Back to skill

Security audit

Discord Weather Reporter

Security checks for vulnerabilities and agentic risk

Overview

This weather skill is simple and purpose-aligned, but its documented shell commands interpolate user-controlled locations into curl commands without validation or encoding.

Review before installing. This skill should only be used if the agent validates or URL-encodes locations and invokes HTTP requests without shell interpolation. Avoid sending sensitive or precise private locations unless you are comfortable sharing them with wttr.in.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Potential Shell Command Injection Through Unsanitized City Input

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–22
Vulnerability Type: Shell command injection caused by unsafe interpolation of user-controlled input
Risk Level: Medium

Vulnerable Code

bash
# Current weather for a city (one-liner)
curl -s "wttr.in/{city}?format=%l:+%c+%t+(feels+like+%f),+%w+wind,+%h+humidity"

# 3-day forecast
curl -s "wttr.in/{city}?format=v2"

# Will it rain?
curl -s "wttr.in/{city}?format=%l:+%c+%p"

The same unsafe interpolation pattern is repeated in SKILL.md at lines 29–44.

Technical Analysis

The {city} placeholder represents location data originating from a user's weather request. The skill directs the agent to insert this value into shell commands but does not require input validation, URL encoding, or execution through a shell-free HTTP API.

Quoting the URL does not make arbitrary input safe if an agent performs direct textual substitution before passing the command to a shell. A malicious value containing a closing quotation mark and shell control syntax could terminate the URL argument and introduce an additional command. Command substitutions can also remain active inside double-quoted shell strings.

For example, a crafted location structurally equivalent to:

text
"; attacker_command; #

could transform the generated instruction into separate shell commands if substituted literally. Exploitability depends on the invoking agent constructing and executing the documented command through a shell rather than using a structured HTTP client.

Attack Path

  1. An attacker submits a weather request containing a location with shell metacharacters.
  2. The agent extracts the attacker-controlled location as the {city} value.
  3. The agent directly replaces {city} in one of the documented curl command strings.
  4. The generated command is passed to a shell without validation or safe argument handling.
  5. The shell interprets the ...[truncated 753 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell command strings by interpolating user-controlled location values.
  2. Use a structured HTTP client that sends the destination URL without invoking a command shell.
  3. If curl must be launched, invoke it through a process API with an explicit argument array and with shell execution disabled.
  4. URL-encode the location as a path component before constructing the request URL.
  5. Validate location input using a conservative allowlist appropriate for city names and airport codes. Reject control characters, quotation marks, backticks, dollar signs, command delimiters, newlines, and other shell metacharacters.
  6. Use an explicit HTTPS endpoint, such as https://wttr.in/, rather than relying on implicit protocol behavior.
  7. Add a warning to the skill instructions stating that {city} must never be substituted directly into a shell command.
  8. Apply runtime restrictions to the agent process, including minimal filesystem permissions, limited environment exposure, and constrained outbound network access, to reduce the impact of any command-execution flaw.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list is broad and conversational enough to overlap with common user speech, increasing the chance the skill activates when the user did not explicitly intend to invoke it. In practice, this can cause unintended external requests containing location queries and can route general conversation into this skill unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill examples and usage notes instruct sending city or airport-code queries to wttr.in without clearly warning users that their location-related input is transmitted to a third-party service. While the data is not highly sensitive in most cases, undisclosed external sharing can create privacy and compliance issues, especially for precise locations, travel plans, or enterprise usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.