Back to skill

Security audit

lsl-test-skill1

Security checks for vulnerabilities and agentic risk

Overview

This weather skill is simple and not deceptive, but it tells the agent to build and run a shell curl command from user-provided city text without validation or URL encoding.

Install only if you are comfortable with the agent making a network weather request. Avoid passing city names containing quotes, shell metacharacters, newlines, or URL delimiters, and prefer using a safer implementation that URL-encodes the city and does not invoke curl through a shell.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:11
Finding

Shell Command Injection Through an Unvalidated City Name

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11-21
Vulnerability Type: User-controlled shell command construction
Risk Level: High

Vulnerable Code

text
## 输入
- 城市名(优先英文,如 Shanghai、Beijing)
- 若用户输入中文城市名,可先尝试查询;失败时提示改英文

## 使用方法
调用 out.in API:

curl "out.in/城市名?id=3"

示例:
curl "wttr.in/Shanghai?id=3"

Technical Analysis

The skill instructs an agent to insert a user-provided city name into a shell command without defining input validation, shell-safe argument handling, or URL encoding. Although the URL is enclosed in double quotes, an attacker can supply a city value containing a double quote followed by shell control characters. If an agent performs direct textual substitution and executes the resulting command through a shell, the attacker can terminate the quoted URL and append an arbitrary command.

The endpoint is also inconsistent: the command template uses out.in, while the example uses wttr.in. Neither command specifies HTTPS explicitly. This inconsistency can cause requests to be sent to an unintended service, while omission of an explicit secure scheme can permit insecure transport depending on client and server behavior.

Attack Path

  1. An attacker submits a crafted city name containing a closing quotation mark, a shell separator, and an operating-system command.
  2. The agent substitutes that value directly into the documented curl command.
  3. The agent invokes the generated text through a shell.
  4. The shell interprets the injected separator and executes the appended command independently of curl.
  5. The injected command runs with the same operating-system privileges, filesystem access, network access, and environment access as the agent process.

For example, a malicious city value shaped like " ; [attacker-command] ; # would transform the intended URL argument into multiple shell operations if inserted without validation.

Impact Assessment

...[truncated 729 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace shell-based URL construction with a structured HTTP client that treats the city name strictly as data.
  2. If curl is required, pass the value as a separately encoded parameter, such as with curl --get --data-urlencode, rather than interpolating it into a command string.
  3. Never invoke the generated request through a shell. Use an argument-array execution interface where the executable and each argument are supplied separately.
  4. Validate city names against a restrictive policy appropriate to supported locations. Reject quotation marks, shell metacharacters, control characters, URL delimiters, and unexpected input lengths.
  5. Normalize and URL-encode accepted Unicode city names before constructing the request.
  6. Correct the endpoint inconsistency and use one explicitly approved HTTPS URL, such as https://wttr.in/, with redirects and destination hosts restricted where possible.
  7. Run the request operation with minimal filesystem, environment, and network privileges to reduce impact if input handling fails.
  8. Add tests covering quotation marks, semicolons, command substitutions, newlines, ampersands, pipes, and other shell-sensitive input.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly requires the output language to be Chinese via '使用中文'. This is a natural-language locale policy constraint, and the file does not offer user opt-in or explain that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.