SkillTotal

Is NumPy safe?

Some risk - review before installing
Notable — review in context (capabilities are not malware):
  • Python shell/command execution
  • Python dynamic code execution
  • Possible command injection (shell + dynamic command)

numpy is an AI python_package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators, though 7 risky constructs are reported for review. It can: dynamic code execution, filesystem read, filesystem write, network egress and shell execution — capabilities are what the code can do, not a verdict on intent. Risk score 40/100 (medium).

numpy 2.5.3

python_package · pypi:numpy
MEDIUM
40
/ 100 risk score
Snapshot · scanned Sep 24, 2026 · numpy@2.5.3 · engine 0.53.0 / ruleset 60

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of NumPy's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
dynamic code executionfilesystem readfilesystem writenetwork egressshell execution

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication
Unsafe deserialization
General Protections / Input Validation

Findings (7)

HIGHPossible command injection (shell + dynamic command)ST-CMDI-PY

The code builds an OS command out of values that can change at runtime, then runs it through a shell.

rc = subprocess.check_call("./scripts/bench-compare.sh '%s' '%s' '%d'" % (baseline, contender, repeatnum), shell=True)
rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%d'" % (branch, repeatnum), shell=True)
rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%s' '%d'" % (branch, args.filter, repeatnum), shell=True)
os.system(f"cp {notes} {target_rst}")

Why it matters: If any of those values come from untrusted input, an attacker can run their own commands on the machine.

Fix: Pass arguments as a list without shell=True (e.g. subprocess.run(['git', 'checkout', branch])); never build a shell string from external input. If a shell is unavoidable, quote with shlex.quote.

HIGHUnsafe deserializationST-DESERIALIZE-PY

It loads data with a format that can rebuild arbitrary objects (e.g. pickle, or unsafe YAML).

array = pickle.load(fp, **pickle_kwargs)
return pickle.load(fid, **pickle_kwargs)

Why it matters: Feeding such a loader untrusted data can execute code hidden inside that data.

Fix: Deserialize untrusted data with a safe format/loader: JSON, or yaml.safe_load / Loader=SafeLoader. Reserve pickle/marshal for data you fully control.

HIGHPython dynamic code executionST-DYN-PY

The code turns strings into live code at runtime (eval / new Function / exec).

value = eval(code, self.default_namespace, ns)
exec(code, self.default_namespace, ns)
return eval(f"{l1}:{' and '.join(l2)}")
return eval(f"{l1}:{' or '.join(l2)}")
return eval('lambda v,f=f:not f(v)')
d = eval(f.read().lower(), {}, {})
ret['size'] = repr(eval(ret['size']))
v = eval(initexpr, {}, params)
value = eval(value, {}, params)
l = str(eval(l, {}, params))
l = str(eval(l, {}, params))
kindselect['kind'] = eval(
                                        kindselect['kind'], {}, params)
p = eval(v, g_params, params)
item = eval(item, g_params, params)
code = compile(code_str, f'Test name: {label} ', 'exec')

Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.

Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.

HIGHPython shell/command executionST-SHELL-PY

The component can run operating-system commands or spawn processes.

