T09 · Insecure Skill Coding Practices
- Location
scripts/weather.py:35- Finding
Weather Data Transmitted Over Unencrypted HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple weather lookup skill, but its install instructions point to a placeholder package name and its live weather request uses unencrypted HTTP.
Review before installing. The weather functionality itself is narrow, but do not follow the placeholder install command unless the publisher replaces it with a verified package name, and prefer a version that uses HTTPS for live weather lookups.
scripts/weather.py:35Weather Data Transmitted Over Unencrypted HTTP
SKILL.md:27Installation Documentation References an Unverified Placeholder Package
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
---
name: weather-query
version: 1.0.0
description: 查询全球任意城市天气,支持中文城市名
The skill includes natural-language output in Chinese in the sample weather description and later emits a Chinese-only usage error message. This imposes a specific language on users without opt-in or any documented locale constraint, which matches the language/locale policy violation criteria.
No suspicious patterns detected.