Back to skill

Security audit

Go Stargazing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese stargazing recommendation tool that uses local region data and Open-Meteo weather queries without evidence of hidden persistence, credential access, or destructive behavior.

Install in an isolated Python environment, pin or lock lunarcalendar and shapely before production use, and expect the skill to send queried coordinates and dates to Open-Meteo when real-weather mode is used. Treat the results as regional planning guidance, especially because some reviewed code comments and formulas suggest possible accuracy bugs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Supply-Chain Changes

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code

text
lunarcalendar
shapely

Technical Analysis

The project declares lunarcalendar and shapely without exact versions or cryptographic hashes. Each installation can therefore resolve to whatever package versions currently satisfy these unconstrained requirements rather than to the versions reviewed during this audit.

This does not prove that either package is currently malicious. The vulnerability is that dependency resolution is mutable and lacks integrity enforcement. If an upstream release, maintainer account, package distribution channel, or transitive dependency is compromised, a later installation could retrieve and execute code that was not part of the audited project.

Python packages can execute code during installation or when imported. In this project, both dependencies are imported by runtime scripts, so compromised package code could execute within the privileges and environment of the user running the installation or application.

Attack Path

  1. An attacker compromises an upstream package release, maintainer account, distribution channel, or relevant transitive dependency.
  2. The attacker publishes a malicious version under the legitimate package name.
  3. A user installs the project dependencies using the unpinned requirements.txt.
  4. The package manager resolves and downloads the malicious or otherwise unreviewed release.
  5. Malicious code executes during package installation or when the dependency is imported by the project.
  6. The code gains access to resources available to the installing or runtime user.

Impact Assessment

Successful exploitation could permit arbitrary Python code execution with the privileges of the user installing or running the project. Depending on that environment, the compromised dependency could read or modify accessible fi ...[truncated 358 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to a specifically reviewed version, for example:

    text
    lunarcalendar==REVIEWED_VERSION
    shapely==REVIEWED_VERSION
    
  2. Generate and commit a lock file or hash-checked requirements file containing resolved transitive dependencies and SHA-256 hashes.

  3. Install dependencies with hash enforcement, such as pip install --require-hashes -r requirements.txt, when using a compatible generated requirements file.

  4. Obtain packages only from an explicitly configured trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.

  5. Review dependency provenance, release history, known vulnerabilities, and transitive dependency changes before updating pins.

  6. Automate dependency vulnerability scanning while keeping updates deliberate and reviewable.

  7. Build and install dependencies in a least-privileged, isolated environment without unnecessary credentials or filesystem access.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description specifies a concrete end-user skill: scanning regions, filtering by cloud cover and actual weather, and producing stargazing recommendations. However, the supplied code chunk contains only a launcher script that imports and runs main() from another file. On its own, this code does not demonstrate the stated functionality, resource access, or output behavior. Because the visible code's primary purpose is delegation rather than implementing the described skill behavior, the description is not accurately represented by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明强调这是一个基于区域和天气条件的“拍星推荐”技能,核心能力应是地理范围筛选、天气/云量数据处理和推荐生成。但提供的代码块是一个本地天文计算模块,主要用于太阳/月亮位置、暮光时间和观测窗口估算。它没有任何网络访问、天气 API、云量处理、区域遍历、全国/省市筛选、推荐决策或气象信息输出能力。虽然这些天文计算可能是拍星推荐系统的支撑组件,但就该代码块本身而言,其实际行为与声明的主要功能存在明显差异,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a functional stargazing recommendation engine that evaluates regions by weather conditions and produces recommendation results. The supplied code chunk does none of that. It contains only two simple helper/stub functions for joint advice/judgement, both returning static or near-static placeholder content with no weather analysis, no date handling, no regional scanning logic, and no recommendation generation. This is a materially different behavior from the declared purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个基于区域、云量和真实天气进行拍星条件筛选与推荐的技能,核心应涉及天气数据获取、区域扫描、条件筛选和推荐输出。实际代码完全没有天气、区域、云量、省市、全国扫描或拍星推荐相关逻辑,也没有任何外部天气资源访问。相反,代码实现的是日期转换和月相查询的命令行工具,主要处理农历/公历转换、日期范围遍历以及月相估算。这属于主要用途明显不同,并且包含与声明无关的实际能力,因此应判定为明显不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
- `scripts/go_stargazing_engine/engine.py`:主流程编排