p = subprocess.run(cmd, check=True, capture_output=True, text=True)
res = run(['gcc', '-v'], check=True, text=True, capture_output=True)
p = subprocess.Popen(
            ['git', '-c', 'log.showSignature=false', 'log', '-1', '--format="%H %aI"'],
            stdout=subprocess.PIPE,
            stderr=subprocess.PIPE,
            cwd=os.path.dirname(__file__),
        )
rc = subprocess.check_call("./scripts/bench-compare.sh '%s' '%s' '%d'" % (baseline, contender, repeatnum), shell=True)
rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%d'" % (branch, repeatnum), shell=True)
rc = subprocess.check_call("./scripts/branch-compare.sh '%s' '%s' '%d'" % (branch, args.filter, repeatnum), shell=True)
subprocess.run(command, cwd=cwd, check=True)
subprocess.check_call(
            ["f2c"] + F2C_ARGS + ['-d', output_dir, fortran_filename]
        )
subprocess.check_call(['patch', '-u', fortran_file, patch_file])
subprocess.check_call(['patch', '-u', c_file, c_patch_file])
output = subprocess.run(cmd, capture_output=True, text=True)
res = subprocess.run(cmd, cwd=cwd, capture_output=True, text=True,
                         errors="replace", **kwargs)
res = subprocess.run(
        [
            "git",
            "diff",
            "--name-only",
            "--diff-filter=ACMR",
            "-z",
            sha,
            "--",
            # Check against C_CPP_EXTENSIONS …
subprocess.check_call(cmd, stdout=pipe, stderr=pipe)
res = subprocess.run(
            command,
            stdout=subprocess.PIPE,
            cwd=self.repository_root,
            encoding="utf-8",
        )
res = subprocess.run(
            command,
            stdout=subprocess.PIPE,
            cwd=self.repository_root,
            encoding="utf-8",
        )
borrowed_res = subprocess.run(
            [sys.executable, borrowed_ref_script],
            cwd=self.repository_root,
            stdout=subprocess.PIPE,
            stderr=subprocess.STDOUT,
            text=True,
            check=False …
result = subprocess.run(
        ["basedpyright", *pyright_args],
        capture_output=True,
        text=True,
    )
os.system(f"cp {notes} {target_rst}")
subprocess.run(
        ["pandoc", "-s", "-o", str(target_md), str(target_rst), "--wrap=preserve"],
        check=True,
    )

Why it matters: Powerful and often legitimate — confirm the commands aren't built from untrusted input.

Fix: Confirm the command and its arguments are fully controlled and not derived from untrusted input; avoid shell=True.

MEDIUMPython filesystem readST-FS-PY-READ

The component reads files from disk.

with open(template_name, "rb") as f:
f_ctx = open(
                os.fspath(filename),
                ('r' if mode == 'c' else mode) + 'b'
            )
ctx = open(os.fspath(fd), 'rb')
with open(filename, encoding=encoding, errors=errors, newline="") as fp:
return self.build_template_path.read_text()
with open(source) as fid:
with open(source) as f:
with open(f2cmap_file) as f:
with open(filename, 'rb') as fhandle:
return open(filename, mode, encoding=encoding)
magic_str = _read_bytes(fp, MAGIC_LEN, "magic string")
hlength_str = _read_bytes(fp, struct.calcsize(hlength_type), "array header length")
header = _read_bytes(fp, header_length, "array header")
data = _read_bytes(fp, read_size, "array data")
with open(os.fspath(filename), mode + 'b') as fp:
with open(os.fspath(filename), 'rb') as fp:

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMPython filesystem write/deleteST-FS-PY-WRITE

The component writes or deletes files on disk.

with open(outfile, 'w') as f:
with open(local, "wt", encoding="utf8") as fid:
with open(pkg_config_fname, "wt", encoding="utf8") as fid:
with open(outfile, 'w') as f:
with open(outfile, 'w') as f:
with open(options.output, "wb") as f:
ctx = open(os.fspath(file), "wb")
with open(filename, "w", encoding=encoding, errors=errors, newline="") as fp:
shutil.copy2(path_object, dest_path)
meson_build_file.write_text(src)
shutil.copy(generated_source, bdir / generated_source.name)
with open(pyffilename, 'w') as f:
with open(options['signsfile'], 'w') as f:
with open(fn, 'w') as f:
with open(fn, 'w') as f:
with open(fn, 'w') as f:

Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.

Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.

MEDIUMPython network egressST-NET-PY

The component makes outbound network requests.

urllib.request.urlretrieve(PYTHONCAPI_COMPAT_URL, target)
from urllib.request import urlopen
with urlopen(path) as openedurl:
from urllib.request import urlopen

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →