Back to skill

Security audit

weather

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward weather lookup skill; it uses external weather APIs and has some disclosure and accuracy caveats, but I found no hidden, destructive, persistent, or credential-stealing behavior.

Install only if you are comfortable sending weather query locations to Open-Meteo. Provide an explicit city when using it, and avoid following the generic pip install guidance in sensitive environments unless dependencies are pinned or installed through your normal trusted package process.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
scripts/weather.py:12
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码的核心功能与声明的大方向一致:它是一个天气查询工具,会根据城市名获取坐标并查询当前天气,默认查询北京。这部分没有发现越权行为或与天气无关的隐藏能力。问题在于声明的能力范围明显强于实际实现。代码没有实现中文转拼音、拼音归一化或多语言输入增强,只是在地理编码失败时打印“可尝试使用拼音/英文名称”的提示,因此“支持拼音输入”不准确。对于“全球任何城市”,虽然调用了全球地理编码 API,理论上可覆盖很多城市,但代码对国际城市主要依赖英文名,且注释中也写明“国际城市请使用英文名称”,与声明中“支持中文、英文、拼音输入,自动匹配最佳位置”的广泛承诺不完全一致。因此应判定为描述与实际行为存在一定失配,属于能力被夸大而非存在额外未声明恶意功能。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script performs outbound HTTP requests to Open-Meteo geocoding and weather APIs via the requests library, but the static finding indicates this network capability is not declared in the skill permissions. Undeclared network access is a real security and governance issue because it transmits user-supplied location queries to third parties and prevents proper review of external data flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is broad enough that ordinary conversation about weather or temperature may invoke the skill unexpectedly. In an agent environment, overbroad activation can cause unintended tool execution, unnecessary external requests, and routing of user input into a shell-backed workflow when the user did not clearly request that action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring defines the tool entirely in Chinese, and the rest of the skill consistently emits Chinese-only user-facing text. The file does not offer a language choice or explain that it is intentionally limited to a Chinese-speaking context, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script sends user-derived inputs and resolved coordinates to external services at api.open-meteo.com and the geocoding endpoint, which is an external transmission of potentially sensitive location intent. In this skill context, external transmission is expected for weather retrieval, but it still matters because users may not realize their queried locations are shared with third-party services.

Content

Scanner excerpt · scripts/weather.py (reported line 272)May include surrounding context.

python
print(f"找到位置:{geocode_result['name']}, {geocode_result.get('admin1', '')}, {geocode_result.get('country', '')}")

    # 构建API请求URL
    url = f"https://api.open-meteo.com/v1/forecast"
    params = {
        "latitude": city["latitude"],
        "longitude": city["longitude"],

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

Defaulting to Beijing without user opt-in can cause the agent to act on unstated assumptions and return location-specific information the user did not request. While the direct security impact is limited, it can leak agent behavior patterns, reduce user control, and produce misleading outputs in context-sensitive workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.