Back to skill

Security audit

度小满天气商户

Security checks for vulnerabilities and agentic risk

Overview

The weather skill has a coherent service purpose, but its bundled scripts handle passwords, endpoint selection, QR data, and file writes in ways that are broader and less disclosed than users would expect.

Install only if you trust dxmpay.com with weather queries, account metadata, purchase details, and any QR content this package may process. Avoid placing the private-key password in command text, do not set SP_WEATHER_BASE unless you fully control and trust the endpoint, and treat generated QR files as persistent local artifacts that may need cleanup.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/qrcode.js:157
Finding

Arbitrary QR Code Content Is Disclosed to a Remote URL-Shortening Service

Content
View full analysis
{ // API parameters const postData = querystring.stringify({ version: '2', url: longUrl }); const options = { hostname: 'www.dxmpay.com', port: 443, path: '/facilepaycenter/tinyurl/createurl', method: 'POST', headers: { 'Content-Type': 'application/x-www-form-urlencoded', 'Content-Length': Buffer.byteLength(postData) }, secureOptions: require('crypto').constants.SSL_OP_LEGACY_SERVER_CONNECT }; const req = https.request(options, (res) => { let result = ''; res.on('data', (chunk) => { result += chunk; }); res.on('end', () => { try { const jsonRes = JSON.parse(result); resolve(jsonRes); } catch (e) { resolve(result); } }); }); req.on('error', (e) => { reject(e); }); req.write(postData); req.end(); }); } ``` ```javascript const shortUrlResult = await createDxmShortUrl(text); if (shortUrlResult && shortUrlResult.content&&shortUrlResult.content.tinyurl) { text = "https://www."+shortUrlResult.content.tinyurl; } ``` ### Technical Analysis The QR generator submits every input string to `www.dxmpay.com` before generating the QR code locally. There is no check that the input is a URL, uses HTTPS, or belongs to the `www.dxmpay.com` domain. This behavior contradicts the restriction stated in `SKILL.md`, which claims that the short-link service only receives URLs beginning with `https://www.dxmpay.com/`. The implementation will instead transmit arbitrary QR content, including access tokens, private links, personal information, ...[truncated 962 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sp-weather-cli.js:11
Finding

Unvalidated Base URL Allows Request Redirection and Plaintext HTTP

Content
View full analysis
{ const urlObj = new URL(url); const lib = urlObj.protocol === 'https:' ? https : http; const reqOptions = { hostname: urlObj.hostname, port: urlObj.port || (urlObj.protocol === 'https:' ? 443 : 80), path: urlObj.pathname + urlObj.search, method: options.method || 'GET', headers: options.headers || {}, }; ``` The unvalidated value is used for registration and subsequent service requests, for example: ```javascript res = await httpRequest(`${BASE_URL}/api/skill/client/register`, { method: 'POST', headers: { 'Content-Type': 'application/json', 'Content-Length': Buffer.byteLength(body), }, body, }); ``` ### Technical Analysis `SP_WEATHER_BASE` accepts an arbitrary URL. The HTTP client explicitly supports both HTTPS and plaintext HTTP, and no hostname or protocol allowlist is enforced. An attacker who can influence the process environment can redirect registration and authenticated API requests to an attacker-controlled host. The transmitted material can include the generated public key, registration signature, user identifier, city and date queries, signed request parameters, and service activity metadata. Although private-key signatures should not directly disclose the private key, collecting signed messages creates an impersonation and protocol-analysis risk if the server does not enforce strict destination, timestamp, and replay controls. Plaintext HTTP additionally permits network interception and response manipulation. This implementation contradicts the documentation's assertion that all reque ...[truncated 922 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sp-weather-cli.js:181
Finding

Legacy TLS Server Connection Mode Is Forced for Sensitive Requests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:47
Finding

Documented Password Handling Exposes Secrets to Shell Interpretation and Logging

Content
View full analysis
&& node scripts/sp-weather-cli.js ``` > **注意**:密码仅在命令行内联使用,不写入任何文件,不输出到日志。 ``` ### Technical Analysis The Skill instructions direct the agent to interpolate a user-provided password into an inline shell command. This is unsafe for two independent reasons: 1. The secret may become visible in agent tool transcripts, command auditing, shell history, diagnostic logging, or process-launch telemetry. 2. The placeholder is not quoted or safely passed through a process API. Passwords containing shell metacharacters, substitutions, whitespace, or control operators may alter parsing and potentially execute unintended commands. The claim that the password is not logged is not guaranteed when the password is embedded directly into a shell command submitted by an agent. The CLI already supports hidden terminal input, so command-line interpolation is unnecessary. ### Attack Path Secret disclosure path: 1. The agent asks the user for the private-key password. 2. The agent constructs the documented inline `export` command. 3. The complete command, including the password, is submitted to a shell tool. 4. Agent transcripts, shell auditing, history, or process telemetry retain the secret. 5. A party with access to those records obtains the private-key password. Command-injection path: 1. A password contains shell syntax such as command separators or command substitution. 2. The agent inserts the value into the command without safe process-level argument handling. 3. The shell interprets the syntax rather than treating the complete value as data. 4. Commands execute with the privileges of the agent process. ### Impact Assessment Password disclosure can c ...[truncated 333 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/qrcode.js:195
Finding

