Lp1
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a straightforward air-quality lookup tool that sends coordinates and a Caiyun API token to Caiyun services as disclosed.
Install only if you are comfortable providing a Caiyun API token and having your requested coordinates sent to Caiyun. Prefer CAIYUN_TOKEN if you do not want the skill reading the optional ~/.config/knowair/token file, and treat the exercise recommendations as air-quality guidance rather than medical advice.
The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
The manifest describes an air-quality forecast skill and allows only Bash(python3:*) and Read, while the documentation says the token may be stored in ~/.config/knowair/token. Accessing a specific local credential file is an additional capability beyond the obvious need to query air-quality data, especially since the manifest's primary credential path is the CAIYUN_TOKEN environment variable.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import urllib.request
import urllib.error
API_BASE = "https://api.caiyunapp.com/v2.6"
STATION_API = "https://singer.caiyunhub.com/v3/aqi/forecast/station"
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
token = get_token()
if not token:
print(json.dumps({"error": "No API token found. Set CAIYUN_TOKEN env var or create ~/.config/knowair/token"}))
sys.exit(2)
hours = max(1, min(360, args.hours))
The description says to use the skill when the user asks 'is it safe to exercise outdoors,' which is broader than a clearly scoped air-quality invocation and could overlap with general health, weather, or activity advice. The trigger list is example-based but does not provide exclusion conditions or boundaries for when the skill should not activate.
No suspicious patterns detected.