Back to skill

Security audit

UAPI 查询天气 接口

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward weather-query skill for one UAPI endpoint, with no local code execution or persistence, though users should be aware of external API calls and possible IP-based location lookup.

Before installing, understand that weather lookups may contact https://uapis.cn and, if you do not provide a city or adcode, the service may infer location from the client IP. Provide an explicit city/adcode for better control, and only add a UAPI Key if you are comfortable using that service account.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The English trigger list includes very broad terms such as "weather" and "weather api", which can cause this skill to be selected for loosely related requests rather than only for the specific GET /misc/weather operation. In an agent setting, overbroad routing can lead to unintended API calls, incorrect handling of user intent, and leakage of user context to an unnecessary external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that if neither city nor adcode is provided, the service will infer location from the client IP, but it does not warn about the privacy implications of transmitting and processing location derived from IP. In an agent setting, this can cause location disclosure without clear user awareness or consent, especially when the agent silently falls back to auto-location instead of prompting for a city.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document is written primarily in Chinese and instructs usage in that locale without offering any language choice or stating that the skill is region-specific. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description is primarily framed around Chinese trigger phrases and Chinese naming of the interface, while not explicitly stating that users may interact in their preferred language. This can be read as a locale/language bias without an explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.