Back to skill

Security audit

weather-skill-yub

Security checks for vulnerabilities and agentic risk

Overview

This is a small weather lookup skill whose behavior matches its stated purpose, with a privacy/integrity caveat because online requests use plaintext HTTP.

Install only if you are comfortable sending city weather queries to wttr.in. Prefer a version that uses HTTPS for online requests, especially on untrusted networks; otherwise use the offline mode for demonstrations without network access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/weather.py:38
Finding

Plaintext HTTP Exposes Weather Queries and Permits Response Tampering

Content
View full analysis

Vulnerability Details

File Location: scripts/weather.py, line 38
Vulnerability Type: Plaintext network communication
Risk Level: Medium

Vulnerable Code

python
url = f'http://wttr.in/{encoded_city}?format=j1'

Technical Analysis

The skill sends the user-provided city name to wttr.in over unencrypted HTTP. Because TLS is not used, network intermediaries can observe the queried location and modify the weather service response in transit.

The application subsequently decodes and parses the unauthenticated response as JSON. Although broad exception handling prevents most malformed responses from terminating the process unexpectedly, it does not protect the integrity or confidentiality of the communication.

Attack Path

  1. A user invokes the skill in online mode with a city name.
  2. The skill URL-encodes the city and sends it to http://wttr.in.
  3. An attacker with a position on the network path intercepts the plaintext request.
  4. The attacker reads the queried city or modifies the returned JSON weather payload.
  5. The skill trusts, parses, and displays the manipulated weather data.

Impact Assessment

An attacker can learn users' location queries and manipulate displayed weather information. This does not directly grant local code execution, additional system privileges, credential access, or persistence. The affected scope is limited to the confidentiality and integrity of online weather requests and responses.

Remediation
View remediation

Remediation Suggestions

Replace the plaintext endpoint with HTTPS:

python
url = f'https://wttr.in/{encoded_city}?format=j1'

Preserve Python's default TLS certificate and hostname verification. Do not install an unverified SSL context or suppress certificate errors. For additional hardening:

  • Verify that the response has a successful HTTP status.
  • Restrict accepted response content types to JSON.
  • Limit the maximum response size before decoding.
  • Validate the response schema and field types before use.
  • Return a generic user-facing error while logging suitably sanitized diagnostic details.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: weather-query
version: 1.0.0
description: 查询全球任意城市天气,支持中文城市名

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The offline sample hard-codes a Chinese weather description ('晴朗'), which means user-visible output may be in Chinese regardless of user preference. This is a natural-language locale policy issue because the script does not provide any opt-in, fallback, or explanation that it is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script prints a Chinese-only usage/error message ('请提供城市名,如:python weather.py 北京') when no arguments are supplied. Because the file does not offer language selection or document a justified locale restriction, this violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.