Back to skill

Security audit

Swmm Params

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a local CSV-to-JSON SWMM parameter mapper with no hidden network, credential, persistence, or destructive behavior.

Safe to install for local SWMM parameter-table generation. Confirm paths before using the documented MCP commands, because the referenced MCP wrapper is not included in this artifact; review generated defaults before production modeling because fallback rows may mask missing land-use or soil classes unless --strict is used.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code’s core behavior is a deterministic land-use-only lookup that produces SWMM subcatchment percent imperviousness and subarea parameters such as Manning’s n, depression storage, routing, and percent routed. This aligns with part of the declared purpose around runoff/subarea parameter generation, but materially omits the declared soil texture dimension and any Green-Ampt infiltration parameter mapping. There are no evident undeclared risky capabilities or external resource accesses beyond reading CSVs and writing JSON, but the declared functional scope is broader than the implementation. Therefore this is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill performs deterministic mapping from land use and soil texture to SWMM and Green-Ampt parameters. The supplied code does not implement those mappings or derive parameters from land use/soil inputs. Instead, it consumes already-produced JSON files from other scripts, merges their sections, validates ids, records incomplete subcatchments, and writes a consolidated JSON output. While this may be part of the same workflow, the primary purpose is materially different: aggregation and validation of prior outputs rather than parameter generation itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is narrowly focused on soil-texture-to-Green-Ampt infiltration mapping. It validates CSV inputs, applies a lookup table, supports default/fallback behavior, and outputs JSON with infiltration parameters only. The declared description says it performs deterministic mapping from both land use and soil texture to SWMM runoff/subarea and Green-Ampt infiltration parameters, implying broader functionality than implemented. There is no land use input, no runoff or subarea parameter derivation, and no generation of the broader parameter set suggested by the description. No suspicious undeclared external access or unrelated behavior is present; the mismatch is due to overstated scope in the description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.