Back to skill

Security audit

Swmm Plot

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a SWMM plotting helper that reads model/run files and writes PNG figures, with no evidence of hidden execution, exfiltration, or persistence.

Install this only if you expect an agent to read SWMM run/model files and write plot PNGs. Review the separate Agentic SWMM toolchain before installing it, since this skill depends on that project but does not bundle or audit the full external runtime here.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose says the skill is for rainfall-runoff plotting, but the behavior described also includes network mapping and other spatial artifact handling that are outside that scope. Description-behavior drift is dangerous because agents and users may approve or invoke the skill under false assumptions, enabling unintended file access, tool execution, or outputs that were not risk-assessed for this skill's stated purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill exposes file-reading behavior over run directories and explicit input/output paths but does not declare any tool scope such as permissions or allowed-tools. In an agent setting, missing scope boundaries can let the model invoke broader file access than users expect, increasing the chance of unintended data exposure from local paths or neighboring project files.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Marking inspection behavior as auto-approved under a QUICK permission profile reduces human review for filesystem reads. Even if the tool is described as read-only, automatic approval can still expose sensitive model files, directory contents, or path-based information if an agent is induced to inspect attacker-chosen or overly broad locations.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
This skill backs three LLM-facing tools. `plot_rain_runoff_si` is routed through the MCP server; `inspect_plot_options` and `map_run` are direct Python handlers in the tool registry (`agentic_swmm/agent/tool_handlers/swmm_plot.py` and `swmm_map.py`).

1. **`inspect_plot_options`** — inspect a run directory (or an explicit `.inp` / `.out` path) and return the available rainfall series names, node IDs, and node output attributes. Call this before `plot_run` so you can pass real names instead of placeholders. Required args: `run_dir` (or `inp_path` + `out_file`). Read-only; auto-approved under the QUICK permission profile.

2. **`map_run`** — render the spatial network layout (subcatchments + conduits + outfalls) as a PNG. Reads the INP from the run directory automatically; pass `inp` to override. Required arg: `run_dir`. Optional: `out_png`, `dpi`, `no_subcatchments`, `no_vertices`.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes the skill as producing paired rainfall and node-flow time-series figures from SWMM .inp + .out files, with strict hydrograph styling. This file instead renders a spatial network map from INP/geoparquet geometry, which is a distinct figure type and data flow not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly states "SI units only," which is a natural-language constraint on output format and measurement locale. The file does not offer opt-in/choice for alternative unit conventions or explain that the tool is intentionally region- or standards-specific beyond a general publication-style preference.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill around generating rainfall-runoff figures from a SWMM .inp + .out pair, optionally cropped to events or days. This script's preferred path consumes nodes/edges/subcatchments geoparquet files and does not use SWMM .out data at all, which expands the described inputs and behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.