Back to skill

Security audit

weather-agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about automated real-money weather-market trading, but it deserves review because it can trade without per-trade approval and has credential-handling weaknesses.

Install only if you are comfortable granting a trading API key and allowing automated trades after manual enablement. Use a small balance, a trading-only Simmer key with no withdrawal or account-admin rights, review config.json before enabling cron, avoid --no-safeguards, and consider pinning python-dotenv and fixing authenticated redirect handling before using this with meaningful funds.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
weather_trader_enhanced.py:582
Finding

Bearer Token May Be Disclosed Through Cross-Origin HTTP Redirects in the Trading Client

Content
View full analysis
dict: url = f"{SIMMER_API_BASE}{endpoint}" headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", } try: if method == "GET": req = Request(url, headers=headers) else: body = json.dumps(data).encode() if data else None req = Request(url, data=body, headers=headers, method=method) with urlopen(req, timeout=30) as response: return json.loads(response.read().decode()) except HTTPError as e: error_body = e.read().decode() if e.fp else str(e) return {"error": f"HTTP {e.code}: {error_body}"} except Exception as e: return {"error": str(e)} ``` ### Technical Analysis The initial request destination is constructed from the fixed `https://api.simmer.markets` base URL, which appropriately limits the normal destination of the bearer token. However, `urllib.request.urlopen` automatically processes HTTP redirects through its default redirect handler. The implementation does not validate the scheme and hostname of a redirect before following it, nor does it explicitly strip the `Authorization` header when the destination origin changes. Consequently, a redirect issued by the authenticated API could cause a subsequent request containing `SIMMER_API_KEY` to be sent to another origin. This network access is necessary for the declared trading functionality, but permitting authenticated cross-origin redirects exceeds the minimum privilege needed. The client only needs to authenticate directly to `api.simmer.markets`. ### Attack Path 1. A user supplies a valid `SIMMER_API_KEY` and runs the trading program. 2. The ...[truncated 1267 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/status.py:37
Finding

Bearer Token May Be Disclosed Through Cross-Origin HTTP Redirects in the Status Utility

Content
View full analysis
dict: """Make authenticated request to Simmer API.""" url = f"{SIMMER_API_BASE}{endpoint}" req = Request(url, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" }) try: with urlopen(req, timeout=30) as resp: return json.loads(resp.read().decode()) except HTTPError as e: error_body = e.read().decode() if e.fp else "" print(f" API Error {e.code}: {error_body}") sys.exit(1) except URLError as e: print(f" Connection error: {e.reason}") sys.exit(1) ``` ### Technical Analysis The status utility sends `SIMMER_API_KEY` as a bearer token to a fixed Simmer API URL. Sending this credential is necessary to obtain the requested account and position information. The request nevertheless uses the default `urllib.request.urlopen` redirect behavior without validating the final destination. The code neither restricts redirects to the original origin nor explicitly removes the authorization header on cross-origin redirects. This creates a potential credential-disclosure path if the trusted endpoint returns a redirect to another host. The utility requires only direct read access to Simmer. Allowing the credential to accompany an unvalidated redirect is not required for its declared functionality. ### Attack Path 1. The user runs `python scripts/status.py` with a valid `SIMMER_API_KEY`. 2. The utility requests `/api/sdk/portfolio` or `/api/sdk/positions`. 3. A compromised API response path returns a redirect to an attacker-controlled URL. 4. The default redirect handler follows that URL without a same-origin policy enforced by the application. 5. The bearer token may be included in the ...[truncated 940 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Security-Sensitive Dependency Uses an Open-Ended Version Constraint Without Integrity Pinning

Content
View full analysis
=1.0.0 ``` ### Technical Analysis The requirement accepts every future `python-dotenv` release at or above version 1.0.0. It does not pin an audited version or provide a package hash. Therefore, installations performed at different times may execute different third-party code despite using an unchanged Skill package. This dependency is imported during program startup and processes the local `.env` file containing `SIMMER_API_KEY`. It consequently runs in a security-sensitive context with access to the process environment and trading credential. No malicious dependency, typosquatted package, or current compromise was identified in the reviewed files. The issue is the avoidable future supply-chain exposure and lack of reproducibility. ### Attack Path 1. A user installs the project dependencies from the open-ended requirements file. 2. The package resolver selects a newer release that was not reviewed with this Skill. 3. The trading or status program imports `dotenv` during startup. 4. If the selected release or distribution channel has been compromised, its initialization code runs with the user’s local privileges. 5. Malicious package code can access `.env`, environment variables, local files available to the process, and the network. 6. The package could steal `SIMMER_API_KEY`, alter configuration loading, or interfere with trading behavior. This is a conditional supply-chain path; the audit found no evidence that the named dependency is presently malicious. ### Impact Assessment A compromised dependency would execute with the same operating-system permissions as the Skill. Potential scope includes: - Reading `SIMMER_API_ ...[truncated 437 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The static finding indicates a major mismatch between the stated purpose and the observed behavior: the skill claims NOAA/Polymarket weather trading logic, but the code reportedly does not perform those actions and instead accesses Simmer account/portfolio resources. Behavior-description mismatch is dangerous because it can mislead users into granting credentials and enabling automation under false assumptions, masking unintended or unauthorized account actions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
1. Edit `SKILL.md` line 5 (the metadata line)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 342)May include surrounding context.

