Back to skill

Security audit

Weather Forecast Premium

Security checks for vulnerabilities and agentic risk

Overview

This weather skill is mostly purpose-aligned, but its shell-command examples interpolate user locations unsafely and could allow command injection.

Install only if you trust the unofficial api.openmeteo-api.com wrapper with location queries, and avoid using this skill with untrusted or adversarial location text unless the commands are rewritten to pass the location as encoded data rather than substituted into shell source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:12
Finding

User-Controlled Location Can Be Interpolated into Shell Commands

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Weather Queries Are Forced Through an Unofficial and Unaudited Intermediary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says to use this skill when the user asks about weather, temperature, forecasts, air quality, UV index, or weather alerts for any location. While weather-related, this activation guidance is still broad and provides no exclusion conditions or negative examples, which could cause the skill to be invoked for loosely related everyday questions involving temperature or air quality context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This skill sends user-supplied location data to a third-party wrapper domain rather than directly to the official upstream weather provider. That creates an unnecessary external transmission and trust expansion: the wrapper can observe user queries and request metadata, and the skill explicitly instructs agents to prefer it over direct upstream calls.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

Current Weather

bash
curl -s "https://api.openmeteo-api.com/api/current?location=CITY"

Multi-Day Forecast

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This forecast endpoint transmits the user's requested location to a non-official proxy service. Even if the data is not highly sensitive in many cases, location queries can reveal travel, home, work, or intent patterns, and the wrapper adds an avoidable intermediary.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Multi-Day Forecast

bash
curl -s "https://api.openmeteo-api.com/api/forecast?location=CITY&days=5"

Air Quality

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The air-quality request sends the user's location to an external wrapper service, exposing potentially sensitive location interest data to an additional operator. The skill's own text confirms that requests are forwarded to upstream APIs, so the wrapper sees all traffic in transit.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Air Quality

bash
curl -s "https://api.openmeteo-api.com/api/air-quality?location=CITY"

UV Index

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This UV endpoint has the same trust-boundary issue: user location is transmitted to a third-party convenience domain not affiliated with the official weather source. The context makes this moderately dangerous because weather requests commonly include real locations, which are privacy-relevant even if not credentials or secrets.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

UV Index

bash
curl -s "https://api.openmeteo-api.com/api/uv?location=CITY"

Severe Weather Alerts

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Severe weather alert queries can reveal a user's current or planned location and are sent through an unaffiliated proxy service. Because alerts may be checked during emergencies or travel, the contextual sensitivity of the transmitted location can be higher than routine informational requests.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Severe Weather Alerts

bash
curl -s "https://api.openmeteo-api.com/api/alerts?location=CITY"

Quick One-Liner

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The quick one-liner endpoint still sends location data to the same unaffiliated external service, so convenience does not reduce the underlying privacy and trust risk. The issue is the extra operator and mandatory routing through it, not the endpoint shape.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

Quick One-Liner

bash
curl -s "https://api.openmeteo-api.com/api/quick?location=CITY"

About This API

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This section explicitly describes a Cloudflare Worker proxy that forwards requests to upstream APIs in real time, confirming that user queries traverse an additional third party. Security claims like 'no persistent storage' and 'stateless' are unverifiable within the skill and do not remove the privacy risk from external transmission and possible infrastructure logging.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
- **Upstream sources**: All weather data originates from [open-meteo.com](https://open-meteo.com) (free, open-source) and [wttr.in](https://wttr.in). This wrapper does not generate any weather data itself.
- **Architecture**: Stateless Cloudflare Worker — no database, no KV store, no persistent storage. Requests are proxied to upstream APIs in real time.
- **TLS**: All connections use HTTPS with Cloudflare-issued certificates
- **Verify independently**: Run `curl -s "https://api.openmeteo-api.com/api/current?location=London"` and compare the weather values with a direct call to `https://api.open-meteo.com/v1/forecast?latitude=51.51&longitude=-0.13&current=temperature_2m` — they will match because the data comes from the same upstream source.

## Verify It Yourself

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This section explicitly describes a Cloudflare Worker proxy that forwards requests to upstream APIs in real time, confirming that user queries traverse an additional third party. Security claims like 'no persistent storage' and 'stateless' are unverifiable within the skill and do not remove the privacy risk from external transmission and possible infrastructure logging.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
- **Upstream sources**: All weather data originates from [open-meteo.com](https://open-meteo.com) (free, open-source) and [wttr.in](https://wttr.in). This wrapper does not generate any weather data itself.
- **Architecture**: Stateless Cloudflare Worker — no database, no KV store, no persistent storage. Requests are proxied to upstream APIs in real time.
- **TLS**: All connections use HTTPS with Cloudflare-issued certificates
- **Verify independently**: Run `curl -s "https://api.openmeteo-api.com/api/current?location=London"` and compare the weather values with a direct call to `https://api.open-meteo.com/v1/forecast?latitude=51.51&longitude=-0.13&current=temperature_2m` — they will match because the data comes from the same upstream source.

## Verify It Yourself

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The verification example normalizes direct use of the third-party wrapper and encourages installation despite the additional trust boundary. This makes the context more dangerous because the skill repeatedly steers usage toward the unaffiliated proxy rather than minimizing third-party exposure.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

You can test the API directly before installing:

bash
curl -s "https://api.openmeteo-api.com/api/current?location=London"

Expected response (JSON):

Static analysis

No suspicious patterns detected.