Back to skill

Security audit

Get My Location

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent IP-location skill, but it sends IP/location lookups to outside services and can fall back to unencrypted HTTP without clear user confirmation.

Review before installing if IP/location privacy matters in your environment. The skill should ideally add a clear privacy notice or confirmation step, restrict lookups to HTTPS providers, and remove the plaintext ip-api.com fallback.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/location.py:89
Finding

Plaintext HTTP Transport for Geolocation Lookup

Content
View full analysis

Vulnerability Details

File Location: scripts/location.py, line 89
Vulnerability Type: Plaintext transmission of geolocation queries and responses
Risk Level: Medium

Vulnerable Code

python
url = "http://ip-api.com/json/" if ip is None else f"http://ip-api.com/json/{quote(ip)}"

Technical Analysis

The third geolocation fallback communicates with ip-api.com over unencrypted HTTP. Unlike the first two providers, this connection provides neither transport confidentiality nor reliable server authentication and response integrity.

A network-positioned attacker can observe queried IP addresses or modify the JSON response in transit. The application accepts a response when its status field equals "success", normalizes its values, and subsequently prints the provider-controlled location fields without integrity verification.

Attack Path

  1. The first two HTTPS providers fail, are unavailable, or return unusable results.
  2. The application invokes the third fallback through plaintext HTTP.
  3. An attacker with a suitable network position intercepts the HTTP request.
  4. The attacker returns modified JSON containing "status": "success" and attacker-selected location values.
  5. The application trusts, normalizes, and displays the forged country, region, city, coordinates, postal code, and timezone.

Impact Assessment

The issue does not grant local code execution, additional operating-system privileges, or persistent access. Its scope is limited to the third fallback's network traffic and resulting output.

An attacker can learn the explicitly queried IP address and manipulate geolocation results. Forged values may mislead users or downstream processes that consume JSON output. Provider-controlled strings also reach terminal output, although no concrete terminal escape exploit was established during this audit.

Remediation
View remediation

Remediation Suggestions

  • Replace the plaintext endpoint with an HTTPS-capable geolocation API.
  • If the provider cannot support HTTPS, remove this fallback rather than downgrading transport security.
  • Require HTTPS for every outbound provider request and reject redirects that downgrade from HTTPS to HTTP.
  • Validate the response schema and expected data types before using returned fields.
  • Apply length limits and strip control characters from externally supplied strings before rendering human-readable terminal output.
  • Add tests confirming that every configured provider URL uses HTTPS and that transport downgrades are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly describes network-backed geolocation behavior but does not declare any tool scope or permissions to reflect that capability. This creates a transparency and governance gap: users and hosting platforms may not realize the skill makes outbound requests to third-party services, which can expose IP-related data and bypass expected policy controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger patterns include broad everyday phrases such as 'where am i' and 'my location', which can cause the skill to activate in contexts where the user did not intend third-party IP geolocation lookups. Because the skill sends location queries externally, accidental invocation can lead to unnecessary disclosure of sensitive location-related data and confusing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documentation explains multi-source fallback to external geolocation APIs but does not clearly warn users that their public IP, or a supplied IP address, will be sent to third-party services. In a location-focused skill, this omission is more serious because the core function inherently handles privacy-sensitive data and may reveal approximate location to external providers without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill transmits the user's current public IP or a supplied IP address to multiple third-party geolocation services as part of its core functionality, but it provides no explicit consent prompt or user-facing notice that this data will be sent externally. IP addresses are personal data in many contexts, and the multi-source fallback increases the number of external disclosures if earlier providers fail.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code explicitly sends data to an external geolocation API, which creates a privacy and data-sharing risk because the user's IP or queried IP is disclosed to a third party. In a location skill this is contextually expected, but it is still security-relevant because users may not realize their network-identifying data is being shared off-box.

Content

Scanner excerpt · scripts/location.py (reported line 73)May include surrounding context.

python
# ── Source 2: api.ipbase.com ──

def try_ipbase(ip=None):
    url = "https://api.ipbase.com/v1/json/" if ip is None else f"https://api.ipbase.com/v1/json/{ip}"
    def _do():
        raw = http_get(url)
        data = json.loads(raw)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function emits all user-facing output strings in Chinese, such as the location header and field labels, regardless of user preference or environment. This is a natural-language policy issue because the skill imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The human-readable output example is presented entirely in Chinese, while the skill description otherwise uses English and does not state that output language is fixed or user-selectable. This suggests a locale-specific behavior without explicit user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.