Back to skill

Security audit

Py Math Viz

Security checks for vulnerabilities and agentic risk

Overview

This plotting skill is mostly coherent, but it ships an undocumented weather helper that sends latitude, longitude, and timezone to an external service.

Install only if you are comfortable with a plotting skill that also includes an undocumented weather script capable of sending coordinates and timezone to Open-Meteo. Prefer requiring the publisher to document or remove that helper, add explicit opt-in for network weather fetching, and bound image sizes/DPI before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Warning
Location
scripts/weather.py:18
Finding

Undisclosed Transmission of Location Data to an External Weather Service

Content
View full analysis
Dict[str, list[float]]: params = { "latitude": latitude, "longitude": longitude, "hourly": "temperature_2m,precipitation,precipitation_probability,windspeed_10m,cloudcover", "forecast_days": 2, "timezone": timezone, } query = "&".join(f"{key}={value}" for key, value in params.items()) with urlopen(f"{API_URL}?{query}") as resp: payload = json.load(resp) return payload["hourly"] ``` ### Technical Analysis The weather helper sends latitude, longitude, and timezone values to `api.open-meteo.com`. These parameters may reveal a user's precise or approximate location. The request is made automatically whenever the helper is executed. The endpoint is fixed and uses HTTPS, and the reviewed code does not transmit credentials or arbitrary local files. Therefore, this is not evidence of malicious exfiltration. However, `SKILL.md` describes local plot rendering and image processing without documenting the weather helper, its network access, the external recipient, or the data being disclosed. The query is also assembled through manual string concatenation rather than a URL-encoding function, and `urlopen` is called without a timeout. This can result in malformed requests for unusual timezone values and can leave the process blocked by network failures. ### Attack Path 1. An agent discovers or is instructed to invoke `scripts/weather.py`. 2. The agent supplies ...[truncated 774 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/plot_from_spec.py:76
Finding

Unbounded Plot Dimensions and DPI Permit Resource Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_PIXELS: raise ValueError("requested plot exceeds the maximum pixel count") ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tile_images.py:54
Finding

Unbounded Tile Geometry and Image Count Permit Memory Exhaustion

Content
View full analysis
Remediation
View remediation
MAX_IMAGES: raise ValueError("too many input images") rows = (len(args.images) + cols - 1) // cols if rows * cols * cw * ch > MAX_OUTPUT_PIXELS: raise ValueError("requested tile exceeds the maximum pixel count") ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This is a meaningful description-behavior mismatch: a skill presented as a general-purpose local visualization tool reportedly also performs remote weather-data retrieval and a specialized forecast workflow. Hidden or undeclared network behavior is dangerous because it can exfiltrate prompts/data, surprise users, and cause the agent to select the skill for tasks outside the user's intent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill metadata omits an explicit tool/permission scope even though the broader implementation reportedly uses file-read and network capabilities. Without declared boundaries, an agent may invoke the skill in contexts where users reasonably expect only local plotting, increasing the chance of unintended data access or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description says to use the skill when the user asks to 'draw graphs' or 'make publication-quality plots', which are broad natural-language triggers without explicit constraints or exclusion examples. In a markdown skill description, this can cause over-selection because the activation scope is described expansively rather than with a narrow trigger list.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script adds live weather-data retrieval from an external service, which exceeds the stated local visualization/export scope and introduces undeclared network behavior. In an agent skill, unexpected outbound access is security-relevant because it expands the trust boundary, can leak user-supplied parameters such as location/timezone, and may violate sandbox or policy expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The hardcoded external API endpoint confirms that the skill transmits data off-host to a third party. In a skill described as local math/data visualization, this mismatch is dangerous because users may provide sensitive location/context data without realizing it will be sent externally.

Content

Scanner excerpt · scripts/weather.py (reported line 20)May include surrounding context.

python
import seaborn as sns


API_URL = "https://api.open-meteo.com/v1/forecast"


@dataclass

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code performs external network access via urlopen to a third-party weather service, a capability not justified by a visualization-only skill description. Even if the endpoint is legitimate, undisclosed network access increases attack surface, creates privacy risk for user location inputs, and can surprise operators who expect offline/local rendering behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill instructs the agent to write generated outputs into out/ but does not include any user-facing warning that it will create or overwrite files in the workspace. For markdown files, behaviors affecting user data or filesystem state should be disclosed so users understand the side effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file includes a command that writes an output image to out/plots/out.png, which affects the user's filesystem. The recipe provides no warning that running it will create or overwrite files, and no disclosure about where artifacts are written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rendering function sets lang: str = "ru" by default, which imposes a specific language choice without user opt-in. This is reinforced elsewhere in the script and can violate language/locale policy when a neutral or user-selected default is expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The command-line interface restricts output to ru or en but defaults to ru, forcing a locale choice unless the user overrides it. Because the policy allows fixed locale only when clearly justified or opt-in, this default is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.