T09 · Insecure Skill Coding Practices
- Location
scripts/tomtom-traffic.sh:34- Finding
Arbitrary Python Code Execution Through the Departure-Time Argument
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This commute helper is mostly coherent, but it should be reviewed because crafted route or email inputs can trigger local code execution in its shell scripts.
Install only if you are comfortable sending route coordinates to TomTom and, if using the example, commute details to AgentMail. Do not pass untrusted departure times, route names, or recipient values to these scripts until the python3 -c interpolation bugs are fixed and python3 plus optional AgentMail requirements are declared clearly.
scripts/tomtom-traffic.sh:34Arbitrary Python Code Execution Through the Departure-Time Argument
examples/commute-email.sh:36Arbitrary Python Code Execution Through Email Workflow Inputs
The skill description centers on TomTom traffic lookups, but the markdown also promotes an email automation workflow using AgentMail, which introduces an additional outbound service and data flow not reflected in the primary description or permissions. This mismatch can mislead users about what the skill may do, reducing informed consent and increasing the chance of unintended data sharing.
The skill declares environment, network, and shell capabilities but does not explicitly scope or document tool permissions. This weakens least-privilege controls and makes it harder for users or reviewers to understand what execution and external access the skill requires before running it.
The documentation does not clearly warn users that origin/destination coordinates and an API-key-authenticated request are sent to TomTom. Location data can be sensitive, and failing to disclose this external transmission undermines privacy expectations and informed use.
The example adds outbound email delivery capability that is not part of the core stated traffic/ETA lookup function. Even though it is documented as optional, it introduces data exfiltration and messaging behavior that broadens the skill's effective capabilities and could be misused in agent contexts that only expected route lookup.
The script uses a third-party email service unrelated to the primary traffic-query purpose, creating an additional outbound channel for user-supplied and derived data. In a skill ecosystem, this mismatch between declared purpose and implemented behavior increases the risk of unexpected data handling and abuse.
The hardcoded AgentMail endpoint indicates intentional communication with a separate external service, which expands the trust boundary and handling of commute/location data. In a skill advertised for traffic information, this additional transmission path is more dangerous because users may not expect their route details to be forwarded to another provider.
# Optionally send email if AgentMail is configured
if [ -n "$AGENTMAIL_API_KEY" ] && [ -n "$AGENTMAIL_INBOX" ] && [ -n "$COMMUTE_TO" ]; then
curl -s -X POST "https://api.agentmail.to/v0/inboxes/${AGENTMAIL_INBOX}/messages/send" \
-H "Authorization: Bearer $AGENTMAIL_API_KEY" \
-H "Content-Type: application/json" \
-d "$(python3 -c "
The hardcoded AgentMail endpoint indicates intentional communication with a separate external service, which expands the trust boundary and handling of commute/location data. In a skill advertised for traffic information, this additional transmission path is more dangerous because users may not expect their route details to be forwarded to another provider.
# Optionally send email if AgentMail is configured
if [ -n "$AGENTMAIL_API_KEY" ] && [ -n "$AGENTMAIL_INBOX" ] && [ -n "$COMMUTE_TO" ]; then
curl -s -X POST "https://api.agentmail.to/v0/inboxes/${AGENTMAIL_INBOX}/messages/send" \
-H "Authorization: Bearer $AGENTMAIL_API_KEY" \
-H "Content-Type: application/json" \
-d "$(python3 -c "
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEPART_PARAM="&departAt=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEPARTURE', safe=''))")"
fi
URL="https://api.tomtom.com/routing/1/calculateRoute/${ORIGIN}:${DEST}/json?key=${API_KEY}&traffic=true&routeType=fastest${DEPART_PARAM}"
RESPONSE=$(curl -s "$URL")
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
DEPART_PARAM="&departAt=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEPARTURE', safe=''))")"
fi
URL="https://api.tomtom.com/routing/1/calculateRoute/${ORIGIN}:${DEST}/json?key=${API_KEY}&traffic=true&routeType=fastest${DEPART_PARAM}"
RESPONSE=$(curl -s "$URL")
No suspicious patterns detected.