Back to skill

Security audit

mycityweather

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Chinese-language weather-query skill with no executable code, persistence, or hidden behavior, though users should understand that real weather API use may send city/date queries to a provider.

Before installing, confirm you are comfortable with a Chinese-language weather skill and with any configured real weather provider receiving the city and date you ask about. Avoid placing real API keys directly in prompts or examples; configure them through the host platform if needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The entire skill documentation is written in Chinese and does not indicate any user-selectable language or locale option. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a policy issue unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api.md (reported line 17)May include surrounding context.

md
\## 请求示例(模拟)

GET https://api.example.com/weather?city=北京\&date=today\&appKey=hhhhh

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire instruction file is written to constrain the skill's behavior in Chinese, including fixed Chinese error output at L14, with no indication that users may choose another language. This creates a language/locale policy issue because the skill appears to enforce a specific language rather than offering user choice or documenting a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool's natural-language description and parameter examples are entirely in Chinese, which implicitly fixes the skill's user-facing locale without offering a language choice or documenting that it is a region-specific tool. This can violate language/locale policy when users have not opted into Chinese output or input conventions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly states it can connect to real third-party weather APIs, but it does not disclose that user-supplied location/date queries may be transmitted off-platform. This creates a privacy and transparency issue because users and deployers may not realize their prompts or extracted parameters are being sent to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This plain-text skill example is written entirely as Chinese user prompts and Chinese output labels, which implicitly constrains interaction to a specific language. The file does not offer any language choice, opt-in mechanism, or justification for a Chinese-only locale, matching the policy-violation criterion for language or locale restrictions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest-style file only describes the tool as "获取指定城市的天气信息" without specifying when it should be invoked, what kinds of requests qualify, or any exclusion conditions. In a tool registry, that broad natural-language description can overlap with many general requests about locations or planning, making invocation boundaries less explicit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.