T09 · Insecure Skill Coding Practices
- Location
scripts/weather.py:38- Finding
Plaintext HTTP Exposes Weather Queries and Permits Response Tampering
- Content
View full analysis
Vulnerability Details
File Location:
scripts/weather.py, line 38
Vulnerability Type: Plaintext network communication
Risk Level: MediumVulnerable Code
python url = f'http://wttr.in/{encoded_city}?format=j1'Technical Analysis
The skill sends the user-provided city name to
wttr.inover unencrypted HTTP. Because TLS is not used, network intermediaries can observe the queried location and modify the weather service response in transit.The application subsequently decodes and parses the unauthenticated response as JSON. Although broad exception handling prevents most malformed responses from terminating the process unexpectedly, it does not protect the integrity or confidentiality of the communication.
Attack Path
- A user invokes the skill in online mode with a city name.
- The skill URL-encodes the city and sends it to
http://wttr.in. - An attacker with a position on the network path intercepts the plaintext request.
- The attacker reads the queried city or modifies the returned JSON weather payload.
- The skill trusts, parses, and displays the manipulated weather data.
Impact Assessment
An attacker can learn users' location queries and manipulate displayed weather information. This does not directly grant local code execution, additional system privileges, credential access, or persistence. The affected scope is limited to the confidentiality and integrity of online weather requests and responses.
- Remediation
View remediation
Remediation Suggestions
Replace the plaintext endpoint with HTTPS:
python url = f'https://wttr.in/{encoded_city}?format=j1'Preserve Python's default TLS certificate and hostname verification. Do not install an unverified SSL context or suppress certificate errors. For additional hardening:
- Verify that the response has a successful HTTP status.
- Restrict accepted response content types to JSON.
- Limit the maximum response size before decoding.
- Validate the response schema and field types before use.
- Return a generic user-facing error while logging suitably sanitized diagnostic details.
