Back to skill

Security audit

TomTom Traffic Commute

Security checks for vulnerabilities and agentic risk

Overview

This commute helper is mostly coherent, but it should be reviewed because crafted route or email inputs can trigger local code execution in its shell scripts.

Install only if you are comfortable sending route coordinates to TomTom and, if using the example, commute details to AgentMail. Do not pass untrusted departure times, route names, or recipient values to these scripts until the python3 -c interpolation bugs are fixed and python3 plus optional AgentMail requirements are declared clearly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/tomtom-traffic.sh:34
Finding

Arbitrary Python Code Execution Through the Departure-Time Argument

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
examples/commute-email.sh:36
Finding

Arbitrary Python Code Execution Through Email Workflow Inputs

Content
View full analysis
/dev/null)" fi ``` ### Technical Analysis `ORIGIN_NAME`, `DEST_NAME`, and `COMMUTE_TO` are expanded by the shell directly into a Python program supplied to `python3 -c`. These values are treated as source code rather than data: - Route names are inserted into a triple-quoted formatted string. - Route names are also inserted into single-quoted Python literals. - `COMMUTE_TO` is inserted into a single-quoted Python literal. An input containing the relevant quote delimiter can terminate the intended literal and append Python statements. In particular, a malicious `COMMUTE_TO` value can break out of the assignment: ```python commute_to = '$COMMUTE_TO' ``` A value shaped like the following illustrates the injection boundary: ```text '; __import__('os').system('id'); # ``` Because the generated program is executed locall ...[truncated 1471 chars]
Remediation
View remediation
/dev/null`; report failures without exposing credentials. 4. Check both Python and `curl` exit statuses and stop on failed payload generation or HTTP errors. 5. Add tests using single quotes, triple quotes, newlines, backslashes, and Unicode input. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill description centers on TomTom traffic lookups, but the markdown also promotes an email automation workflow using AgentMail, which introduces an additional outbound service and data flow not reflected in the primary description or permissions. This mismatch can mislead users about what the skill may do, reducing informed consent and increasing the chance of unintended data sharing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares environment, network, and shell capabilities but does not explicitly scope or document tool permissions. This weakens least-privilege controls and makes it harder for users or reviewers to understand what execution and external access the skill requires before running it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation does not clearly warn users that origin/destination coordinates and an API-key-authenticated request are sent to TomTom. Location data can be sensitive, and failing to disclose this external transmission undermines privacy expectations and informed use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example adds outbound email delivery capability that is not part of the core stated traffic/ETA lookup function. Even though it is documented as optional, it introduces data exfiltration and messaging behavior that broadens the skill's effective capabilities and could be misused in agent contexts that only expected route lookup.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script uses a third-party email service unrelated to the primary traffic-query purpose, creating an additional outbound channel for user-supplied and derived data. In a skill ecosystem, this mismatch between declared purpose and implemented behavior increases the risk of unexpected data handling and abuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The hardcoded AgentMail endpoint indicates intentional communication with a separate external service, which expands the trust boundary and handling of commute/location data. In a skill advertised for traffic information, this additional transmission path is more dangerous because users may not expect their route details to be forwarded to another provider.

Content

Scanner excerpt · examples/commute-email.sh (reported line 37)May include surrounding context.

sh
# Optionally send email if AgentMail is configured
if [ -n "$AGENTMAIL_API_KEY" ] && [ -n "$AGENTMAIL_INBOX" ] && [ -n "$COMMUTE_TO" ]; then
  curl -s -X POST "https://api.agentmail.to/v0/inboxes/${AGENTMAIL_INBOX}/messages/send" \
    -H "Authorization: Bearer $AGENTMAIL_API_KEY" \
    -H "Content-Type: application/json" \
    -d "$(python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The hardcoded AgentMail endpoint indicates intentional communication with a separate external service, which expands the trust boundary and handling of commute/location data. In a skill advertised for traffic information, this additional transmission path is more dangerous because users may not expect their route details to be forwarded to another provider.

Content

Scanner excerpt · examples/commute-email.sh (reported line 37)May include surrounding context.

sh
# Optionally send email if AgentMail is configured
if [ -n "$AGENTMAIL_API_KEY" ] && [ -n "$AGENTMAIL_INBOX" ] && [ -n "$COMMUTE_TO" ]; then
  curl -s -X POST "https://api.agentmail.to/v0/inboxes/${AGENTMAIL_INBOX}/messages/send" \
    -H "Authorization: Bearer $AGENTMAIL_API_KEY" \
    -H "Content-Type: application/json" \
    -d "$(python3 -c "

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
DEPART_PARAM="&departAt=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEPARTURE', safe=''))")"
fi

URL="https://api.tomtom.com/routing/1/calculateRoute/${ORIGIN}:${DEST}/json?key=${API_KEY}&traffic=true&routeType=fastest${DEPART_PARAM}"

RESPONSE=$(curl -s "$URL")

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tomtom-traffic.sh (reported line 39)May include surrounding context.

sh
DEPART_PARAM="&departAt=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEPARTURE', safe=''))")"
fi

URL="https://api.tomtom.com/routing/1/calculateRoute/${ORIGIN}:${DEST}/json?key=${API_KEY}&traffic=true&routeType=fastest${DEPART_PARAM}"

RESPONSE=$(curl -s "$URL")

Static analysis

No suspicious patterns detected.