Back to skill

Security audit

Daily Geopolitical TikTok Reporter

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to fetch public news feeds and draft local TikTok scripts, with disclosed but avoidable risks around dependency installation, scheduling, and one insecure HTTP feed.

Install this in a virtual environment, avoid the system-wide install option, and do not enable cron/systemd/Heartbeat scheduling unless you intentionally want automatic daily runs. Review generated scripts carefully before posting, especially because one feed uses HTTP and the generator uses attention-grabbing wording rather than independent fact verification.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
news_gathering/fetch_news.py:17
Finding

Plaintext HTTP RSS Feed Allows News Content Tampering

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Dependencies and Unsafe System-Wide Installation Guidance

Content
View full analysis
=6.0.0 pyyaml>=6.0 python-dateutil>=2.8.0 requests>=2.28.0 ``` The README also recommends installation methods that do not constrain package versions and may modify a system-managed Python environment: ```bash # Option A: Using virtual environment (recommended) python3 -m venv venv source venv/bin/activate pip install -r requirements.txt # Option B: System-wide (if allowed) pip install --break-system-packages -r requirements.txt # Option C: Using pipx pipx install feedparser pyyaml python-dateutil requests ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. Consequently, installation can resolve to arbitrary future versions that were not present during review. No lock file or package hashes are provided to establish a reproducible, integrity-checked dependency set. The `pipx` command omits version constraints entirely. The `--break-system-packages` option bypasses protections designed to prevent `pip` from modifying an externally managed Python environment. This can create package conflicts or alter software used by other applications on the host. The reviewed package names appear conventional, and no dependency-confusion or typosquatting package was identified. The confirmed issue is therefore unsafe and non-reproducible dependency management rather than evidence that a currently listed dependency is malicious. ### Attack Path 1. A user follows one of the documented installation commands. 2. The package resolver queries the configured Python package index. 3. Because no exact versions or hashes are required, it selects the newest release satisfying each open-ended constraint. 4. A compromised, malicious, or incompatible future pack ...[truncated 922 chars]
Remediation
View remediation
PyYAML== python-dateutil== requests== ``` 2. Generate and commit a lock file containing the complete transitive dependency graph. 3. Use hash-verified installation, such as a requirements file generated with hashes and installed using: ```bash pip install --require-hashes -r requirements.txt ``` 4. Retain virtual-environment installation as the supported approach. 5. Remove the `pip install --break-system-packages` recommendation. 6. If `pipx` remains documented, install the project as a properly packaged application with reviewed version constraints rather than installing each dependency independently. 7. Introduce routine dependency vulnerability scanning and a controlled process for reviewing and updating pinned versions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code aligns with the 'free news sources' and 'last 24 hours geopolitical developments' parts of the description, but its actual function is limited to collecting and ranking news articles from RSS feeds. It does not generate daily TikTok scripts, captions, hooks, or formatted content for TikTok. This is a material primary-purpose mismatch: the declared description promises script generation, while the supplied code chunk only performs upstream news ingestion and relevance analysis.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 74)May include surrounding context.

Using Cron (Linux/macOS):

bash
# Edit crontab
crontab -e

# Add this line (runs every day at 8 AM UTC)
0 8 * * * cd /path/to/skill && python3 generate_daily_report.py --scripts 3

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 82)May include surrounding context.

Using Systemd Timer (Linux):

bash
# Create service file at /etc/systemd/system/geo-tiktok.service
# See config/config.yaml for example

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill references editable configuration and template files, which implies file-write capability, but it does not declare any tool scope or permissions boundaries. Undeclared write capability is dangerous because an agent or reviewer cannot accurately determine what the skill may modify, increasing the risk of unintended file changes or abuse if the skill is invoked in a broader environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation language is broad enough to match many ordinary summarization, news, or content-creation requests, which can cause over-triggering. Over-broad invocation is dangerous because it can make the agent apply this skill in situations the user did not intend, potentially pulling in geopolitics-focused framing, configuration behavior, or external-source assumptions unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example trigger phrase 'Generate today's geopolitical TikTok scripts' is generic and lacks invocation constraints, which reinforces accidental or overly broad activation. In an agent ecosystem, loose trigger phrases can cause the wrong skill to be selected for routine content requests, leading to unintended behavior and increasing the attack surface for prompt-routing mistakes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code invokes a news gatherer to fetch content from external sources, which is a network operation covered by the missing-warning rule for code files. Although the script prints progress messages, it does not explicitly disclose that it will contact external services or potentially transmit request metadata, and no warning is present in the function docstring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The hardcoded hooks use sensationalized and overly certain phrasing such as 'This changes everything' and 'You won't believe this', which can systematically frame fast-moving geopolitical events in a misleading, manipulative way. In this skill's context, the risk is elevated because it transforms real-world news about conflicts and diplomacy into short-form content where nuance is already constrained, increasing the chance of misinformation, hype, or trust erosion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill fetches an RSS feed over plain HTTP from the BBC source, which allows a man-in-the-middle to tamper with news content in transit. In this skill’s context, untrusted or modified headlines/descriptions could silently influence generated geopolitical scripts, causing misinformation or manipulation even though there is no direct code-execution path.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency is specified with a minimum version only, which allows future installs to resolve to different versions over time. This weakens build reproducibility and makes it harder to verify whether known-vulnerable or breaking releases could be introduced into the skill's environment.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0

Unverifiable Dependency: feedparser has 10 known advisory(ies) (CVE-2011-1157 (feedparser Cross-site Scripting vulnerability); CVE-2009-5065 (feedparser Cross-site Scripting vulnerability); CVE-2011-1158 (feedparser Cross-site Scripting vulnerability) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Feedparser has multiple historical advisories, and because the manifest does not pin a version, it is impossible to verify from this file whether the deployed release is affected. This creates audit ambiguity and could allow vulnerable versions to be installed in some environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using an unpinned PyYAML version means installations may pull in different releases depending on timing and resolver behavior. Because PyYAML has had past security issues, lack of version pinning reduces confidence that only reviewed, non-vulnerable versions will be deployed.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

PyYAML has a history of serious issues including unsafe deserialization-related flaws, and the unpinned requirement prevents verification that a safe release is used. If the skill later processes untrusted YAML, an affected version could materially increase exploitation risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The python-dateutil package is not pinned to an exact version, so deployments are not deterministic. While not inherently exploitable by itself, this practice increases supply-chain risk and complicates auditing and incident response.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Requests is declared with only a lower bound, so future installs may fetch newer releases that have not been reviewed for this skill. In a network-facing skill that pulls external news sources, this increases supply-chain uncertainty and can expose the environment to dependency regressions or known package flaws.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
feedparser>=6.0.0
pyyaml>=6.0
python-dateutil>=2.8.0
requests>=2.28.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Requests has multiple published advisories, and the manifest does not establish which exact version will be installed. Since this skill consumes external news sources over the network, unverifiable requests versions are more concerning because network-facing libraries are directly exposed to hostile inputs and malicious URLs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.