T09 · Insecure Skill Coding Practices
- Location
scripts/weather_query.py:26- Finding
Cleartext HTTP Allows Weather Response Tampering
- Content
View full analysis
Vulnerability Details
File Location:
scripts/weather_query.py:26
Vulnerability Type: Cleartext HTTP transport
Risk Level: MediumVulnerable Code
python def fetch_weather_page(city_code: str) -> str: """获取天气网页面内容""" url = f"http://www.weather.com.cn/weather/{city_code}.shtml" try: req = urllib.request.Request( url, headers={ 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36', 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8', 'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8', } ) with urllib.request.urlopen(req, timeout=15) as response: return response.read().decode('utf-8')The same insecure endpoint is recommended in
SKILL.md:29-32andSKILL.md:87and is referenced inreferences/city_codes.md:107-108.Technical Analysis
The application retrieves weather data using unencrypted HTTP. HTTP provides neither server authentication nor transport integrity, allowing an attacker with a suitable network position to intercept and modify the response.
The returned HTML is passed directly to
parse_weather_info(). Parsed weather conditions and temperatures are then used to generate user-visible forecasts and clothing advice. No independent response-integrity or authenticity verification is performed.The documented
web_fetchworkflow likewise instructs an agent to retrieve and parse content through HTTP. If downstream processing does not strictly isolate remote content as untrusted data, attacker-injected page text could also attempt to influence agent behavior. This audit did not establish that arbitrary code execution results from such content.Attack Path
- A user invokes the Skill to query weather for a supported city.
...[truncated 958 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace every
http://www.weather.com.cnURL in the script and documentation withhttps://www.weather.com.cn. - Reject redirects from HTTPS to HTTP and verify that the final response URL retains the expected HTTPS scheme and trusted hostname.
- Validate input before constructing the request URL:
python if not re.fullmatch(r"\d{9}", city_code): raise ValueError("City code must contain exactly nine digits") - Treat all downloaded content as untrusted data. Parse only expected weather fields and never interpret remote page content as agent instructions or executable code.
- Add tests confirming that plaintext endpoints and HTTPS-to-HTTP redirects are rejected.
- Update
SKILL.mdandreferences/city_codes.mdso users and agents are not directed to insecure HTTP endpoints.
- Replace every
