T09 · Insecure Skill Coding Practices
- Location
search.sh:18- Finding
JSON Request Injection Through an Unescaped Station Search Query
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Austrian public-transport lookup tool, with limited input-handling weaknesses but no evidence of hidden, persistent, destructive, or data-stealing behavior.
Suitable to install for personal transit lookups. Prefer normal station IDs and small numeric counts, and do not expose these scripts directly to untrusted web or chat inputs without adding input validation, JSON-safe request construction, request timeouts, and result limits.
search.sh:18JSON Request Injection Through an Unescaped Station Search Query
departures.sh:29JSON and jq Expression Injection Through Departure Arguments
route.sh:25JSON and jq Expression Injection Through Route Arguments
disruptions.sh:9Unvalidated Disruption Result Limit Allows JSON Injection and Resource Abuse
No suspicious patterns detected.