Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a narrow weather lookup tool that uses a Caiyun API token and location coordinates to fetch short-term rain forecasts.
Install this only if you are comfortable providing a Caiyun Weather API token and having queried coordinates sent to Caiyun. Prefer using the CAIYUN_TOKEN environment variable and review when the skill is invoked for broad weather questions.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill description contains broad natural-language trigger phrases like 'will it rain soon' and 'should I bring an umbrella,' which can cause the skill to activate on ordinary weather-related conversation without strong user intent to invoke this specific capability. This increases the chance of unintended tool use and unnecessary external API calls, though the direct security impact is limited because the skill’s function is narrowly scoped to weather lookup.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import urllib.request
import urllib.error
API_BASE = "https://api.caiyunapp.com/v2.6"
def get_token():
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
token = get_token()
if not token:
print(json.dumps({"error": "No API token found. Set CAIYUN_TOKEN env var or create ~/.config/knowair/token"}))
sys.exit(2)
url = f"{API_BASE}/{token}/{args.lng},{args.lat}/minutely?lang={args.lang}"
No suspicious patterns detected.