Back to skill

Security audit

News Aggregator Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real news aggregator, but its deep-fetch mode can make the agent visit arbitrary links and use untrusted web content without enough safeguards.

Install only if you are comfortable with a news skill that performs broad outbound scraping, browser automation, local report writes, and deep fetching of links from third-party feeds. Prefer running it in a restricted network environment, avoid deep-fetch mode on untrusted sources, pin dependencies, and review generated reports as untrusted web-derived content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/fetch_news.py:29
Finding

Server-Side Request Forgery Through Untrusted Article URLs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rss_parser.py:7
Finding

TLS Certificate Verification Disabled for RSS Downloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_news.py:84
Finding

News and Feed Data Retrieved Over Plaintext HTTP

Content
View full analysis
{timestamp_24h}&hitsPerPage={limit*2}&query={requests.utils.quote(query_str)}" data = requests.get(api_url, timeout=10).json() hits = data.get('hits', []) if not hits and raw_keywords: simple_query = raw_keywords[0] api_url_simple = f"http://hn.algolia.com/api/v1/search_by_date?tags=story&numericFilters=created_at_i>{timestamp_24h}&hitsPerPage={limit*2}&query={requests.utils.quote(simple_query)}" data = requests.get(api_url_simple, timeout=10).json() ``` A plaintext feed is also configured at line 562: ```python ("Paul Graham", "http://www.aaronsw.com/2002/feeds/pgessays.rss"), ``` ### Technical Analysis HTTP provides no server authentication or transport integrity. An on-path attacker can observe or modify requests and responses without needing to compromise the source website. The Hacker News API response supplies article titles and destination URLs. The configured RSS source supplies similar security-relevant data. Modified URLs can subsequently be opened by users or fetched by the deep-enrichment workflow. Although the requests do not contain secrets, the absence of transport protection permits manipulation of the Skill’s effective input and can be chained with prompt injection or SSRF. ### Attack Path 1. A user performs a keyword-based Hacker News request or requests the plaintext RSS source. 2. An attacker intercepts the HTTP connection. 3. The attacker changes the returned title, summary, or article URL. 4. The application parses the modified content as authentic source data. 5. The forged content is included in the report. 6. If deep enrichment is active, the Agent host requests the attacker-supplied URL. 7. The attacker ca ...[truncated 574 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
scripts/fetch_news.py:29
Finding

Untrusted Web Content Is Passed to the Agent Without Prompt-Injection Isolation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Dependencies and Mutable Remote Installation Sources

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill launches auxiliary scripts to fetch content, which exceeds the minimal behavior expected from a news reader and increases the trusted code base. If those helper scripts are modified, replaced, or contain insecure browser automation, the main skill becomes a launcher for additional code with network and local access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Playwright fallback path introduces browser automation via subprocess for feed retrieval, which materially broadens the skill's capabilities beyond simple HTTP/RSS aggregation. In a skill context, this raises risk because automated browsing can execute complex page logic, touch more endpoints, and rely on unreviewed helper scripts without user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly advertises Deep Fetch that uses Playwright to bypass anti-bot protections and retrieve full article content, but does not disclose the resulting automated browsing, external requests, or privacy and compliance implications. In an agent setting, this can lead users to trigger stealthy outbound network activity against third-party sites without informed consent, potentially exposing identifiers, cookies, or organizational traffic patterns.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx skills add without pinning a specific package version or commit, which can cause installation of whatever version is currently served at execution time. In an agent-skill context, that creates a supply-chain risk: a compromised or maliciously updated package or installer path could execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs use of shell commands, network fetching, file reads, and file writes, but it declares no tool scope or permission boundaries. That creates an over-privileged skill surface where an agent may invoke sensitive capabilities without an explicit allowlist or user-visible constraint, increasing the risk of unintended command execution, data exfiltration, or persistent local writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Very broad trigger phrases like 'tech news', 'finance updates', 'deep analysis', and menu-related terms can cause accidental invocation in unrelated conversations. Because the skill also performs network access and local file writes, unintended activation can lead to unnecessary external requests, persistence of generated content, and surprising side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises real-time fetching and optional deep downloads but does not clearly warn users that it will access external network resources and retrieve third-party content. Hidden network activity can create privacy, compliance, and trust issues, especially if requests include user-supplied keywords or occur in restricted environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file instructs translation of all content to Simplified Chinese and later states that ALL output must be in Simplified Chinese. This forces a specific language/locale without user opt-in, which matches the policy's language/locale violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill mandates saving generated reports to local storage but does not warn the user that their content will be persisted on disk. This can expose sensitive prompts, fetched content, or generated analysis to later access by other local users, processes, backups, or logs, especially when the user expects an ephemeral response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The rule "ALL output in Simplified Chinese" imposes a language requirement across all uses of the skill. Because the file does not provide an opt-in choice or a clear region-specific justification, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'menu/help' trigger is especially ambiguous because those words commonly appear in ordinary support interactions. In a skill that can read files, run scripts, fetch network content, and write reports, accidental invocation raises the risk of unrequested actions and privacy-impacting side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The plan adds scheduled execution through crontab, which expands the skill from an on-demand news tool into a persistent system-level automation. Even though the purpose is operationally related to news collection, persistence and autonomous execution increase risk because the task will continue running without user initiation, can repeatedly access network resources, and may be modified later to perform broader actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The manual verification step confirms the presence of a crontab entry, which indicates session persistence via scheduled execution. In a skill context, persistence is security-relevant because it establishes behavior that survives the current interaction and can continue running without repeated user intent, increasing the blast radius of any future script change or misconfiguration.

Content

Scanner excerpt · implementation_plan.md (reported line 40)May include surrounding context.

md
- Verify the content of the markdown file is readable and contains news from multiple sources.

### Manual Verification
- Check `crontab -l` after installation to confirm the job is listed.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The report format requires every item to use "[Title (Translated)]", which imposes a language/localization behavior in the output. Because the file does not provide user opt-in or explain a justified region-specific requirement, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction explicitly requires the summary to be written 'in Chinese', which imposes a specific language on the output. The file does not provide any opt-in, fallback, or user-selectable locale, so this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes Simplified Chinese as the output language, overriding user preference and reducing user agency. While not a direct code-execution or data-exfiltration issue, it can cause misleading or unusable output for users who expect another language, and it may violate product policies requiring user-controlled language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The report structure requires mixed Chinese labels such as "热门项目", "核心价值", and "启发思考" in the output format. This imposes a specific language/locale style on users without stating that language choice is optional or justified, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.