
It loads data with a format that can rebuild arbitrary objects (e.g. pickle, or unsafe YAML).
array = pickle.load(fp, **pickle_kwargs)
return pickle.load(fid, **pickle_kwargs)
Why it matters: Feeding such a loader untrusted data can execute code hidden inside that data.
Fix: Deserialize untrusted data with a safe format/loader: JSON, or yaml.safe_load / Loader=SafeLoader. Reserve pickle/marshal for data you fully control.
The code turns strings into live code at runtime (eval / new Function / exec).
value = eval(code, self.default_namespace, ns)
exec(code, self.default_namespace, ns)
value = eval(value)
return eval(f"{l1}:{' and '.join(l2)}")return eval(f"{l1}:{' or '.join(l2)}")return eval('lambda v,f=f:not f(v)')d = eval(f.read().lower(), {}, {})ret['size'] = repr(eval(ret['size']))
v = eval(v, {}, {})v = eval(initexpr, {}, params)r = eval(e, g, l)
value = eval(value, {}, params)l = str(eval(l, {}, params))l = str(eval(l, {}, params))kindselect['kind'] = eval(
kindselect['kind'], {}, params)p = eval(v, g_params, params)
item = eval(item, g_params, params)
v = eval(v)
exec(astr, dict)
code = compile(code_str, f'Test name: {label} ', 'exec')exec(code, globs, locs)
Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.
Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.
The component can run operating-system commands or spawn processes.
p = subprocess.run(cmd, check=True, capture_output=True, text=True)
res = run(['gcc', '-v'], check=True, text=True, capture_output=True)
p = subprocess.Popen(
['git', '-c', 'log.showSignature=false', 'log', '-1', '--format="%H %aI"'],
stdout=subprocess.PIPE,
stderr=subprocess.PIPE,
cwd=os.path.dirname(__file__),
)rc = subprocess.check_call("./scripts/bench-compare.sh '%s' '%s' '%d'" % (baseline, contender, repeatnum), shell=True)rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%d'" % (branch, repeatnum), shell=True)rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%s' '%d'" % (branch, args.filter, repeatnum), shell=True)subprocess.run(command, cwd=cwd, check=True)
subprocess.check_call(
["f2c"] + F2C_ARGS + ['-d', output_dir, fortran_filename]
)subprocess.check_call(['patch', '-u', fortran_file, patch_file])
subprocess.check_call(['patch', '-u', c_file, c_patch_file])
output = subprocess.run(cmd, capture_output=True, text=True)
res = subprocess.run(cmd, cwd=cwd, capture_output=True, text=True,
errors="replace", **kwargs)res = subprocess.run(
[
"git",
"diff",
"--name-only",
"--diff-filter=ACMR",
"-z",
sha,
"--",
# Check against C_CPP_EXTENSIONS …subprocess.check_call(cmd, stdout=pipe, stderr=pipe)
res = subprocess.run(
command,
stdout=subprocess.PIPE,
cwd=self.repository_root,
encoding="utf-8",
)res = subprocess.run(
command,
stdout=subprocess.PIPE,
cwd=self.repository_root,
encoding="utf-8",
)borrowed_res = subprocess.run(
[sys.executable, borrowed_ref_script],
cwd=self.repository_root,
stdout=subprocess.PIPE,
stderr=subprocess.STDOUT,
text=True,
check=False …result = subprocess.run(
["basedpyright", *pyright_args],
capture_output=True,
text=True,
)os.system(f"cp {notes} {target_rst}")subprocess.run(
["pandoc", "-s", "-o", str(target_md), str(target_rst), "--wrap=preserve"],
check=True,
)Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.
Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; avoid shell=True.
The component reads files from disk.
with open(source) as fid:
fid = open(file, 'r')
with open(init) as fid:
with open(filename, "rb") as f:
with open(template_name, "rb") as f:
fo = open(filename, 'r')
with open(filename) as f:
with open(file) as fid:
f_ctx = open(
os.fspath(filename),
('r' if mode == 'c' else mode) + 'b'
)ctx = open(os.fspath(fd), 'rb')
with open(filename, encoding=encoding, errors=errors, newline="") as fp:
return self.build_template_path.read_text()
with open(source) as fid:
with open(source) as f:
with open(f2cmap_file) as f:
with open(filename, 'rb') as fhandle:
return open(filename, mode, encoding=encoding)
open(l).close()
with open(l):
magic_str = _read_bytes(fp, MAGIC_LEN, "magic string")
hlength_str = _read_bytes(fp, struct.calcsize(hlength_type), "array header length")
header = _read_bytes(fp, header_length, "array header")
data = _read_bytes(fp, read_size, "array data")
with open(os.fspath(filename), mode + 'b') as fp:
with open(os.fspath(filename), 'rb') as fp:
Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component writes or deletes files on disk.
with open(outfile, 'w') as f:
with open(local, "wt", encoding="utf8") as fid:
with open(pkg_config_fname, "wt", encoding="utf8") as fid:
outfile = open(newname, 'w')
with open(outfile, 'w') as f:
with open(outfile, 'w') as f:
with open(outfile, 'w') as f:
with open(options.output, "wb") as f:
ctx = open(os.fspath(file), "wb")
with open(filename, 'w') as fid:
with open(outfile, 'w') as f:
with open(target, 'w') as fid:
shutil.rmtree(path)
with open(filename, "w", encoding=encoding, errors=errors, newline="") as fp:
shutil.copy2(path_object, dest_path)
os.remove(path_object)
meson_build_file.write_text(src)
shutil.copy(source, bdir)
shutil.copy(generated_source, bdir / generated_source.name)
shutil.copy(obj, bdir)
with open(pyffilename, 'w') as f:
with open(options['signsfile'], 'w') as f:
with open(fn, 'w') as f:
with open(fn, 'w') as f:
with open(fn, 'w') as f:
Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.
Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.
The component makes outbound network requests.
import urllib.request
urllib.request.urlretrieve(PYTHONCAPI_COMPAT_URL, target)
from urllib.request import urlopen
with urlopen(path) as openedurl:
from urllib.request import urlopen
netfile = urlopen(path)
Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →