Back to skill

Security audit

cn-weather

Security checks for vulnerabilities and agentic risk

Overview

This weather skill does what it says, but its shell-based examples can be unsafe if a city name is inserted directly into the command.

Review this skill before installing. It is narrowly useful for Chinese mainland weather, but agents should only invoke it when the user explicitly asks for current weather or forecasts. Prefer a structured HTTP client or safely serialized JSON body instead of direct shell interpolation, and validate city names and returned station IDs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:18
Finding

Shell Command Injection Through Unsafe City-Name Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–21
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code

bash
curl --location 'https://data.cma.cn/kbweb/home/getStationID' \
  --header 'Content-Type: application/json' \
  --data '{"city":"<城市名>"}'

Technical Analysis

The skill directs the agent to replace the city-name placeholder with user-controlled input inside a single-quoted shell argument. It does not require validation, safe JSON serialization, or shell-safe parameter handling.

A city name containing a single quote can terminate the --data argument. Subsequent shell metacharacters can then introduce additional commands. JSON escaping alone would not prevent this issue because the vulnerable interpretation occurs in the command shell before the request is sent.

The vulnerability is exploitable when an agent follows the documented workflow by constructing and executing the displayed Bash command through a shell using literal placeholder substitution.

Attack Path

  1. An attacker submits a crafted value as the requested city name.
  2. The value contains a single quote that terminates the shell argument, followed by shell syntax and an attacker-selected command.
  3. The agent substitutes the value directly for the placeholder in the documented command.
  4. The agent executes the resulting command through a shell.
  5. The shell interprets the injected syntax as a separate local command rather than as part of the HTTP request body.
  6. The injected command runs with the operating-system privileges and environmental access of the agent process.

A conceptual malicious city value could take the following form:

text
x"}' ; attacker-controlled-command ; #

Impact Assessment

Successful exploitation can provide arbitrary command execution under the account running the agent. The resulting scope depends on that account's privileges and sandbox restrictions. Potential consequences ...[truncated 582 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not construct shell command text by substituting untrusted city names into the displayed command.
  • Prefer a structured HTTP client or tool that accepts the URL, headers, and JSON body as separate typed parameters without invoking a shell.
  • If Bash is unavoidable, store the city name in a quoted variable and use a JSON serializer such as jq:
bash
CITY="$USER_SUPPLIED_CITY"
BODY="$(jq -n --arg city "$CITY" '{city: $city}')"

curl --location 'https://data.cma.cn/kbweb/home/getStationID' \
  --header 'Content-Type: application/json' \
  --data "$BODY"
  • Pass commands as argument arrays where supported and disable shell interpretation.
  • Validate that the city name conforms to an appropriate length and character policy. Validation should be defense in depth and must not replace safe argument handling.
  • Explicitly instruct the agent never to interpret city names as command syntax and never to use eval, command substitution, or string-built shell commands.
  • Treat API responses as untrusted data and validate the returned station identifier against the expected identifier format before using it in the second request URL.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is very broad and instructs the agent to use this skill whenever weather is mentioned, including casual discussion or clothing/travel advice. Over-broad triggering can cause unnecessary external requests and unintended disclosure of user-provided location context to third-party services, even when the user did not clearly ask for live weather lookup.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill sends user-supplied city data to an external CMA endpoint, which is a real external data transmission. In context this is expected functionality, but it still creates privacy and data-governance risk because user queries and inferred location interest are disclosed to a third party whenever the skill runs.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

调用站点查询接口,将城市名转为气象站点 ID:

bash
curl --location 'https://data.cma.cn/kbweb/home/getStationID' \
  --header 'Content-Type: application/json' \
  --data '{"city":"<城市名>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill sends user-supplied city data to an external CMA endpoint, which is a real external data transmission. In context this is expected functionality, but it still creates privacy and data-governance risk because user queries and inferred location interest are disclosed to a third party whenever the skill runs.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

调用站点查询接口,将城市名转为气象站点 ID:

bash
curl --location 'https://data.cma.cn/kbweb/home/getStationID' \
  --header 'Content-Type: application/json' \
  --data '{"city":"<城市名>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

示例请求:

bash
curl --location 'https://data.cma.cn/kbweb/home/getStationID' \
  --header 'Content-Type: application/json' \
  --data '{"city":"张家港"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The note states that city names should use Chinese full names, which imposes a language constraint in the skill instructions. The file does not offer an opt-in, fallback, or alternative for users who provide city names in another language or script.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.