Back to skill

Security audit

Weather Plus

Security checks for vulnerabilities and agentic risk

Overview

The weather features are mostly coherent, but the skill includes real billing actions that can charge by default and lacks clear consent and credential-handling safeguards.

Review this skill carefully before installing. The weather functions are straightforward, but the billing script can perform real SkillPay charges and defaults to charging unless another mode is selected. Only use it where per-call billing is intended, avoid passing API keys on the command line, and require explicit user approval before any charge or payment-link action.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/billing.py:51
Finding

SkillPay API Key Exposure Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/billing.py, lines 51–60
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

python
p = argparse.ArgumentParser()
p.add_argument("--user-id", required=True)
p.add_argument("--amount", type=float, default=0.001)
p.add_argument("--api-key", default=None)
g = p.add_mutually_exclusive_group()
g.add_argument("--charge", action="store_true", default=True)
g.add_argument("--balance", action="store_true")
g.add_argument("--payment-link", action="store_true")
a = p.parse_args()
if a.balance: r = balance(a.user_id, a.api_key)

The parsed credential is also passed to the charge or payment-link functions on the subsequent branches:

python
elif a.payment_link: r = payment_link(a.user_id, a.amount or 5.0, a.api_key)
else: r = charge(a.user_id, a.amount, a.api_key)

Technical Analysis

The script allows the SkillPay API credential to be supplied using the --api-key command-line option. Command-line arguments are not an appropriate secret transport mechanism because they can be exposed through:

  • Process inspection utilities while the command is running.
  • Operating-system process accounting or monitoring systems.
  • Shell command history.
  • Automation logs, diagnostic output, and job-control interfaces.

A local user or monitoring process with permission to inspect the invoking user's processes or command history could recover the credential. The recovered key is transmitted to the declared SkillPay endpoint as an X-API-Key header, so possession of it may enable unauthorized requests to the billing API.

Sending the key to https://skillpay.me/api/v1 is consistent with the billing functionality disclosed in SKILL.md and is not evidence of covert exfiltration. The vulnerability is specifically the optional command-line method used to provide that secret.

Attack Pat

...[truncated 1262 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --api-key command-line option and do not accept secrets through process arguments.
  2. Read the credential exclusively from SKILLPAY_API_KEY or a dedicated secret-management service.
  3. For interactive use, optionally obtain the key through getpass.getpass() so it is not echoed or retained in shell history.
  4. Ensure application, orchestration, and diagnostic logs redact API keys and authorization headers.
  5. Grant the key only the minimum billing permissions required by this Skill and use a separate credential for each deployment.
  6. Rotate any key that has previously been supplied through --api-key, because it may already exist in process records or shell history.
  7. Apply server-side transaction limits, auditing, anomaly detection, and key revocation controls to reduce the consequences of disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill claims current weather, clothing advice, comfort index, and billing integration that are not actually present or visible, users may be misled into trusting and invoking a capability set that the code does not support. In a paid skill, inaccurate capability claims materially increase risk because they can mask monetization behavior or cause unintended use of a nonfunctional tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill claims current weather, clothing advice, comfort index, and billing integration that are not actually present or visible, users may be misled into trusting and invoking a capability set that the code does not support. In a paid skill, inaccurate capability claims materially increase risk because they can mask monetization behavior or cause unintended use of a nonfunctional tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill claims current weather, clothing advice, comfort index, and billing integration that are not actually present or visible, users may be misled into trusting and invoking a capability set that the code does not support. In a paid skill, inaccurate capability claims materially increase risk because they can mask monetization behavior or cause unintended use of a nonfunctional tool.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill claims current weather, clothing advice, comfort index, and billing integration that are not actually present or visible, users may be misled into trusting and invoking a capability set that the code does not support. In a paid skill, inaccurate capability claims materially increase risk because they can mask monetization behavior or cause unintended use of a nonfunctional tool.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable scripts and requires an API key, but the manifest provides no explicit tool/permission boundaries despite detected shell, network, and environment access. That creates unnecessary ambiguity around what the skill is allowed to do and increases the risk of over-privileged execution or abuse if the scripts perform actions beyond the stated weather use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow shows a charge command as the first step, and the documentation mentions a per-call fee, but it does not clearly warn that running billing commands may initiate a paid transaction. This is dangerous because users or agents may execute the example flow automatically and incur charges without informed consent, especially in an environment where tools are orchestrated from documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a weather skill that provides forecasts, clothing index, and feels-like temperature, but this file retrieves a secret API key from the environment to authenticate against a billing service. Although the manifest mentions SkillPay integration, credential handling is a separate payment capability not encompassed by the user-facing weather functionality described.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file implements charging and payment-link creation capabilities that are unrelated to core weather retrieval and materially expand the skill's authority to move money and solicit payments. In skill ecosystems, hidden or under-disclosed monetization logic is dangerous because users and hosts may invoke functionality expecting weather data while the code can perform billing actions against a user identifier.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The charge request sends user identifiers and payment metadata to a third-party billing API, but the code contains no visible disclosure, consent, or minimization controls around that transfer. In the context of a weather skill, transmitting financial and identity-linked data to an external payment processor is more sensitive than the skill's core function suggests, increasing privacy and trust risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI defaults to the charge path, so invoking the script with only a user ID can immediately attempt a bill without an explicit --charge acknowledgment or confirmation step. Defaulting to a financial side effect increases the risk of accidental or scripted unauthorized charges, especially in automated agent/tooling environments where arguments may be assembled implicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill embeds user-facing labels, clothing descriptions, tips, and formatted output entirely in Chinese across the recommendation data and output formatter. Because the file does not offer user language selection or state that it is intentionally limited to Chinese-speaking users, it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The formatted forecast output is hardcoded in Chinese (for example, '天预报', '体感', '湿度', and '风速') with no option to select another language. This is a natural-language policy concern because it imposes a specific locale without user opt-in or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill provides current weather, multi-day forecasts, clothing index, and dressing recommendations. This file only requests wttr.in with format=j1, reads current_condition, and returns current conditions plus a locally computed comfort level; it does not extract forecast days or implement a clothing index/recommendation feature.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains multiple hard-coded Chinese strings in returned labels and formatted output, such as comfort levels and weather field labels. Because the skill does not offer a language selection or document that it is intentionally Chinese-only, it violates the language/locale policy requirement for user opt-in or justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The reference content is entirely presented in Chinese, including headings, table labels, and guidance text, with no indication that the skill is China-specific or that users can opt into this locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends the user-supplied city name to wttr.in, a third-party service, without any in-code disclosure, consent prompt, or privacy notice. While the data sent is limited, location queries can still reveal sensitive user interests or whereabouts, and the skill context makes this relevant because all weather lookups inherently require transmitting user input off-platform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.