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring at L111-L113 says the function returns a UTC datetime for the sun reaching the requested altitude. However, the implementation converts to local time at L122-L133 and then discards the computed result, returning sunset_local at L148-L150, which is just the local date at 00:00:00. This is an active contradiction between the documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares network and file-dependent behavior but does not specify any tool scope or allowed-tools boundary in the manifest. That creates an authorization ambiguity where an agent/runtime may grant broader file or network access than the skill actually needs, increasing the blast radius if the skill is invoked or later extended unsafely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction "只说自然中文" mandates a specific language for all user-facing output. This is a natural-language policy concern because it does not offer the user any language choice or indicate that Chinese is optional or region-justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code hard-codes all user-facing advisory text and weather labels in Chinese, indicating the skill will respond in a specific language regardless of user preference. That is a natural-language policy concern because the file does not offer any locale selection, opt-in, or justification for a Chinese-only experience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring at L317 states 'Moon above horizon: interference = illum * cos(altitude) normalized' and L321 comments that cosine is 1 when overhead and 0 near horizon, but cos(0)=1 and cos(90)=0, so the comment is reversed. As implemented at L322-L323, the score gives less interference when the moon is higher, contradicting the stated intent of the documentation.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/go_stargazing_engine/astronomy.py (reported line 380)May include surrounding context.

python
steps = int(((t_end - t_start).total_seconds() / 60 / step_minutes))
    for i in range(steps):
        t_current = t_start.replace(minute=t_start.minute + i * step_minutes)
        if t_current.day != (t_start + __import__('datetime').timedelta(minutes=i*step_minutes)).day:
            break
        current_alt = moon_alt_at_hours(t_current)
        # Detect crossing from below to above (moonrise)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function returns multiple hard-coded Chinese natural-language messages, which imposes a specific language on users. There is no visible opt-in, configuration, or documentation in this file indicating that the skill is intentionally limited to Chinese-speaking users or a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains many user-visible strings in Chinese for notes, labels, and output lines, such as the text returned in helper functions and ranking output. Because the skill forces a specific language in its natural-language outputs without any visible user opt-in or locale selection mechanism in this file, it matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains many user-facing response strings in Chinese, beginning with module-level constants and continuing throughout the output-building functions. Because the skill forces a specific language in its natural-language outputs without any visible opt-in or configurable locale handling, it violates the language/locale policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains extensive natural-language output content in Chinese, including city names, descriptive labels, and returned user-facing strings, but provides no indication that the skill is China-region-specific or that users can opt into the locale. Under the policy, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function defaults to Chinese text for both the fallback label and the returned user-facing message. Because this is a code file and there is no indication that the skill is region-specific or that users can opt into Chinese output, this appears to enforce a specific locale in natural-language output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The returned user-facing strings are all hard-coded in Chinese, and there is no indication in this file that the skill offers a language choice or that the locale restriction is documented. This can violate language/locale policy because the skill appears to force a specific language on all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file constructs all user-facing phrases and labels in Chinese, including summaries, advisories, and display labels, with no indication that the user can opt into another language. This matches the policy category for language/locale violations because the skill appears to force a specific language in natural-language outputs without documented justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The note strings in this section are written only in Chinese and appear intended for end-user consumption via the score breakdown. That imposes a specific language on users without offering a language choice or documenting a justified region-specific restriction, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The comments say that for stargazing, less moonlight is better and therefore 'moonlight_helps' should be '(100 - moonlight_score)'. But the documented meaning of 'moonlight_score' on the preceding lines is already '100 = no moonlight' and '0 = bright moon above horizon', so subtracting it inverts the intended preference and rewards more moonlight. This is an active contradiction between the inline documentation and the implemented calculation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/go_stargazing_engine/weather.py (reported line 19)May include surrounding context.

python
from .models import SamplePoint
from .scoring import best_true_window, classify_cloud_stability, derive_night_window, deterministic_value, is_usable_observation_hour, longest_true_streak, moon_factor, safe_float, sample_stddev, segment_name

OPEN_METEO_FORECAST_URL = "https://api.open-meteo.com/v1/forecast"
# Open-Meteo hourly forecast window (days from today)

OPEN_METEO_HOURLY_WINDOW_DAYS = 16

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This line sets tz_offset = 8.0 # Asia/Shanghai, embedding a specific locale assumption directly in the code path for moonrise/moonset and dark-window computation. Because the file otherwise accepts a timezone parameter, this fixed locale is inconsistent and may force a specific regional setting without explicit user choice or documented necessity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring describes this file as a '农历/公历转换查询工具' and exposes commands for calendar conversion, date ranges, and moon-phase estimation. The manifest, however, describes a lightweight regional stargazing recommendation skill focused on cloud/weather-based screening and nightly recommendations, so this functionality is outside the described behavior rather than an obvious implementation detail.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency lunarcalendar is unpinned, so installs may pull different versions over time, including versions with breaking changes or newly introduced malicious or vulnerable code from the supply chain. In a skill that relies on external packages for date and astronomy-related filtering, this mainly creates reproducibility and supply-chain risk rather than an immediate direct exploit in this file alone.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
lunarcalendar
shapely

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency shapely is unpinned, which allows future installs to resolve to any available version, increasing exposure to accidental breakage or supply-chain compromise. Because shapely is a compiled/geospatial package often distributed as wheels, unpinned resolution can also introduce platform-specific instability or vulnerable builds if the upstream ecosystem is compromised.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
lunarcalendar
shapely

Static analysis

No suspicious patterns detected.