T09 · Insecure Skill Coding Practices
- Location
news_gathering/fetch_news.py:17- Finding
Plaintext HTTP RSS Feed Allows News Content Tampering
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to fetch public news feeds and draft local TikTok scripts, with disclosed but avoidable risks around dependency installation, scheduling, and one insecure HTTP feed.
Install this in a virtual environment, avoid the system-wide install option, and do not enable cron/systemd/Heartbeat scheduling unless you intentionally want automatic daily runs. Review generated scripts carefully before posting, especially because one feed uses HTTP and the generator uses attention-grabbing wording rather than independent fact verification.
news_gathering/fetch_news.py:17Plaintext HTTP RSS Feed Allows News Content Tampering
requirements.txt:1Unbounded Dependencies and Unsafe System-Wide Installation Guidance
The code aligns with the 'free news sources' and 'last 24 hours geopolitical developments' parts of the description, but its actual function is limited to collecting and ranking news articles from RSS feeds. It does not generate daily TikTok scripts, captions, hooks, or formatted content for TikTok. This is a material primary-purpose mismatch: the declared description promises script generation, while the supplied code chunk only performs upstream news ingestion and relevance analysis.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Edit crontab
crontab -e
# Add this line (runs every day at 8 AM UTC)
0 8 * * * cd /path/to/skill && python3 generate_daily_report.py --scripts 3
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Create service file at /etc/systemd/system/geo-tiktok.service
# See config/config.yaml for example
The skill references editable configuration and template files, which implies file-write capability, but it does not declare any tool scope or permissions boundaries. Undeclared write capability is dangerous because an agent or reviewer cannot accurately determine what the skill may modify, increasing the risk of unintended file changes or abuse if the skill is invoked in a broader environment.
The activation language is broad enough to match many ordinary summarization, news, or content-creation requests, which can cause over-triggering. Over-broad invocation is dangerous because it can make the agent apply this skill in situations the user did not intend, potentially pulling in geopolitics-focused framing, configuration behavior, or external-source assumptions unexpectedly.
The example trigger phrase 'Generate today's geopolitical TikTok scripts' is generic and lacks invocation constraints, which reinforces accidental or overly broad activation. In an agent ecosystem, loose trigger phrases can cause the wrong skill to be selected for routine content requests, leading to unintended behavior and increasing the attack surface for prompt-routing mistakes.
This code invokes a news gatherer to fetch content from external sources, which is a network operation covered by the missing-warning rule for code files. Although the script prints progress messages, it does not explicitly disclose that it will contact external services or potentially transmit request metadata, and no warning is present in the function docstring.
The hardcoded hooks use sensationalized and overly certain phrasing such as 'This changes everything' and 'You won't believe this', which can systematically frame fast-moving geopolitical events in a misleading, manipulative way. In this skill's context, the risk is elevated because it transforms real-world news about conflicts and diplomacy into short-form content where nuance is already constrained, increasing the chance of misinformation, hype, or trust erosion.
The skill fetches an RSS feed over plain HTTP from the BBC source, which allows a man-in-the-middle to tamper with news content in transit. In this skill’s context, untrusted or modified headlines/descriptions could silently influence generated geopolitical scripts, causing misinformation or manipulation even though there is no direct code-execution path.
The dependency is specified with a minimum version only, which allows future installs to resolve to different versions over time. This weakens build reproducibility and makes it harder to verify whether known-vulnerable or breaking releases could be introduced into the skill's environment.
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0
Feedparser has multiple historical advisories, and because the manifest does not pin a version, it is impossible to verify from this file whether the deployed release is affected. This creates audit ambiguity and could allow vulnerable versions to be installed in some environments.
Using an unpinned PyYAML version means installations may pull in different releases depending on timing and resolver behavior. Because PyYAML has had past security issues, lack of version pinning reduces confidence that only reviewed, non-vulnerable versions will be deployed.
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0
PyYAML has a history of serious issues including unsafe deserialization-related flaws, and the unpinned requirement prevents verification that a safe release is used. If the skill later processes untrusted YAML, an affected version could materially increase exploitation risk.
The python-dateutil package is not pinned to an exact version, so deployments are not deterministic. While not inherently exploitable by itself, this practice increases supply-chain risk and complicates auditing and incident response.
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0
Requests is declared with only a lower bound, so future installs may fetch newer releases that have not been reviewed for this skill. In a network-facing skill that pulls external news sources, this increases supply-chain uncertainty and can expose the environment to dependency regressions or known package flaws.
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0
Requests has multiple published advisories, and the manifest does not establish which exact version will be installed. Since this skill consumes external news sources over the network, unverifiable requests versions are more concerning because network-facing libraries are directly exposed to hostile inputs and malicious URLs.
No suspicious patterns detected.