Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This weather skill does what it says: it runs a local Python script that sends coordinates and a Caiyun API token to Caiyun to fetch forecasts.
Install this only if you are comfortable using Caiyun Weather and sending requested coordinates to that service. Store the Caiyun token as an environment variable if possible, and avoid querying exact private locations when approximate coordinates are sufficient.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import urllib.request
import urllib.error
API_BASE = "https://api.caiyunapp.com/v2.6"
SKYCON_EN = {
"CLEAR_DAY": "Clear", "CLEAR_NIGHT": "Clear",
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
token = get_token()
if not token:
print(json.dumps({"error": "No API token found. Set CAIYUN_TOKEN env var or create ~/.config/knowair/token"}))
sys.exit(2)
if args.forecast_type == "hourly":
The example includes a Chinese-language user prompt and explicitly passes --lang zh, which indicates a forced locale/output language in the skill behavior. The file does not state that language selection is optional or user-configurable, so this can conflict with language/locale policy expectations.
The CLI enforces --lang choices of only en and zh, which is a language/locale constraint expressed in natural-language-facing behavior. There is no accompanying justification that this limitation is required by a region-specific or compliance-specific use case.
The skill transmits precise latitude/longitude and the API token to an external third-party service, which has privacy implications because location data can be sensitive. In this weather-skill context, the transmission is functionally necessary, so the main issue is lack of explicit disclosure/consent rather than covert exfiltration.
No suspicious patterns detected.