Back to skill

Security audit

geoskill-emergency-evacuation-routing

Security checks across malware telemetry and agentic risk

Overview

The routing tool itself is local, but the package includes under-disclosed credential and network helpers that do not fit the stated evacuation-routing purpose.

Review this package before installing in an environment with credentials. The main evacuation-routing script appears local, but the bundle includes unrelated helpers that can read credential files, use hardcoded service credentials, perform network geocoding/downloads, and write home-directory cache files. Prefer a version that removes or clearly documents those helpers and pins dependencies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (34)

Lp3

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding
The skill documentation declares no permissions, yet the detected capabilities include file read/write, shell, environment access, and network. That mismatch weakens trust boundaries and can expose users to unexpected local data access or outbound communication if the underlying skill code actually uses those capabilities.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The declared purpose is offline evacuation routing, but the analyzed behavior reportedly includes external geocoding, generic downloading, credential harvesting from environment/.netrc/secrets files, and even hardcoded fallback Earthdata credentials. This is a serious description-behavior mismatch because it hides high-risk functionality unrelated to the stated task, enabling secret exposure, unauthorized network access, and supply-chain style abuse under the guise of a benign geospatial skill.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The vendored core metadata identifies the skill as 'landsat-download', which does not match the declared emergency evacuation routing purpose. This kind of provenance mismatch undermines trust in the packaged code, suggests copy/paste or supply-chain hygiene issues, and can conceal inclusion of functionality that operators do not expect in a safety-critical routing skill.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The vendored inventory includes modules such as safe_download.py, sensors.py, and credentials.py that appear unrelated to evacuation routing. In this context, unjustified download and credential-handling capabilities expand the attack surface, may enable unexpected network access or secret processing, and are especially concerning because the skill's purpose is public-safety route planning rather than data acquisition.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
This credentials module exposes broad secret-access capability unrelated to the stated emergency evacuation routing purpose, including OpenAI, CMA, FIRMS, EOG, Earthdata, .netrc, and a user secrets file. In a skill context, unnecessary credential aggregation increases blast radius: any other code in the skill can import this module and harvest or misuse unrelated credentials, which is especially dangerous because the skill's declared function does not justify that breadth of access.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The documentation states that passwords are not cached, but `load_user_secrets()` copies secrets into the process-global `_DEFAULTS` dictionary and reuses them for later calls. This creates a misleading security boundary and keeps sensitive values resident in memory longer than claimed, increasing exposure to accidental disclosure, debugging dumps, or misuse by other in-process code.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
User-supplied place names are sent to external geocoding services (Open-Meteo and optionally Nominatim), which can disclose sensitive operational intent, especially in an emergency-evacuation routing skill. In this context, queried locations may reveal incident sites, evacuation zones, or planning targets to third parties without explicit user awareness or consent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
Resolved queries are stored persistently under the user's home directory, which can leave a local record of searched places and associated AOI data. In an emergency-routing skill, cached locations may expose sensitive movement planning, disaster response focus areas, or personally relevant destinations to other local users, backup systems, or forensic review.

Missing User Warnings

High
Confidence
99% confidence
Finding
The module hardcodes fallback credentials, including a plaintext Earthdata username and password, directly in source. Hardcoded credentials are a serious secret-management failure because they can be extracted from the repository, reused by unauthorized parties, and often persist long after disclosure.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The code hard-codes an Accept-Language header of zh-CN for Nominatim requests, which discloses a China-oriented locale preference to a third-party service regardless of the actual user’s preferences or consent. This creates a privacy and policy-compliance issue by leaking user/environment metadata unnecessarily, though it does not by itself enable code execution or direct compromise.

Credential Access

High
Category
Privilege Escalation
Content
/ `EARTHDATA_TOKEN` / `FIRMS_MAP_KEY` / `OPENAI_API_KEY` /
  `CMA_API_KEY` / `EOG_USERNAME` / `EOG_PASSWORD` 任何一项显式设置
  都优先于默认值。
- **支持 .netrc**:若 ~/.netrc 中存在 `machine urs.earthdata.nasa.gov`
  行,优先取 .netrc 凭证。
- **支持用户级 secrets 文件** ``~/.geoskill/secrets.json``:Phase 7
  (2026-07-27) 新增。本文件在用户 home,**不** vendor 到任何 skill,
Confidence
78% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
/ `EARTHDATA_TOKEN` / `FIRMS_MAP_KEY` / `OPENAI_API_KEY` /
  `CMA_API_KEY` / `EOG_USERNAME` / `EOG_PASSWORD` 任何一项显式设置
  都优先于默认值。
- **支持 .netrc**:若 ~/.netrc 中存在 `machine urs.earthdata.nasa.gov`
  行,优先取 .netrc 凭证。
- **支持用户级 secrets 文件** ``~/.geoskill/secrets.json``:Phase 7
  (2026-07-27) 新增。本文件在用户 home,**不** vendor 到任何 skill,
Confidence
78% confidence
Finding
~/.netrc

