Back to skill

Security audit

Wind & Site

Security checks for vulnerabilities and agentic risk

Overview

This wind-data skill is purpose-aligned and disclosed, with ordinary dependency and third-party API considerations but no hidden or destructive behavior found.

Install this only if you are comfortable sending requested coordinates and date ranges to Open-Meteo. Use a virtual environment or other isolation for the Python dependencies, and prefer pinned dependency versions for reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Python Dependencies

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-3
Related Installation Instruction: SKILL.md:20
Vulnerability Type: Supply-chain exposure through mutable dependency resolution
Risk Level: Medium

Vulnerable Code

text
requests
numpy
matplotlib

The dependencies are installed through the following documented command:

bash
pip install -r requirements.txt

Technical Analysis

The dependency declarations do not specify exact versions or package integrity hashes. Consequently, each installation can resolve to different package releases from the configured Python package index. The installed code may therefore differ from the dependency versions that were present when the Skill was reviewed.

This does not establish that the listed packages are currently malicious. However, it creates a supply-chain weakness: a compromised future release, compromised package-index account, malicious package source configured in the environment, or unexpected incompatible update could introduce attacker-controlled behavior during package installation or subsequent script execution.

Because Python packages can execute build or installation logic and are later imported by the Skill scripts, dependency code runs with the privileges of the user performing setup or invoking the Skill.

Attack Path

  1. An attacker compromises a dependency release channel, package maintainer account, configured package index, or package-resolution path.
  2. The attacker publishes or serves a malicious version that still satisfies the unrestricted dependency declaration.
  3. A user follows the documented pip install -r requirements.txt setup procedure.
  4. pip resolves and downloads the attacker-controlled package because no reviewed version or integrity hash is enforced.
  5. Malicious code executes during package installation, import, or use by scripts/wind_info.py or scripts/wind_rose.py.
  6. T ...[truncated 599 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every dependency to an exact, reviewed version using ==.

  2. Generate and record cryptographic hashes for all packages and transitive dependencies.

  3. Install with hash verification enabled, for example:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Use a dependency-locking workflow such as pip-tools to resolve and lock transitive dependencies reproducibly.

  5. Review and test dependency upgrades before updating the lockfile rather than accepting new releases automatically.

  6. Use an explicitly trusted package index and avoid untrusted additional indexes.

  7. Run dependency installation and the Skill under a non-privileged account or isolated virtual environment to reduce the impact of a supply-chain compromise.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The script performs outbound HTTP requests to Open-Meteo via requests.get, but the skill metadata declares only shell:exec permission. This creates a permission-model mismatch: reviewers or policy engines could believe the skill cannot exfiltrate or transmit data externally when it in fact can send user-supplied coordinates to a third party.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code makes a direct outbound network request despite the manifest declaring only shell:exec permission. In an agent ecosystem, undeclared capabilities are dangerous because they bypass operator expectations and can be reused to transmit sensitive user inputs or environment-derived data to external services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The script is explicitly configured to contact external endpoints at api.open-meteo.com and archive-api.open-meteo.com, which constitutes data egress to a third party. In this skill's context, external access is functionally expected, but it still matters because the manifest does not declare network capability and the transmitted data includes user-supplied location.

Content

Scanner excerpt · scripts/wind_info.py (reported line 32)May include surrounding context.

python
"timezone": "UTC",
        }
    else:
        url = "https://api.open-meteo.com/v1/forecast"
        params = {
            "latitude": lat,
            "longitude": lon,

Scope Creep

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script makes outbound HTTP requests to the Open-Meteo API even though the skill manifest declares only shell:exec permission. This creates a capability/permission mismatch that can bypass operator expectations and policy controls, and in a broader agent environment could be abused for unapproved data exfiltration or network access.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'requests' is unpinned, so installs may resolve to different versions over time, reducing build reproducibility and making it impossible to verify whether a vulnerable or incompatible release will be pulled in. In a skill with shell execution permission, supply-chain uncertainty is more concerning because compromised or vulnerable packages could be leveraged in a higher-privilege runtime.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
numpy
matplotlib

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest references 'requests' without a version pin even though the package has multiple published advisories, so there is no way to determine from this file whether deployment will use a fixed or vulnerable release. This is dangerous because vulnerable dependency resolution may occur silently during installation, and the skill's shell execution capability increases the consequences of any compromised runtime component.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'numpy' is unpinned, which creates non-reproducible environments and leaves the actual installed version undefined at deployment time. That uncertainty can expose the skill to known vulnerable releases or unexpected behavior changes, especially if the environment rebuilds automatically.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
numpy
matplotlib

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

The manifest lists 'numpy' without a pinned version despite known advisories affecting some releases, so the security posture of the installed package cannot be verified from the file alone. In practice, this can result in environments resolving to a vulnerable build or changing unexpectedly over time, undermining both security and reliability.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'matplotlib' is unpinned, allowing future installations to fetch arbitrary newer or older compatible releases depending on resolver behavior and package index state. This increases supply-chain risk and makes security review of the runtime environment incomplete.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests
numpy
matplotlib

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The request includes user-provided latitude and longitude values and sends them to an external API without any in-code user-facing disclosure. While the data here is limited to location coordinates for the stated function, it is still external transmission of potentially sensitive location information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.