QR Filename Path Traversal and Unconditional File Creation

Content
View full analysis
{ ``` ### Technical Analysis The utility always writes a PNG file, even when `options.saveToFile` is false. In addition, `options.fileName` is passed to `path.join(process.cwd(), filename)` without rejecting absolute-path behavior, path separators, or `..` traversal segments. A malicious filename such as `../../target` can escape the working directory. `fs.writeFileSync()` uses overwrite semantics, so an existing writable file may be replaced with PNG bytes. The attack is constrained by the operating-system permissions of the process. It cannot overwrite files that the process cannot write. ### Attack Path 1. An attacker influences the filename passed through `--filename`, `-f`, or the programmatic API. 2. The attacker supplies a traversal path such as `../../some-writable-file`. 3. `path.join()` resolves the path outside the intended working directory. 4. `fs.writeFileSync()` creates or overwrites the destination with PNG data. 5. The target file becomes corrupted or replaced. Separately, normal QR generation without `--save` still creates a file because the `saveToFile` option is ignored. ### Impact Assessment The process can create or overwr ...[truncated 293 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sp-weather-cli.js:365
Finding

Undefined QR Rendering Function Enables Server-Triggered Payment-Flow Denial of Service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding reflects another documented behavior mismatch: the skill encompasses QR/image rendering and arbitrary text-to-QR transformation capabilities not implied by the weather-service description. Such hidden general-purpose encoding/output features can be repurposed to package untrusted content into user-scannable artifacts, expanding the attack surface beyond the stated domain context. The mismatch is especially dangerous because users may trust the skill as a narrow informational tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding reflects another documented behavior mismatch: the skill encompasses QR/image rendering and arbitrary text-to-QR transformation capabilities not implied by the weather-service description. Such hidden general-purpose encoding/output features can be repurposed to package untrusted content into user-scannable artifacts, expanding the attack surface beyond the stated domain context. The mismatch is especially dangerous because users may trust the skill as a narrow informational tool.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
**脚本路径**: `scripts/sp-weather-cli.js`(相对于 skill 目录)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script advertises a local, dependency-free QR generator, but it actually sends the supplied input to an external shortening service and may replace the original content with a returned short URL. This creates an undisclosed data exfiltration path and changes the encoded payload, which is especially dangerous if the input contains internal URLs, tokens, or user data that should never leave the environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Within a weather-service skill, embedding QR generation, URL shortening, and local file-writing functionality is out of scope and materially increases attack surface. In this context, the capability can be abused to package arbitrary links into QR codes, transmit data to an external service, and leave artifacts on disk, none of which are necessary for the stated weather/usage-query purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function contract says file saving is optional, but the implementation always writes a PNG into the current working directory regardless of the caller's choice. Unconditional filesystem writes can leak data to disk, overwrite expected workspace contents, and create persistence or storage side effects in environments that assume pure in-memory processing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares environment-variable usage and operational behavior but does not specify an explicit tool/permission scope. In practice, it expects access to sensitive environment variables and shell execution patterns, which can cause an agent platform to grant broader capabilities than users realize. This is more concerning because the skill handles a password-like secret and persists local configuration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad everyday language such as generic weather-related questions, making accidental invocation more likely. Over-broad activation increases the chance that the skill collects a password prompt, accesses configuration, or reaches external services in contexts where the user did not intend to use this specific provider. In a skill that can escalate into account/order/payment flows, accidental triggering meaningfully raises risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

文件整体以中文规定触发词、提示语和执行话术,尤其描述字段直接限定为中文用户提问场景,但没有说明支持其他语言或允许用户自行选择语言。这构成潜在的语言/locale 策略问题,因为它默认强制单一语言而非显式 opt-in。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are loosely bounded across multiple query types and do not provide exclusions or disambiguation rules. This can cause the skill to activate on ambiguous requests and then perform sensitive follow-on steps, including secret collection and external API usage, without strong user intent validation. The broader the intent surface, the easier it is to socially engineer or accidentally invoke privileged behaviors.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.