T09 · Insecure Skill Coding Practices
- Location
scripts/gas_alternative.py:75- Finding
Location Queries and Station Results Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a gas-station lookup helper, but it substantially overstates its monitoring and nationwide Costco/price capabilities and sends location queries over plaintext HTTP.
Review this before installing if you need accurate prices or non-Columbus coverage. Treat results as estimates, avoid enabling daily alerts unless you are comfortable with recurring external location lookups, and prefer updating the Overpass endpoint to HTTPS and pinning dependencies before use.
scripts/gas_alternative.py:75Location Queries and Station Results Transmitted over Plaintext HTTP
SKILL.md:206Unpinned Third-Party Packages and Browser Components Installed from Mutable Sources
The description overstates the skill's capabilities. The code can search for gas station locations within a radius and produce a local summary, but it does not obtain real-time gas prices except for fabricated Costco estimates based on a user-supplied base price. It also lacks any persistent monitoring, daily execution, or notification mechanism. Although it accepts city/state/ZIP/lat/lon inputs, the implementation is not truly location-agnostic because several behaviors are Columbus-specific: a hardcoded downtown Columbus reference is used for distance filtering in the main OSM search, the summary header always says Columbus, OH, and Costco stations are drawn from a fixed Columbus-area list. This is a material mismatch between declared purpose and actual behavior.
The core declared purpose suggests both search and ongoing monitoring with daily gas price notifications. The supplied code only performs a single on-demand GasBuddy search/scrape and outputs current station data to JSON plus a cheapest list. There is no scheduler, persistence for historical tracking, alerting mechanism, email/SMS/push integration, or trigger logic. The description also mentions tracking Costco and other discount stations, but the code does not identify or filter those brands. While the code does support configurable fuel type and takes coordinates plus a radius argument, the radius is not actually used in constructing the query or filtering results. Therefore the description materially overstates the implemented behavior.
The manifest says the skill supports any US location, but core logic uses a fixed Columbus reference point and Columbus-specific summary text. In search_gas_stations, distances are computed from DOWNTOWN_COLUMBUS rather than the user-supplied coordinates, and generate_summary always labels results as 'Columbus, OH', causing incorrect behavior outside Columbus.
The manifest advertises tracking Costco and other discount fuel stations for any US location, but search_costco_locations only checks a static list of known Columbus-area Costco stations. For users searching other cities or states, the Costco capability is not actually implemented as described.
The skill documents network access and file output behavior but does not declare any explicit tool scope or permissions boundary. In an agent environment, undeclared capabilities increase the risk of overbroad execution, unexpected outbound requests, or writes to local storage without clear user consent or platform enforcement.
The docstring says the function searches for gas stations using Overpass API, implying results are filtered around the supplied coordinates. However, the implementation later measures distance from downtown Columbus and filters by that fixed point, which contradicts the documented behavior for arbitrary search locations.
The script sends location-based queries to the Overpass API over plain HTTP, exposing user search coordinates and query contents to interception or modification by a network attacker. Because the response is trusted and parsed as station data, an attacker on the network path could tamper with results, causing misinformation and loss of privacy.
The function signature and docstring imply authenticated API use is supported, but the code ignores the provided api_key and always performs browser-like unauthenticated web scraping against the public site. This mismatch can mislead operators into believing they are using an authorized access path when the skill is actually bypassing intended access controls or terms, increasing legal, operational, and blocking risk in an automation context.
The README instructs users to configure daily alerts that invoke the script on a cron schedule, but it does not clearly warn that each scheduled run will perform outbound geocoding and OpenStreetMap/Overpass network requests. This can lead to unintended recurring traffic, rate-limit issues, or unexpected privacy/operational impact for users who enable automation without understanding the external dependency behavior.
The skill encourages scheduled daily notifications and Telegram delivery without clearly warning users that it will create recurring outbound communications and may share location-derived data with external services. This can lead to privacy surprises, unintended persistence of alerts, or disclosure of sensitive routine/location information through third-party channels.
The request headers hard-code Accept-Language: en-US,en;q=0.9, which imposes a specific language/locale preference. This is a natural-language policy concern because the file does not offer user opt-in or explain why a US English locale is required.
The manifest describes finding and monitoring gas prices with notifications, but this file also persists retrieved station data to an arbitrary local output path. Local file writing is an additional behavior beyond simple searching/monitoring, and the manifest does not mention storing results on disk.
No suspicious patterns detected.