Back to skill

Security audit

Weather Radar

Security checks for vulnerabilities and agentic risk

Overview

This weather radar skill does what it claims: it fetches public map and radar tiles to generate a GIF, with no hidden persistence or credential access found.

Before installing, be aware that radar generation contacts RainViewer and OpenStreetMap and can reveal the approximate requested location through map tile requests. For higher-control environments, pin dependency versions and run the skill in a sandbox with only the output directory writable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Unpinned Runtime Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34–36
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
### Dependencies

The script requires `requests` and `Pillow`. If they are not installed, run `pip install requests Pillow` before executing the script.

Technical Analysis

The Skill instructs the agent to install requests and Pillow directly from the package index without specifying reviewed versions or validating package hashes. This makes installation results dependent on mutable external package-index state.

Although both package names are legitimate and no malicious dependency is included in the repository, the instruction lacks safeguards against a compromised release, compromised package-index account, unexpected dependency change, or future incompatible version. Python package installation can execute package-controlled build logic, and installed code subsequently executes when imported by scripts/generate_radar.py.

Attack Path

  1. One of the named packages, or a dependency selected by pip, is compromised upstream.
  2. The required module is absent from the runtime environment.
  3. The agent follows SKILL.md and runs pip install requests Pillow.
  4. Pip resolves and downloads the current, unverified package artifacts.
  5. Malicious package-controlled code executes during installation, build processing, or subsequent import.
  6. The payload operates with the privileges and environmental access of the account running the agent.

This path requires an upstream supply-chain compromise or unsafe package-index configuration; the audited project does not itself provide or retrieve an identified malicious package.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the agent process. Depending on its environment, this may expose accessible files, environment variabl ...[truncated 242 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a reviewed dependency lock file containing exact versions and cryptographic hashes.
  • Install dependencies with hash enforcement, for example:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  • Use an isolated virtual environment or sandbox with minimal filesystem and network permissions.
  • Configure pip to use an explicitly trusted package index and disallow unexpected extra indexes.
  • Periodically review pinned versions for security advisories and update them through a controlled dependency-review process.
  • Prefer a prebuilt, reproducible runtime image so the Skill does not install packages dynamically during normal execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a Python script that performs external network access, but the manifest does not declare any tool scope or permissions boundary. This weakens reviewability and policy enforcement because an agent may use network-capable code without an explicit declaration that users or platform controls can inspect and restrict.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_radar.py (reported line 34)May include surrounding context.

python
"""
    # 1. Fetch radar timestamps
    try:
        rv_api = requests.get("https://api.rainviewer.com/public/weather-maps.json").json()
        rv_host = rv_api["host"]
        # Get the last N frames
        past_data = rv_api["radar"]["past"][-num_frames:]

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill instructs using the user's known location as a default and fetching third-party radar data, but it does not disclose the privacy implications or external data transfer. This can cause unanticipated sharing of location-derived context and file generation/sending behavior without adequate transparency or consent cues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes fetching and generating an image of the current weather radar combined with a base map. This implementation explicitly fetches multiple past radar frames, composites them, and saves an animated GIF, which is broader than a single current radar image.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The argument declaration sets the default for --frames to 8, but the help string says only 'Number of historical frames to include' while the function signature default is 6. This creates conflicting documentation about actual behavior for omitted values.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.