Back to skill

Security audit

Weather Plus Cn

Security checks for vulnerabilities and agentic risk

Overview

This is a purpose-aligned China weather lookup skill, with a notable but limited risk from using unencrypted weather requests.

Installers should understand that this skill is designed for Chinese city weather queries and may return Chinese-language output. Its main risk is that weather.com.cn is fetched over HTTP in both instructions and script, so avoid relying on it for safety-critical severe-weather decisions unless the URLs are updated to HTTPS and remote page content is treated strictly as untrusted data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/weather_query.py:26
Finding

Cleartext HTTP Allows Weather Response Tampering

Content
View full analysis

Vulnerability Details

File Location: scripts/weather_query.py:26
Vulnerability Type: Cleartext HTTP transport
Risk Level: Medium

Vulnerable Code

python
def fetch_weather_page(city_code: str) -> str:
    """获取天气网页面内容"""
    url = f"http://www.weather.com.cn/weather/{city_code}.shtml"
    
    try:
        req = urllib.request.Request(
            url,
            headers={
                'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36',
                'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8',
                'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8',
            }
        )
        with urllib.request.urlopen(req, timeout=15) as response:
            return response.read().decode('utf-8')

The same insecure endpoint is recommended in SKILL.md:29-32 and SKILL.md:87 and is referenced in references/city_codes.md:107-108.

Technical Analysis

The application retrieves weather data using unencrypted HTTP. HTTP provides neither server authentication nor transport integrity, allowing an attacker with a suitable network position to intercept and modify the response.

The returned HTML is passed directly to parse_weather_info(). Parsed weather conditions and temperatures are then used to generate user-visible forecasts and clothing advice. No independent response-integrity or authenticity verification is performed.

The documented web_fetch workflow likewise instructs an agent to retrieve and parse content through HTTP. If downstream processing does not strictly isolate remote content as untrusted data, attacker-injected page text could also attempt to influence agent behavior. This audit did not establish that arbitrary code execution results from such content.

Attack Path

  1. A user invokes the Skill to query weather for a supported city.

...[truncated 958 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace every http://www.weather.com.cn URL in the script and documentation with https://www.weather.com.cn.
  2. Reject redirects from HTTPS to HTTP and verify that the final response URL retains the expected HTTPS scheme and trusted hostname.
  3. Validate input before constructing the request URL:
    python
    if not re.fullmatch(r"\d{9}", city_code):
        raise ValueError("City code must contain exactly nine digits")
    
  4. Treat all downloaded content as untrusted data. Parse only expected weather fields and never interpret remote page content as agent instructions or executable code.
  5. Add tests confirming that plaintext endpoints and HTTPS-to-HTTP redirects are rejected.
  6. Update SKILL.md and references/city_codes.md so users and agents are not directed to insecure HTTP endpoints.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The request header sets Accept-Language to zh-CN,zh;q=0.9,en;q=0.8, which forces a specific locale preference in outbound requests. Under the policy rules, this is a natural-language locale constraint and there is no user opt-in or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, including usage instructions and examples. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.