Back to skill

Security audit

gpx-kml-visualizer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it ships a real-looking precise GPS track and identifying local path metadata that users should review before installing.

Install only if you are comfortable handling GPS tracks locally and with interactive maps contacting external tile services. Treat GPX/KML/track JSON files as sensitive, avoid opening generated HTML from untrusted track JSON, and prefer an isolated Python environment with pinned dependencies. The packaged sample route should be removed or replaced with synthetic data before broader distribution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/plot_interactive.py:169
Finding

Stored HTML Injection Through Unescaped Source Filename

Content
View full analysis

🗺️ {source}

Distance: {stats['total_distance_km']:.2f} km Points: {stats['point_count']} Elev Gain: +{stats['elevation_gain_m']:.0f} m Elev Loss: -{stats['elevation_loss_m']:.0f} m Max Elev: {stats['max_elevation_m']:.0f} m Min Elev: {stats['min_elevation_m']:.0f} m Avg Elev: {stats['avg_elevation_m']:.0f} m
""" # Get the raw HTML html = m.get_root().render() # Insert stats panel after body_idx = html.find("") if body_idx != -1: insert_pos = body_idx + len("") html = html[:insert_pos] + stats_html + html[insert_pos:] ``` ### Technical Analysis The `source_file` property is read from an input JSON document and reduced to a basename, but it is not HTML-escaped. The resulting `source` value is interpolated directly into `stats_html`, which is then inserted into the generated HTML document as raw markup. `Path(...).name` does not sanitize HTML metacharacters. An attacker able to provide or modify the input JSON can use a value such as: ```json { "source_file": "

" } ``` When the generated map is opened in a browser, the inject ...[truncated 1369 chars]

Remediation
View remediation
`, `"`, `'`, `&`, closing tags, and `

other

Warning
Location
track_tianmu.json:2
Finding

Distribution of Precise Geolocation and Identifying Source-Path Metadata

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:68
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
numpy== folium== Pillow== ``` 2. Generate and verify cryptographic hashes for all direct and transitive dependencies. 3. Install with hash enforcement: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Document the trusted package index and disable unintended extra indexes that could enable dependency confusion. 5. Run dependency vulnerability and provenance scans during continuous integration. 6. Review and update pinned versions through a controlled process rather than resolving mutable latest releases during installation. 7. Recommend installation in an isolated virtual environment without administrator privileges. 8. Where practical, publish a software bill of materials covering direct and transitive dependencies. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to read user-supplied files and write generated outputs, but it does not declare any explicit tool scope or permission boundaries. That creates unnecessary ambiguity about what files may be accessed or written, increasing the risk of overbroad filesystem access if the runtime grants defaults or if downstream tooling interprets the skill permissively.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger language is broad enough to match generic requests about drawing, plotting, converting, generating HTML/JPG, or route planning, which can cause the skill to activate outside its intended GPX/KML use case. Over-triggering is risky because this skill performs file parsing and output generation, so unintended invocation could lead to unnecessary file access, confusing behavior, or misuse in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated HTML includes third-party tile servers (Esri and OpenTopoMap), so opening what appears to be a local visualization causes the viewer's browser to make external network requests. This can disclose IP address, access time, user agent, and potentially sensitive route-viewing behavior, which is risky for GPS track data that may reflect home, work, or private travel patterns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The JSON includes two classes of unnecessary sensitive data for a visualization skill: a local Windows file path that reveals personal/device context and a full set of precise GPS track points that can identify routes, habits, or home/work locations. Even if the skill is intended to render maps, retaining or exposing the raw source path and exact coordinates beyond what is minimally necessary increases privacy and re-identification risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.