Back to skill

Security audit

Gas Price Alert

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real gas-station search skill, but it overstates its coverage and alert features and sends location searches over an unencrypted external request.

Review this before installing if you care about location privacy or accurate non-Columbus results. Treat prices as estimates, avoid scheduled alerts unless you are comfortable sharing the same location query repeatedly, and prefer fixing the Overpass endpoint to HTTPS plus the Columbus-specific distance and summary logic before relying on it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gas_alternative.py:75
Finding

Location Data Transmitted Through Unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/gas_alternative.py:75
Vulnerability Type: Plaintext transmission of location data and unauthenticated API responses
Risk Level: Medium

Vulnerable Code

python
overpass_url = "http://overpass-api.de/api/interpreter"

The endpoint is subsequently used at scripts/gas_alternative.py:99:

python
response = requests.post(overpass_url, data=query, headers=headers, timeout=30)

Technical Analysis

The Overpass query contains the latitude, longitude, and calculated geographic bounding box supplied for the gas-station search. Because the endpoint uses plaintext HTTP, neither the confidentiality nor the integrity of the request and response is protected by TLS.

An attacker with a network-level interception position could observe the approximate location being searched. The attacker could also modify the returned JSON data, including station names, coordinates, brands, and addresses. The application accepts the response, processes its elements collection, and writes the resulting records to the configured output file without authenticating the server response.

Attack Path

  1. A user invokes the script with a ZIP code or geographic coordinates.
  2. The script constructs an Overpass query containing a bounding box around that location.
  3. The query is sent over plaintext HTTP.
  4. An attacker controlling or monitoring an intermediate network observes the requested location.
  5. The attacker may replace the response with valid-looking, attacker-controlled JSON.
  6. The forged station information is processed, displayed in the summary, and saved to the output file.

Impact Assessment

Exploitation does not directly grant local system privileges or arbitrary code execution. It can expose a user's approximate searched location and compromise the integrity of gas-station recommendations. A successful active interception could misdirect the us ...[truncated 182 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the endpoint with its HTTPS equivalent:

    python
    overpass_url = "https://overpass-api.de/api/interpreter"
    
  • Keep TLS certificate verification enabled; do not use verify=False.

  • Validate that the response has an expected JSON content type before parsing it.

  • Validate response structure and enforce reasonable limits on the number and types of returned records.

  • Reject malformed coordinates and records containing unexpected field types.

  • Consider using a trusted, configurable list of HTTPS Overpass endpoints with controlled failover behavior.

T08 · Insecure Dependencies

Note
Location
README.md:52
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:52
Vulnerability Type: Unpinned dependency and supply-chain exposure
Risk Level: Low

Vulnerable Code

bash
pip install requests geopy

Similar unpinned installation instructions appear in SKILL.md:206-216, including:

bash
pip install requests geopy

and:

bash
pip install playwright
playwright install

Technical Analysis

The project does not provide a version-pinned dependency manifest, lock file, or package hashes. Following the documented commands therefore installs whichever package versions the configured package index resolves at installation time. The optional Playwright setup also downloads browser components without a project-controlled artifact version or integrity policy.

This makes the effective dependency set mutable after the skill has been audited. A compromised package release, package-index account, mirror, or future incompatible release could introduce unexpected behavior into the installation or runtime environment. No evidence was found that the currently named packages are malicious; the issue is the absence of reproducible and integrity-verified dependency resolution.

Attack Path

  1. A user follows the documented installation instructions.
  2. pip resolves the latest available versions from the user's configured package index.
  3. If an upstream release, maintainer account, index, or mirror is compromised, a modified package may be selected.
  4. The package is installed into the user's Python environment.
  5. Malicious dependency code could execute during package use with the same operating-system permissions as the user running the skill.
  6. For the optional browser setup, unpinned Playwright tooling may additionally retrieve mutable browser artifacts.

Impact Assessment

The project itself does not obtain elevated privileges. If the supply chain were compromised, dependency code w ...[truncated 324 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a reviewed dependency manifest with exact versions, for example:

    text
    requests==<reviewed-version>
    geopy==<reviewed-version>
    playwright==<reviewed-version>
    
  • Generate and commit a lock file containing cryptographic hashes.

  • Install dependencies using hash enforcement, such as pip install --require-hashes.

  • Document installation inside a dedicated virtual environment rather than a system-wide Python environment.

  • Regularly scan pinned dependencies for known vulnerabilities and update them through reviewed changes.

  • Pin and verify Playwright browser artifacts where supported.

  • Advise users not to run package installation with administrator or root privileges.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The description overstates the skill. The code does perform a gas-station search with configurable radius, fuel type, ZIP/city/state inputs, and includes Costco-focused handling, so there is partial alignment. However, several core claims are not implemented: there is no mechanism for daily notifications, alerts, or ongoing monitoring; most stations have no actual prices because the script only queries OSM locations and sets price to 0/'N/A'; Costco prices are estimated rather than fetched; and Costco support is not generic nationwide because the Costco station list is hardcoded for Columbus, Ohio. Additionally, parts of the logic and output remain Columbus-specific, which conflicts with 'supports any US location.'

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code’s core behavior partially matches the 'find gas prices' part of the description: it retrieves nearby station price data for a given fuel type and outputs cheapest results. However, significant declared capabilities are missing. There is no scheduling, persistence for repeated checks, notification mechanism, or alerting logic, so 'monitor' and 'daily notifications' are unsupported. The code does not identify or prioritize Costco/discount stations. Although a radius argument exists, it is not meaningfully applied to the GasBuddy query or filtering. The implementation is therefore materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The station filter uses distance from downtown Columbus rather than the user-requested origin, so users can receive materially incorrect results while believing they are location-specific. In this skill context, that can misdirect travel decisions and produce deceptive outputs, especially because the skill advertises support for arbitrary US locations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents network access and file output behavior but does not declare any explicit tool scope or permissions boundaries. This creates a governance and least-privilege problem: an agent may be allowed to make external requests or write files without transparent user-facing restriction, increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to send location-based gas searches to external services and mentions Telegram notifications, but it does not clearly disclose that sensitive location/query data may be transmitted to third parties. Repeated scheduled use can create a persistent record of a user's location patterns, which raises privacy and data-sharing risks even if the functionality is otherwise legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code sends ZIP/city/state or latitude/longitude-derived query data to external services via Nominatim geocoding and the Overpass API. While there are runtime status prints, the user-facing description only says it uses free APIs and public data sources and does not clearly warn that supplied location information will be transmitted off-system.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill supports any US location, but the code anchors distance calculations to a fixed Columbus coordinate and later generates summaries labeled specifically for Columbus, OH. This means results can be inaccurate or misleading for non-Columbus searches, so the implemented behavior does not match the claimed geographic scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Always labeling summaries as 'Columbus, OH' can misrepresent where the results apply, which is a data-integrity issue. In a location-based consumer skill, misleading geographic context can cause users to act on incorrect information, though the security impact remains limited.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The docstring suggests API-backed availability in general terms, but the implementation is strictly a fixed list of three Columbus-area Costco stations. This creates an intent mismatch because the comment implies broader location support than the code actually provides.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script writes JSON results to a user-specified path, which affects local filesystem state. Although it prints after saving, there is no prior warning, confirmation, or note in the description/help that running the script will create or overwrite the output file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The request headers hard-code Accept-Language: en-US,en;q=0.9, which imposes a specific language/locale preference. This is a natural-language policy concern because the file does not offer user opt-in or explain why an English-US locale is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.