T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Weather requests use unencrypted HTTP transport
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16, 22, 28, and 38
Vulnerability Type: Plaintext external service communication
Risk Level: MediumVulnerable Code:
bash curl -s "wttr.in/London?format=3"bash curl -s "wttr.in/London?format=%l:+%c+%t+%h+%w"bash curl -s "wttr.in/London?T"bash curl -s "wttr.in/Berlin.png" -o /tmp/weather.pngTechnical Analysis
The wttr.in URLs omit an explicit URI scheme. Curl treats these host-style URLs as HTTP requests, so the location query and returned weather information are transmitted without TLS protection.
An attacker with a privileged network position, such as an operator of a malicious access point or a compromised network intermediary, could observe requested locations or modify responses in transit. Because the returned text may be consumed directly by an AI agent, response tampering could also provide misleading or attacker-controlled content to the current workflow.
Attack Path
- A user asks the agent to obtain weather information.
- The agent executes one of the documented curl commands.
- Curl connects to wttr.in over plaintext HTTP because no HTTPS scheme is specified.
- A network-positioned attacker intercepts the request.
- The attacker observes the requested location, modifies the response, or redirects the request.
- The agent presents or processes the untrusted response as weather-service output.
Impact Assessment
Exploitation does not directly grant local system privileges. It can expose queried location information and compromise the integrity of weather data returned to the agent. The scope is limited to requests made through the affected wttr.in commands and content derived from their responses.
- Remediation
View remediation
Remediation Suggestions
-
Specify HTTPS explicitly for every wttr.in request:
bash curl --fail --silent --show-error "https://wttr.in/London?format=3" -
Update all remaining examples to use
https://wttr.in/.... -
Use
--proto '=https'to prevent fallback to unencrypted protocols:bash curl --fail --silent --show-error --proto '=https' \ "https://wttr.in/London?format=3" -
Validate or safely treat external responses as untrusted data before using them in subsequent agent operations.
-
