Back to skill

Security audit

ip-lookup

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it gives the agent an under-scoped network helper that can be pointed at arbitrary URLs and can expose caller IP metadata.

Review this skill before installing in any private, corporate, or sensitive network. Use it only when you intend to send an IP lookup request to MyIPChecker, avoid caller-IP lookups unless you are comfortable revealing the runtime's apparent IP/location metadata, and do not allow arbitrary --base-url values unless the agent is network-sandboxed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/get_myipchecker_ip_info.sh:4
Finding

Unrestricted Base URL and Redirect Following Enable Server-Side Request Forgery

Content
View full analysis
&2 exit 2 fi BASE_URL=$2 shift 2 ;; ``` ```sh BASE_URL=${BASE_URL%/} URL="$BASE_URL/api/ip" ``` ```sh if [ -n "$IP" ]; then HTTP_STATUS=$(curl -sS -L -G \ -H "Accept: application/json" \ -H "User-Agent: $USER_AGENT" \ --connect-timeout "$TIMEOUT_SECONDS" \ --max-time "$TIMEOUT_SECONDS" \ --data-urlencode "ip=$IP" \ -o "$BODY_FILE" \ -w "%{http_code}" \ "$URL" 2>"$STATUS_FILE") else HTTP_STATUS=$(curl -sS -L \ -H "Accept: application/json" \ -H "User-Agent: $USER_AGENT" \ --connect-timeout "$TIMEOUT_SECONDS" \ --max-time "$TIMEOUT_SECONDS" \ -o "$BODY_FILE" \ -w "%{http_code}" \ "$URL" 2>"$STATUS_FILE") fi CURL_EXIT=$? if [ "$CURL_EXIT" -ne 0 ]; then REASON=$(cat "$STATUS_FILE") printf '{\n "transport_error": "request_error",\n "reason": "%s",\n "url": "%s"\n}\n' "$(json_escape "$REASON")" "$(json_escape "$URL")" exit 1 fi BODY=$(cat "$BODY_FILE") case "$HTTP_STATUS" in 2??) if [ -z "$BODY" ]; then printf '{\n "transport_error": "invalid_json",\n "url": "%s",\n "body": ""\n}\n' "$(json_escape "$URL")" exit 1 fi printf '%s\n' "$BODY" ;; *) printf '{\n "transport_error": "http_error",\n "status": %s,\n "reason": "HTTP %s",\n "url": "%s",\n "body": "%s"\n}\n' \ "$HTTP_STATUS" \ "$HTTP_STATUS" \ "$(json_escape "$URL")" \ "$(json_escape "$BODY")" exit 1 ;; esac ``` The skill do ...[truncated 3058 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to execute a shell helper for live external requests but does not declare any explicit tool scope or permission boundary in the skill metadata. That creates an authorization ambiguity where an agent may invoke shell unnecessarily or more broadly than intended, increasing the chance of unintended command execution or policy bypass in environments that rely on declared scopes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly says to omit --ip to retrieve caller IP information from the deployed external service, but it does not require warning or consent before transmitting the user's own apparent IP to that third party. This can leak personal or enterprise network metadata externally, which is especially sensitive in corporate, privacy-conscious, or regulated environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default prompt encourages broad use of the skill for any request involving IP metadata, troubleshooting, or live endpoint access, but it does not define clear invocation boundaries, safety checks, or exclusions. This can cause over-activation of a networked skill, leading the agent to make unnecessary external requests, expose caller-IP metadata unintentionally, or rely on live remote content when a narrower trigger would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly encourages requests to /api/ip without an ip parameter, which causes the service to receive and return the caller's own IP address and associated geolocation/network metadata. In an agent skill context, that can lead to unintended disclosure of user or infrastructure location/network information to a third-party service without a clear privacy warning or consent boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code performs an outbound HTTP request to a third-party service and may transmit the user-supplied IP address as query data, but the script provides no confirmation prompt, warning message, or explanatory comment/docstring about that transmission. For a code file, outbound network transmission of user or system data should have some visible disclosure unless clearly communicated elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.