Back to skill

Security audit

Weather Fetch

Security checks for vulnerabilities and agentic risk

Overview

This is a small weather-scraping skill, but it loads remote web content in Chromium with the browser sandbox disabled and overstates its city coverage.

Review before installing. The skill appears intended to fetch Chinese weather data and does not show exfiltration or persistence, but it should be run in a contained, low-privilege environment because it disables Chromium's sandbox while visiting a remote site. Also expect it to work only for the two hardcoded cities unless the city list is expanded.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/weather_fetch.py:18
Finding

Chromium Sandbox Explicitly Disabled for Remote Content

Content
View full analysis

Vulnerability Details

File Location: scripts/weather_fetch.py:18
Vulnerability Type: Browser sandbox disabled
Risk Level: Medium

Complete Code Snippet:

python
with sync_playwright() as p:
    browser = p.chromium.launch(headless=True, args=['--no-sandbox'])
    context = browser.new_context(user_agent='Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15')
    page = context.new_page()
    page.goto(url, timeout=30000)
    page.wait_for_timeout(5000)

Technical Analysis

The skill launches Chromium with the --no-sandbox argument and then navigates it to a remotely controlled web page. Chromium's sandbox is a defense-in-depth boundary intended to contain a compromised renderer or related browser process. Disabling it does not itself create a browser exploit, but it materially weakens containment if the remote website, one of its included resources, or the network response supplies content that exploits a vulnerability in the installed Chromium version.

HTTPS protects the connection in transit but does not protect against compromise of the destination service or malicious third-party content loaded by that service. The code therefore processes untrusted remote content without Chromium's normal process sandbox.

Attack Path

  1. An attacker compromises m.weathercn.com, influences a resource loaded by the page, or otherwise causes the destination to serve malicious browser content.
  2. The user invokes the weather skill.
  3. Playwright launches Chromium with --no-sandbox.
  4. Chromium loads and processes the attacker-controlled content.
  5. The content exploits a compatible Chromium vulnerability.
  6. Because the browser sandbox is disabled, the exploit has fewer isolation boundaries to overcome and may execute with the privileges of the account running the skill.

This path requires a separate browser vulnerability and attacker control over content processed ...[truncated 674 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the --no-sandbox argument and allow Chromium to use its default sandbox:

    python
    browser = p.chromium.launch(headless=True)
    
  2. Run the skill as a dedicated, non-privileged operating-system user with access only to resources required for the weather query.

  3. Keep Playwright and its managed Chromium build updated with current security patches.

  4. Apply additional operating-system or container isolation, including a read-only filesystem where practical, restricted mounts, dropped Linux capabilities, and outbound network access limited to the required weather host.

  5. Avoid running the skill as root. If the deployment environment currently requires --no-sandbox, correct the container or host configuration instead of disabling this security boundary.

  6. Consider validating the final navigation origin and blocking unnecessary third-party requests to reduce exposure to untrusted remote resources.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码的核心功能确实是抓取天气数据,因此与声明的大方向基本一致,没有发现额外的可疑能力或无关行为。但声明中“支持全国城市”与实现明显不符:城市列表被硬编码为仅两个条目,其他城市会直接返回“未知城市”。此外,声明提到 weathercn.com,而代码访问的是 m.weathercn.com,属于资源范围上的轻微不一致。综合看,这是一个描述夸大覆盖范围的功能性不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request URL explicitly forces the Chinese locale path (/zh/cn/), and the rest of the parsing logic assumes Chinese text patterns. This imposes a specific language/locale behavior on users without offering a choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill title and all usage instructions are presented only in Chinese, including the required city-name input examples. This creates a natural-language locale constraint without any opt-in, alternative language option, or explicit justification that the skill is intentionally Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and main heading/body present the skill entirely as a China-specific, Chinese-language tool without indicating that this locale constraint is optional or user-selectable. The policy requires flagging language or locale constraints when they are imposed without user opt-in or explicit justification as a region-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.