Credential Access

High
Category
Privilege Escalation
Content
`CMA_API_KEY` / `EOG_USERNAME` / `EOG_PASSWORD` 任何一项显式设置
  都优先于默认值。
- **支持 .netrc**:若 ~/.netrc 中存在 `machine urs.earthdata.nasa.gov`
  行,优先取 .netrc 凭证。
- **支持用户级 secrets 文件** ``~/.geoskill/secrets.json``:Phase 7
  (2026-07-27) 新增。本文件在用户 home,**不** vendor 到任何 skill,
  **不** push 到 GitHub;用于把个人真实凭证(NASA Earthdata bearer
Confidence
78% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
(2026-07-27) 新增。本文件在用户 home,**不** vendor 到任何 skill,
  **不** push 到 GitHub;用于把个人真实凭证(NASA Earthdata bearer
  token 等)放在 skill 之外。
- **不缓存密码**:每次调用读环境或 .netrc(避免长寿命进程泄露)。
- **统一接口**:`get_earthdata_creds()` / `get_earthdata_token()` /
  `get_firms_key()` / `get_cma_key()` / `get_openai_key()` /
  `get_eog_creds()` 六个 helper。
Confidence
80% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
"EOG_PASSWORD": "",
}

# .netrc 解析(仅在 UNIX-like / WSL 下 ~/.netrc 可用;Windows 下
# 通常用 %USERPROFILE%\_netrc,但 .netrc 本身仍是约定俗成的名称)。
_NETRC_HOSTS = {
    "urs.earthdata.nasa.gov": ("EARTHDATA_USERNAME", "EARTHDATA_PASSWORD"),
Confidence
82% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
"EOG_PASSWORD": "",
}

# .netrc 解析(仅在 UNIX-like / WSL 下 ~/.netrc 可用;Windows 下
# 通常用 %USERPROFILE%\_netrc,但 .netrc 本身仍是约定俗成的名称)。
_NETRC_HOSTS = {
    "urs.earthdata.nasa.gov": ("EARTHDATA_USERNAME", "EARTHDATA_PASSWORD"),
Confidence
82% confidence
Finding
~/.netrc

Credential Access

High
Category
Privilege Escalation
Content
}

# .netrc 解析(仅在 UNIX-like / WSL 下 ~/.netrc 可用;Windows 下
# 通常用 %USERPROFILE%\_netrc,但 .netrc 本身仍是约定俗成的名称)。
_NETRC_HOSTS = {
    "urs.earthdata.nasa.gov": ("EARTHDATA_USERNAME", "EARTHDATA_PASSWORD"),
    "firms.modaps.eosdis.nasa.gov": ("FIRMS_MAP_KEY",),
Confidence
84% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
def _read_netrc(host: str) -> Optional[Tuple[str, ...]]:
    """从 ~/.netrc 读指定 host 的凭证(无 token 格式)。"""
    for path in (Path.home() / ".netrc", Path.home() / "_netrc"):
        if not path.is_file():
            continue
Confidence
90% confidence
Finding
~/.netrc

Credential Access

High
Category
Privilege Escalation
Content
def _read_netrc(host: str) -> Optional[Tuple[str, ...]]:
    """从 ~/.netrc 读指定 host 的凭证(无 token 格式)。"""
    for path in (Path.home() / ".netrc", Path.home() / "_netrc"):
        if not path.is_file():
            continue
        try:
Confidence
90% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
def _resolve(name: str) -> str:
    """env > 用户 secrets > .netrc > 默认. 空字符串视为未设."""
    env_val = os.environ.get(name, "").strip()
    if env_val:
        return env_val
Confidence
76% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
def _resolve_with_netrc(env_name: str, netrc_host: str, field_index: int) -> str:
    """env > 用户 secrets > .netrc > 默认."""
    env_val = os.environ.get(env_name, "").strip()
    if env_val:
        return env_val
Confidence
82% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
解析顺序:
    1. env: EARTHDATA_USERNAME / EARTHDATA_PASSWORD
    2. ~/.geoskill/secrets.json
    3. .netrc: machine urs.earthdata.nasa.gov
    4. _DEFAULTS 兜底
    """
    u = _resolve_with_netrc("EARTHDATA_USERNAME", "urs.earthdata.nasa.gov", 0)
Confidence
83% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
解析顺序:
    1. env: EARTHDATA_TOKEN
    2. ~/.geoskill/secrets.json
    3. .netrc: machine urs.earthdata.nasa.gov account <TOKEN>
    4. _DEFAULTS(通常为空)
    """
    return _resolve("EARTHDATA_TOKEN")
Confidence
81% confidence
Finding
.netrc

Credential Access

High
Category
Privilege Escalation
Content
都优先于默认值。
- **支持 .netrc**:若 ~/.netrc 中存在 `machine urs.earthdata.nasa.gov`
  行,优先取 .netrc 凭证。
- **支持用户级 secrets 文件** ``~/.geoskill/secrets.json``:Phase 7
  (2026-07-27) 新增。本文件在用户 home,**不** vendor 到任何 skill,
  **不** push 到 GitHub;用于把个人真实凭证(NASA Earthdata bearer
  token 等)放在 skill 之外。
Confidence
84% confidence
Finding
secrets.json

Credential Access

High
Category
Privilege Escalation
Content
_DEFAULTS: dict[str, str] = {
    "EARTHDATA_USERNAME": "ruiduobao",
    "EARTHDATA_PASSWORD": "Ruiduobao123",
    "EARTHDATA_TOKEN": "",  # 用户级 secrets.json 提供(不走默认值以免推到 GitHub)
    "FIRMS_MAP_KEY": "",
    "CMA_API_KEY": "",
    "OPENAI_API_KEY": "",
Confidence
80% confidence
Finding
secrets.json

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/conftest.py:15