Back to skill

Security audit

A nach B - AT Public Transport Service (VOR)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Austrian public-transport lookup tool, with limited input-handling weaknesses but no evidence of hidden, persistent, destructive, or data-stealing behavior.

Suitable to install for personal transit lookups. Prefer normal station IDs and small numeric counts, and do not expose these scripts directly to untrusted web or chat inputs without adding input validation, JSON-safe request construction, request timeouts, and result limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Note
Location
search.sh:18
Finding

JSON Request Injection Through an Unescaped Station Search Query

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
departures.sh:29
Finding

JSON and jq Expression Injection Through Departure Arguments

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi if [[ ! "$COUNT" =~ ^[0-9]+$ ]] || (( COUNT < 1 || COUNT > 100 )); then printf 'Count must be an integer from 1 to 100\n' >&2 exit 2 fi ``` Build JSON with typed jq arguments: ```bash payload="$( jq -n \ --arg station_id "$STATION_ID" \ --argjson count "$COUNT" \ '{ svcReqL: [{ req: { stbLoc: {extId: $station_id, type: "S"}, type: "DEP", maxJny: $count }, meth: "StationBoard", id: "1|2|" }], client: {id: "VAO", v: "1", type: "AND", name: "nextgen"}, ver: "1.73", lang: "de", auth: {aid: "nextgen", type: "AID"} }' )" ``` Pass the count as data to the output filter rather than inserting it into jq source: ```bash jq --argjson count "$COUNT" ' .svcResL[0].res as $res | { departures: [ ($res.jnyL // [])[:$count] | .[] ] } ' ``` Also set request timeouts and fail on HTTP errors: ```bash curl --fail-with-body --show-error --silent \ --connect-timeout 10 --max-time 30 ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
route.sh:25
Finding

JSON and jq Expression Injection Through Route Arguments

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi if [[ ! "$COUNT" =~ ^[0-9]+$ ]] || (( COUNT < 1 || COUNT > 20 )); then printf 'Results must be an integer from 1 to 20\n' >&2 exit 2 fi ``` Use `jq -n` with `--arg` and `--argjson` to create the request: ```bash payload="$( jq -n \ --arg from_id "$FROM_ID" \ --arg to_id "$TO_ID" \ --argjson count "$COUNT" \ '{ svcReqL: [{ req: { depLocL: [{extId: $from_id, type: "S"}], arrLocL: [{extId: $to_id, type: "S"}], getPasslist: false, maxChg: 5, numF: $count }, meth: "TripSearch", id: "1|3|" }], client: {id: "VAO", v: "1", type: "AND", name: "nextgen"}, ver: "1.73", lang: "de", auth: {aid: "nextgen", type: "AID"} }' )" ``` Pass the value to jq as data: ```bash jq --argjson count "$COUNT" ' .svcResL[0].res as $res | { trips: [ ($res.outConL // [])[:$count] | .[] ] } ' ``` If station names are intended to be supported, resolve names through a separate, safely encoded location lookup rather than treating arbitrary names as station IDs. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
disruptions.sh:9
Finding

Unvalidated Disruption Result Limit Allows JSON Injection and Resource Abuse

Content
View full analysis
Remediation
View remediation
100 )); then printf 'Maximum results must be an integer from 1 to 100\n' >&2 exit 2 fi ``` Construct the request using a typed JSON argument: ```bash payload="$( jq -n --argjson max_results "$MAX_RESULTS" '{ svcReqL: [{ req: { maxNum: $max_results, himFltrL: [ {mode: "INC", type: "HIMCAT", value: "*"} ] }, meth: "HimSearch", id: "1|4|" }], client: {id: "VAO", v: "1", type: "AND", name: "nextgen"}, ver: "1.73", lang: "de", auth: {aid: "nextgen", type: "AID"} }' )" ``` Use `--data-binary "$payload"`, enable HTTP error reporting, and configure connection and total-operation timeouts. Consider imposing a response-size limit in the calling environment where this script is exposed to untrusted users. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.