Back to skill

Security audit

Swmm Builder

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent SWMM model builder, but its generated model file can be altered by crafted input strings because some text fields are not safely constrained for the SWMM INP format.

Review before installing if you may process untrusted model inputs. Use it only in a constrained workspace, choose output paths deliberately, and treat generated INP files from third-party inputs as untrusted until the builder adds target-format string validation for titles, identifiers, and other emitted text fields.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_swmm_inp.py:720
Finding

Unescaped Input Allows SWMM INP Directive and Section Injection

Content
View full analysis
str: if value is None: raise ValueError(f"{context} missing required field '{field}'") text = str(value).strip() if not text: raise ValueError(f"{context} field '{field}' must be a non-blank string") return text ``` The configuration title is also accepted without output-safety validation and emitted directly into the INP document: ```python def title_from_config(config: dict[str, Any]) -> str: return str(config.get("title") or "SWMM model generated by swmm-builder") ``` ```python def emit_title(title: str) -> list[str]: return ["[TITLE]", title] ``` Other attacker-controlled textual fields are similarly interpolated directly into structured SWMM rows: ```python def emit_subcatchments( subcatchments: dict[str, dict[str, Any]], params_subcatchments: dict[str, dict[str, Any]], *, default_gage_id: str, ) -> list[str]: lines = [ "[SUBCATCHMENTS]", ";;Name Rain Gage Outlet Area %Imperv Width %Slope CurbLen SnowPack", ] for subcatchment_id in sorted(subcatchments): sc = subcatchments[subcatchment_id] p = params_subcatchments[subcatchment_id] rain_gage = sc.get("rain_gage") or default_gage_id lines.append( f"{subcatchment_id:<18} {rain_gage:<18} {sc['outlet']:<18} " f"{format_num(sc['area_ha'] ...[truncated 3683 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes deterministic file reading and writing of multiple user-supplied paths, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this can lead to over-broad file system access, making path misuse, unintended overwrites, or reading sensitive local files more likely if the wrapper or caller does not enforce strict constraints.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

Pass --water-quality-json <path> to enable pollutant buildup/washoff simulation. The JSON must satisfy the schema in skills/swmm-water-quality/SKILL.md. Omit the flag for pure hydrology runs (Water Quality: NO in the INP).

bash

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code writes two output files: the generated INP and a manifest JSON. Although the CLI argument names imply output destinations, the script itself provides no confirmation prompt, explicit warning comment, or user-facing notice before performing these writes, which matches the missing-warning criterion for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.