md
- [ ] Understand autonomous trading risks
- [ ] Know max daily deployment (~$30-60, max $100)
- [ ] Comfortable with no per-trade approval
- [ ] Know how to stop (disable in OpenClaw or edit SKILL.md)
- [ ] Started with small balance ($50-100)

### Platform Behavior

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 360)May include surrounding context.

bash
# Option 1: Disable in OpenClaw UI

# Option 2: Edit SKILL.md
# Change line 5: "autostart":false
# Then: openclaw restart

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 292)May include surrounding context.

md
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/status.py (reported line 25)May include surrounding context.

python
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · weather_trader_enhanced.py (reported line 40)May include surrounding context.

python
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · requirements.txt (reported line 8)May include surrounding context.

text
# Optional: tradejournal for logging trade details
# NOT INSTALLED BY DEFAULT - Only install if you want trade logging
# WARNING: If installing, inspect tradejournal source code first to verify
# it doesn't send data to external services
# tradejournal  # Uncomment to enable (inspect source first!)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's functionality is materially different from the declared skill purpose: instead of NOAA-based weather-market analysis/trading safeguards, it accesses Simmer account portfolio and positions. This kind of scope mismatch is dangerous because users may grant or place trust in a skill under one description while it actually interacts with a third-party trading account and reveals financial account data.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/status.py (reported line 28)May include surrounding context.

python
# Load .env file if it exists
try:
    from dotenv import load_dotenv
    env_path = Path(__file__).parent.parent / '.env'
    if env_path.exists():
        load_dotenv(env_path)
except ImportError:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · weather_trader_enhanced.py (reported line 45)May include surrounding context.

python
# Load .env file if it exists
try:
    from dotenv import load_dotenv
    env_path = Path(__file__).parent.parent / '.env'
    if env_path.exists():
        load_dotenv(env_path)
except ImportError:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool scope despite requiring environment access, file writes, and network connectivity. In an autonomous trading context, missing capability boundaries weakens sandboxing and makes it harder for a host platform or reviewer to restrict the skill to only the minimum privileges it actually needs.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
- Default State: `autostart:false` - Will NOT run automatically
- Autonomous Behavior: Runs every 6 hours when manually enabled
- Financial Risk: Can deploy $30-60/day (max $100/day with quality filter)
- No Per-Trade Review: Trades execute automatically without approval

## Installation & Security

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · requirements.txt (reported line 8)May include surrounding context.

text
# Optional: tradejournal for logging trade details
# NOT INSTALLED BY DEFAULT - Only install if you want trade logging
# WARNING: If installing, inspect tradejournal source code first to verify
# it doesn't send data to external services
# tradejournal  # Uncomment to enable (inspect source first!)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code loads a Simmer API key from environment variables/.env and uses it to query a third-party trading account, which is unrelated to the advertised weather-focused function. In the context of an agent skill, undisclosed credential use and external account access increase the risk of unauthorized data exposure, user surprise, and misuse of connected financial services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The optional tradejournal integration adds a separate trade-logging capability that is not described in the manifest. Journaling may be useful operationally, but it is not an obvious requirement of using NOAA forecasts to trade temperature markets with safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill can overwrite a local config.json file in its own directory without confirmation or integrity checks. In an agent setting, this creates persistent state mutation that can silently alter future trading behavior, thresholds, or locations beyond a single run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code writes config.json silently, with no user-facing warning that local files will be created or modified. Silent persistence is dangerous for agent skills because it can create hard-to-notice behavioral drift across runs and undermines informed consent for filesystem changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The --set CLI path allows persistent modification of strategy parameters and location filters by writing to config.json, affecting later executions. In an automated or delegated agent context, this persistence can be abused to weaken safeguards, raise position sizing, or broaden trading scope without an obvious one-time action trail.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency specification uses a lower-bound constraint instead of pinning to a specific vetted version, which weakens reproducibility and can allow installation of unexpected or vulnerable releases. In security-sensitive automation, unpinned dependencies increase supply-chain risk even when the package is common and optional.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
# Optional: python-dotenv for .env file support
# The skill will work without it using system environment variables
python-dotenv>=1.0.0

# Optional: tradejournal for logging trade details
# NOT INSTALLED BY DEFAULT - Only install if you want trade logging

Unverifiable Dependency: python-dotenv has 2 known advisory(ies) (CVE-2026-28684 (python-dotenv: Symlink following in set_key allows arbitrary file overwrite via ); CVE-2026-28684 (python-dotenv reads key-value pairs from a .env file and can set them as environ)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest includes python-dotenv without a fixed version while known advisories exist for some releases, so the actual installed version may be affected and cannot be verified from this file alone. This makes the dependency posture uncertain and increases supply-chain exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest describes a weather-market trading skill using NOAA forecasts and safeguards, but this file also proactively loads a local .env file and imports optional journal integration modules. While API-key access is necessary for trading, the broader config/bootstrap behavior is not reflected in the stated purpose and adds capability outside the user-facing description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest specifically claims trading weather markets using NOAA forecasts, which suggests NOAA as the external weather-data basis. The implementation additionally queries the Nominatim OpenStreetMap API to geocode arbitrary locations, expanding external data dependencies and behavior beyond the NOAA-centered description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.