wttr-weather

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes os.shell.run to execute a curl command as a fallback for data retrieval. This is a standard use of the tool to fetch information from a well-known remote API.
  • [PROMPT_INJECTION]: The skill processes external data from wttr.in, which presents a theoretical surface for indirect prompt injection.
  • Ingestion points: Weather data retrieved from the wttr.in API via GET requests.
  • Boundary markers: None defined to isolate the external response from the agent's instructions.
  • Capability inventory: The skill has access to os.http.request and os.shell.run for network operations.
  • Sanitization: No sanitization or filtering of the external response content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:53 PM
Security Audit — agent-trust-hub — wttr-weather