Back to skill

Security audit

Cputemp

Security checks for vulnerabilities and agentic risk

Overview

The skill claims to fetch Yahoo Finance stock quotes but includes an unrelated Raspberry Pi temperature script and no visible quote-fetching implementation.

Review before installing. The submitted package is not coherent: it presents itself as a Yahoo Finance quote skill but ships unrelated local host telemetry code. Install only if the publisher corrects the package so the documentation, metadata, and implementation all match, or if you intentionally want the Raspberry Pi temperature script and it is clearly documented as such.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Note
Location
alltemp.sh:6
Finding

Undeclared Collection and Disclosure of Host Thermal Telemetry

Content
View full analysis

Vulnerability Details

File Location: alltemp.sh, lines 6–10
Vulnerability Type: Undeclared System Information Collection
Risk Level: Low

bash
cpu=$( < /sys/class/thermal/thermal_zone0/temp)
#echo "$(date) @ $(hostname)"
#echo "-------------------------------------------"
echo "CPU=$((cpu/1000))"
echo "GPU=$(vcgencmd measure_temp | egrep -o '[0-9]*\.[0-9]*')"

Technical Analysis

The package describes itself in SKILL.md as a Yahoo Finance stock-quote skill. However, the bundled shell script reads the host's CPU thermal interface, invokes the Raspberry Pi vcgencmd utility to retrieve GPU temperature, and writes both values to standard output. This host-telemetry behavior is unrelated to the documented finance functionality.

The script does not transmit the collected data over a network, elevate privileges, establish persistence, or execute a remote payload. No automatic invocation path is visible in the audited files. Consequently, exploitation requires a user or agent to execute alltemp.sh, either directly or through an external integration not present in this project.

Attack Path

  1. A user or agent installs or reviews the package based on its declared stock-quote purpose.
  2. The user, agent, or an external launcher executes alltemp.sh.
  3. The script reads /sys/class/thermal/thermal_zone0/temp and runs vcgencmd measure_temp.
  4. Local CPU and GPU thermal telemetry is printed to standard output.
  5. Any caller that captures command output can receive this undeclared host information.

Impact Assessment

The script can disclose CPU and GPU temperature information available to the executing account. Its scope is limited to local thermal telemetry exposed by the operating system and Raspberry Pi firmware tooling. The reviewed implementation provides no evidence of credential access, arbitrary command execution, privilege escalation, persistence, destructive behavior, or net ...[truncated 134 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove alltemp.sh from the stock-quote package because it is unrelated to the documented functionality.
  • If thermal monitoring is intentional, place the script in a separately named and documented skill with explicit user consent before collecting host telemetry.
  • Add the actual Yahoo Finance quote-fetching implementation and define an unambiguous entry point matching SKILL.md.
  • Restrict packaged files to those necessary for the declared purpose and add automated checks that compare documented capabilities with executable behavior.
  • Avoid returning host telemetry unless it is required for the requested task, and clearly identify every collected field and its destination.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill fetches real-time stock quotes from Yahoo Finance, implying a finance/data retrieval function and likely network access. The actual code does something entirely different: it reads and prints Raspberry Pi CPU and GPU temperatures using local system files and a device-specific command. There is no stock quote functionality, no Yahoo Finance access, and no network behavior. This is a clear material mismatch in primary purpose and accessed resources.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file's behavior does not match the declared skill purpose: instead of fetching Yahoo Finance stock quotes, it reads local Raspberry Pi CPU and GPU temperatures. This kind of capability mismatch is dangerous because it misleads reviewers and users about what will execute, undermines trust boundaries, and can conceal unauthorized host inspection or repurposed code in a skill that claims an unrelated function.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline comments explicitly document Raspberry Pi temperature monitoring, which directly contradicts the declared Yahoo Finance stock-quote function of the skill. While the code itself is simple, this discrepancy indicates deceptive or careless packaging and increases the risk that consumers invoke local system-access behavior they did not intend to authorize.

Content

No source excerpt is available for this finding.