T09 · Insecure Skill Coding Practices
- Location
scripts/crawl_longli_weather.py:20- Finding
Weather Data Retrieved Over Unencrypted HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Longli County weather-and-clothing-advice reporter with disclosed cron use and no evidence of hidden access, exfiltration, or destructive behavior.
Install only if you want a Chinese-language Longli County weather cron report. Prefer running it in a virtual environment, consider pinning dependencies, and switch the weather endpoint to HTTPS if supported because the current HTTP source can be tampered with on the network.
scripts/crawl_longli_weather.py:20Weather Data Retrieved Over Unencrypted HTTP
SKILL.md:65Unpinned Third-Party Python Dependencies
The message template strings are all hard-coded in Chinese, which imposes a specific language on the skill's user-facing output. The file does not indicate that language is configurable or that the skill is intentionally limited to a Chinese-speaking or region-specific audience.
This Python skill is entirely written for Chinese-language interaction, including comments, docstrings, and all user-facing return strings such as the advice text. The file does not offer any language choice or document that it is intentionally limited to a Chinese-speaking or region-specific context, which creates a natural-language locale policy concern under the stated rule.
No suspicious patterns detected.