Back to skill

Security audit

weather-cn-fixed

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese weather tool, but its shell script unsafely evaluates weather data fetched from the internet as shell code.

Review before installing. The skill does what it says, but the included bash script should be fixed to remove eval before routine use; otherwise a manipulated weather.com.cn response could execute commands as the user running the skill. Network calls are expected for weather lookup, and the optional shell alias should only be added if you want persistent convenience behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
weather-cn.sh:158
Finding

Remote Weather Response Evaluated as Shell Code

Content
View full analysis
/dev/null) ``` ```bash local weather weather=$(cat "$tmpfile" | grep -o '[^<]*' | sed 's///' | sed 's/天气预报.*//' | head -1) ``` ```bash echo "WEATHER=${weather:-未知}" echo "TEMP=${temp:-未知}" echo "COLD_INDEX=${cold_index}" echo "SPORT_INDEX=${sport_index}" echo "DRESS_INDEX=${dress_index}" echo "WASH_INDEX=${wash_index}" echo "UV_INDEX=${uv_index}" ``` ```bash local data="$@" # Parse data eval "$data" ``` ### Technical Analysis The script downloads HTML from an external weather service and extracts the contents of its HTML title into the `weather` variable. That value is subsequently serialized as a shell assignment: ```bash WEATHER=<network-controlled value> ``` The generated assignment text is passed to `eval`, which parses and executes its argument as shell code. Quoting `"$data"` when invoking `eval` does not make the contents safe because `eval` performs an additional shell-parsing pass. An attacker who can influence the returned HTML can insert shell metacharacters, command substitutions, or additional commands into the title. For example, a title value containing a command substitution could cause that command to run when the generated `WEATHER` assignment is evaluated. HTTPS limits ordinary network interception, but it does not justify evaluating the response as code. Exploitation remains possible if the upstream service is compromised, its response-generation path is manipulated, DNS or trusted-certificate infrastructure is compromised, or traffic is intercepted through a locally trusted proxy or certificate autho ...[truncated 1471 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script uses eval "$data" to deserialize weather fields, but data is derived from HTML fetched from a remote website. An attacker who can influence the upstream response, a compromised mirror, or any parsing edge case could inject shell syntax into the generated assignments and achieve arbitrary command execution in the user's shell context. In a simple weather-query tool, eval is unnecessary and materially increases risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation is entirely in Chinese and the examples, headings, and usage instructions assume Chinese-language interaction, but there is no indication that this language constraint is optional or explicitly limited to a region-specific audience. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises executable shell usage via scripts and command examples, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege and governance gap: an agent may invoke shell capabilities for this skill without a clearly documented boundary, making misuse or unintended command execution harder to control and audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description presents the skill as a Chinese weather tool and the document consistently assumes Chinese input/output, including "原生中文" messaging, but does not offer opt-in language selection. Under the stated policy, forcing a specific language without user choice can be a locale-policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

方案2:Open-Meteo API

bash
curl -s "https://api.open-meteo.com/v1/forecast?latitude=39.9042&longitude=116.4074&current_weather=true&daily=temperature_2m_max,temperature_2m_min,weathercode&timezone=Asia%2FShanghai"

方案3:wttr.in

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are very broad and overlap with ordinary conversation about weather, increasing the chance that the skill is auto-invoked when a user is merely chatting rather than requesting this specific tool. In an agent environment, over-broad activation can cause unnecessary network access and shell execution, expanding the skill's effective attack surface beyond intentional use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script description and usage text are explicitly Chinese-only, indicating the skill is intended to operate in Chinese without any user opt-in or alternative locale. This is a natural-language locale policy concern because the skill appears to force a specific language rather than offering a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This plain-text skill file contains only Chinese headings and Chinese city names, which imposes a specific language/locale on users without any opt-in or documented regional justification in the file. Under the policy rule for natural-language violations, forcing a specific language without choice can be non-compliant.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.