Back to skill

Security audit

weather-cn-pro

Security checks for vulnerabilities and agentic risk

Overview

This China weather skill mostly matches its stated purpose, but its shell script unsafely evaluates data parsed from a remote weather page, which could allow command execution if that page or connection is compromised.

Review before installing. The main concern is not ordinary weather lookup; it is that the script uses eval on data parsed from a remote web page. Install only if you are comfortable fixing or accepting that command-execution risk. The dormant AQI function should also be documented or removed before broader use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
weather-cn-pro.sh:169
Finding

Remote Command Injection Through Unsafe Evaluation of Weather Data

Content
View full analysis
[^<]*' | sed 's///' | sed 's/天气预报.*//' | head -1) fi rm -f "$tmpfile" echo "WEATHER=${weather:-未知}" echo "TEMP=${temp:-未知}" ``` The serialized values are subsequently evaluated as Bash code: ```bash format_output() { local city="$1" shift local data="$@" eval "$data" ``` ### Technical Analysis The script downloads HTML from `www.weather.com.cn` and treats that response as untrusted weather data. If the primary weather extraction does not produce a value, lines 61–62 obtain the weather description from the remote page's `<title>` element. The extracted title is not constrained to a safe weather-value character set. It is serialized into a string resembling a shell assignment: ```bash WEATHER=<remote value> ``` `main` combines this string with lifestyle data and passes it to `format_output`. Line 169 executes the resulting text with `eval`, causing Bash to parse shell metacharacters, command substitutions, variable expansions, and control operators in the remote value. For example, a malicious title containing a command substitution such as `$(attacker_command)` can survive extraction and be embedded into the `WEATHER` assignment. When `eval` parses that assignment, the command substitution is executed. HTTPS reduces ordinary network interception risk but does not make remote content safe to evaluate; exploitation remains possible through an upstream compromise, maliciously altered response, DNS/TLS trust compromise, or another mechanism capable of influencing the downloaded page. ### Attack Path 1. The attacker gains the ability to influence the HTML returned for the requested weather page. 2. The attacker provides ...[truncated 1458 chars]
Remediation
View remediation
` for later evaluation. 4. **Validate all remotely derived values.** Restrict weather descriptions and temperatures to the formats actually required by the application. Prefer an explicit allowlist of expected weather terms. Reject or replace values containing shell metacharacters, control characters, or unexpected newlines. Validation is defense in depth and is not a substitute for removing `eval`. 5. **Treat every HTTP response as attacker-controlled.** Continue using HTTPS, add `curl --fail --show-error`, validate response size and content type where practical, and fail safely when the response does not match the expected format. 6. **Add regression tests.** Test title values containing command substitutions, semicolons, quotes, backticks, newlines, and redirection operators, and verify that they are displayed only as inert text and never executed. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented purpose is weather lookup, but the analysis indicates additional undeclared behavior including AQI queries, third-party interface access, and dependence on local mapping files while permissions remain empty. Undeclared network and data-access behavior is dangerous because it prevents informed consent, weakens sandbox policy enforcement, and can conceal broader external communications than users expect from the description alone.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-based execution requirements via metadata (curl, grep) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates a trust and policy gap: a reviewer or execution framework cannot tell from the declared policy that the skill needs command execution and network-capable utilities, which can lead to overbroad or implicit execution of shell actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language content of the skill is consistently presented in Chinese, including the description, usage, and examples. Under the policy, forcing a specific language without user opt-in can be a language/locale policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file header says the enhanced version includes realtime weather, AQI, hourly forecast, and 7-day forecast. However, get_aqi() is defined but never invoked from main(), and format_output() contains no AQI display, so the documented capability contradicts actual behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script description and all user-facing messages are exclusively in Chinese, indicating a fixed language/locale experience without any opt-in or explanation that the tool is intentionally region-specific. The policy allows locale constraints when they are clearly documented and justified, but this file does not explicitly state that the skill is limited to Chinese-speaking users or China-specific weather use cases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes an enhanced China Weather Network skill focused on realtime weather, hourly forecast, 7-day forecast, and lifestyle indices. This code adds a separate capability to query AQI data from api.aooi.com, which is not mentioned in the manifest description and expands data sourcing beyond the stated scope.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · weather-cn-pro.sh (reported line 142)May include surrounding context.

sh
get_aqi() {
    local city="$1"
    # 尝试多个AQI接口
    local aqi_data=$(curl -s --max-time 5 "https://api.aooi.com/weather/index?city=${city}" 2>/dev/null)
    if [ -n "$aqi_data" ]; then
        echo "$aqi_data" | grep -oE '"aqi":[0-9]+|"level":"[^"]+"' | head -2
    else

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script sends the user-supplied city name to a third-party AQI API via curl, but there is no visible print/log message, prompt, or explanatory comment warning the user that their input will be transmitted off-device. For code files, network calls that transmit user data should have some form of disclosure unless clearly covered by the skill's stated purpose; the AQI third-party fallback is not surfaced to the user in output or usage text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file header and data are entirely in Chinese, which establishes a fixed language/locale context without any visible opt-in, alternative language support, or documented regional justification. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.