Back to skill

Security audit

Weathercli

Security checks for vulnerabilities and agentic risk

Overview

This weather skill is mostly coherent, but its install instructions tell agents to fetch and run an unpinned third-party executable, which users should review before installing.

Review the upstream weathercli project before installing, prefer a pinned reviewed version with checksum or signature verification, and avoid submitting sensitive exact addresses unless needed. Once installed, the weather commands themselves appear limited to weather and location lookup.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:214
Finding

Unpinned Third-Party Executable Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 214–222
Vulnerability Type: Supply-chain risk from mutable and unverifiable third-party dependencies
Risk Level: Medium

Vulnerable Code

bash
# Via Go
go install github.com/pjtf93/weathercli/cmd/weathercli@latest

# Or download binary from releases
# https://github.com/pjtf93/weathercli/releases

Technical Analysis

The installation guidance uses the mutable @latest selector to retrieve and compile third-party code that is not included in the audited project. The alternative release-download guidance similarly provides no fixed version, checksum, digital signature, or verification procedure.

Because dependency contents are resolved at installation time, the executable ultimately installed and run may differ from the implementation that the skill author reviewed or described. Static review of SKILL.md therefore cannot verify that the executable only performs the documented geocoding and Open-Meteo requests.

Exploitation requires control of, or malicious publication through, the referenced upstream repository or release channel. There is no evidence in the audited artifact that the named upstream project is currently malicious.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, build pipeline, or release account, or otherwise causes a malicious version to become the version resolved as latest.
  2. A user or agent follows the skill's installation instructions.
  3. go install ...@latest retrieves and compiles the attacker-controlled source, or the user downloads a substituted release binary.
  4. The resulting weathercli executable is invoked for a weather request.
  5. The malicious executable runs with the privileges and environmental access of the invoking user or agent.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing or invoking us ...[truncated 526 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a reviewed, immutable version or commit identifier.
  2. Publish the expected cryptographic checksum for each supported release artifact and require verification before execution.
  3. Prefer signed releases and document signature verification against a trusted maintainer key or identity.
  4. Pin transitive Go dependencies through a reviewed go.mod and go.sum in auditable source.
  5. Avoid automatic installation. Require explicit user approval before downloading or executing third-party software.
  6. Where feasible, vendor the reviewed source or distribute reproducible builds so users can confirm that binaries correspond to audited code.
  7. Run the utility with least privilege and a restricted environment, filesystem view, and network policy limited to documented weather-service endpoints.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied locations to an external weather/geocoding service, but the description does not clearly disclose that this data leaves the local environment. While locations are usually low-sensitivity, they can reveal private information such as home address, travel plans, or whereabouts, so the omission is a real privacy/transparency issue rather than a direct code-execution risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The notes specify temperatures in Celsius and wind speed in km/h, with only manual conversion guidance, which imposes a locale-specific presentation by default. Under the language/locale policy, hard-coding one regional convention without offering a user-selectable option can be a policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.