Back to skill

Security audit

Weather Tool

Security checks for vulnerabilities and agentic risk

Overview

This is a simple weather skill whose behavior matches its purpose, but it has an insecure HTTPS implementation users should understand before relying on it.

This skill appears safe to install for basic weather lookups, but treat its results as untrusted until the HTTPS verification issue is fixed. Avoid using it for safety-critical travel, emergency, or automated decisions, and be aware that entered location names are sent to the external wttr.in service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/weather.py:24
Finding

HTTPS Certificate and Hostname Verification Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/weather.py, lines 24–29
Vulnerability Type: Improper TLS certificate validation
Risk Level: Medium

Vulnerable Code

python
ctx = ssl.create_default_context()
ctx.check_hostname = False
ctx.verify_mode = ssl.CERT_NONE

req = urllib.request.Request(url)

with urllib.request.urlopen(req, timeout=10, context=ctx) as resp:
    data = json.loads(resp.read().decode())

Technical Analysis

The script creates a default TLS context but then explicitly disables both hostname verification and certificate verification. Consequently, the HTTPS connection does not authenticate the identity of wttr.in.

An attacker capable of intercepting the connection can present an arbitrary certificate and impersonate the weather service. The script will accept the connection, decode the response, parse it as JSON, and either print the complete response or extract weather fields from it.

The response is treated as data rather than executable code, so the reviewed implementation does not provide a demonstrated remote-code-execution path. Nevertheless, disabling TLS validation compromises the authenticity and integrity guarantees expected from HTTPS.

Attack Path

  1. A user invokes the Skill to obtain weather information.
  2. The script constructs an HTTPS URL for wttr.in.
  3. An attacker with a network interception position redirects or intercepts the connection.
  4. The attacker presents a certificate that would ordinarily fail trust or hostname validation.
  5. Because the script sets check_hostname to False and verify_mode to ssl.CERT_NONE, it accepts the attacker's endpoint.
  6. The attacker returns crafted JSON matching, or partially matching, the expected response structure.
  7. The script parses and displays the attacker-controlled weather data. A malformed or excessively large response may also trigger processing errors or consume resources.

Impact Assessment

An on-path attacker can comprom ...[truncated 553 chars]

Remediation
View remediation

Remediation Suggestions

Remove the insecure TLS context configuration and rely on Python's platform-default certificate and hostname validation:

python
req = urllib.request.Request(url)

with urllib.request.urlopen(req, timeout=10) as resp:
    data = json.loads(resp.read().decode())

If an explicit context is required, retain the secure defaults without modifying check_hostname or verify_mode:

python
ctx = ssl.create_default_context()
req = urllib.request.Request(url)

with urllib.request.urlopen(req, timeout=10, context=ctx) as resp:
    data = json.loads(resp.read().decode())

Additionally:

  1. Handle certificate-validation failures as hard errors; do not silently retry with verification disabled.
  2. Limit the number of response bytes read before JSON parsing to reduce denial-of-service risk from oversized responses.
  3. Validate the returned JSON structure and expected field types before formatting it.
  4. Add automated tests confirming that untrusted certificates and hostname mismatches are rejected.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill documentation exposes executable code usage for a weather script that likely performs network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: the agent may invoke code with network capability without an explicit policy boundary, making review, sandboxing, and least-privilege enforcement harder.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code disables both TLS certificate validation and hostname verification before fetching weather data over HTTPS, which allows a man-in-the-middle attacker to impersonate wttr.in and return attacker-controlled responses. In this skill context, the tool consumes remote content and can emit it as raw JSON, so compromised transport undermines the trustworthiness of all output and could mislead downstream automation or users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request URL includes lang=en in both branches, which forces English output regardless of user preference. The policy explicitly flags language or locale constraints when they are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/weather.py:24