T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fetch_news.py:29- Finding
Server-Side Request Forgery Through Untrusted Article URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real news aggregator, but its deep-fetch mode can make the agent visit arbitrary links and use untrusted web content without enough safeguards.
Install only if you are comfortable with a news skill that performs broad outbound scraping, browser automation, local report writes, and deep fetching of links from third-party feeds. Prefer running it in a restricted network environment, avoid deep-fetch mode on untrusted sources, pin dependencies, and review generated reports as untrusted web-derived content.
scripts/fetch_news.py:29Server-Side Request Forgery Through Untrusted Article URLs
scripts/rss_parser.py:7TLS Certificate Verification Disabled for RSS Downloads
scripts/fetch_news.py:84News and Feed Data Retrieved Over Plaintext HTTP
scripts/fetch_news.py:29Untrusted Web Content Is Passed to the Agent Without Prompt-Injection Isolation
requirements.txt:1Unpinned Dependencies and Mutable Remote Installation Sources
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This mismatch is substantiated by the SKILL.md itself: it directs saving reports to disk and includes essay/blog aggregation, while the short description focuses on news aggregation and does not disclose local persistence. Undisclosed storage and materially different content scope can cause users and policy layers to underestimate privacy, retention, and operational risk.
This skill launches auxiliary scripts to fetch content, which exceeds the minimal behavior expected from a news reader and increases the trusted code base. If those helper scripts are modified, replaced, or contain insecure browser automation, the main skill becomes a launcher for additional code with network and local access.
The Playwright fallback path introduces browser automation via subprocess for feed retrieval, which materially broadens the skill's capabilities beyond simple HTTP/RSS aggregation. In a skill context, this raises risk because automated browsing can execute complex page logic, touch more endpoints, and rely on unreviewed helper scripts without user awareness.
The README explicitly advertises Deep Fetch that uses Playwright to bypass anti-bot protections and retrieve full article content, but does not disclose the resulting automated browsing, external requests, or privacy and compliance implications. In an agent setting, this can lead users to trigger stealthy outbound network activity against third-party sites without informed consent, potentially exposing identifiers, cookies, or organizational traffic patterns.
The README instructs users to run npx skills add without pinning a specific package version or commit, which can cause installation of whatever version is currently served at execution time. In an agent-skill context, that creates a supply-chain risk: a compromised or maliciously updated package or installer path could execute unexpected code during installation.
The skill explicitly instructs use of shell commands, network fetching, file reads, and file writes, but it declares no tool scope or permission boundaries. That creates an over-privileged skill surface where an agent may invoke sensitive capabilities without an explicit allowlist or user-visible constraint, increasing the risk of unintended command execution, data exfiltration, or persistent local writes.
Very broad trigger phrases like 'tech news', 'finance updates', 'deep analysis', and menu-related terms can cause accidental invocation in unrelated conversations. Because the skill also performs network access and local file writes, unintended activation can lead to unnecessary external requests, persistence of generated content, and surprising side effects.
The skill advertises real-time fetching and optional deep downloads but does not clearly warn users that it will access external network resources and retrieve third-party content. Hidden network activity can create privacy, compliance, and trust issues, especially if requests include user-supplied keywords or occur in restricted environments.
The file instructs translation of all content to Simplified Chinese and later states that ALL output must be in Simplified Chinese. This forces a specific language/locale without user opt-in, which matches the policy's language/locale violation criteria.
The skill mandates saving generated reports to local storage but does not warn the user that their content will be persisted on disk. This can expose sensitive prompts, fetched content, or generated analysis to later access by other local users, processes, backups, or logs, especially when the user expects an ephemeral response.
The rule "ALL output in Simplified Chinese" imposes a language requirement across all uses of the skill. Because the file does not provide an opt-in choice or a clear region-specific justification, this is a natural-language policy violation.
The 'menu/help' trigger is especially ambiguous because those words commonly appear in ordinary support interactions. In a skill that can read files, run scripts, fetch network content, and write reports, accidental invocation raises the risk of unrequested actions and privacy-impacting side effects.
The plan adds scheduled execution through crontab, which expands the skill from an on-demand news tool into a persistent system-level automation. Even though the purpose is operationally related to news collection, persistence and autonomous execution increase risk because the task will continue running without user initiation, can repeatedly access network resources, and may be modified later to perform broader actions.
The manual verification step confirms the presence of a crontab entry, which indicates session persistence via scheduled execution. In a skill context, persistence is security-relevant because it establishes behavior that survives the current interaction and can continue running without repeated user intent, increasing the blast radius of any future script change or misconfiguration.
- Verify the content of the markdown file is readable and contains news from multiple sources.
### Manual Verification
- Check `crontab -l` after installation to confirm the job is listed.
The report format requires every item to use "[Title (Translated)]", which imposes a language/localization behavior in the output. Because the file does not provide user opt-in or explain a justified region-specific requirement, this is a natural-language locale policy concern.
The instruction explicitly requires the summary to be written 'in Chinese', which imposes a specific language on the output. The file does not provide any opt-in, fallback, or user-selectable locale, so this is a natural-language policy concern under the language/locale rule.
The skill hard-codes Simplified Chinese as the output language, overriding user preference and reducing user agency. While not a direct code-execution or data-exfiltration issue, it can cause misleading or unusable output for users who expect another language, and it may violate product policies requiring user-controlled language selection.
The report structure requires mixed Chinese labels such as "热门项目", "核心价值", and "启发思考" in the output format. This imposes a specific language/locale style on users without stating that language choice is optional or justified, which is a natural-language policy concern.
No suspicious patterns detected.