Back to skill

Security audit

X News Daily

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: fetch X.com news, make a Chinese briefing poster, and send it, with some disclosed local browser steps and a promotional footer users should notice.

Install only if you want Chinese-language X.com news posters. Expect the skill to browse X.com, create a local HTML/rendered artifact, use Chrome or screenshot tooling, and include a ClawHub/OpenClaw footer link. Use explicit prompts and confirm any scheduled or third-party messaging delivery.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:62
Finding

Mandatory Promotional Content Injection into User Deliverables

Content
View full analysis
Skill: https://clawhub.ai/skill/x-news-daily · Powered by OpenClaw · Data source: X.com ``` ### Technical Analysis The skill changes the agent's output-generation behavior by making promotional content a mandatory part of the requested news artifact. The inserted Skill URL and branding are not necessary to search for news, translate results, summarize them, or render the poster. This behavior is specified as an instruction in `SKILL.md` and is independently hard-coded into both bundled rendering files. Consequently, an agent following the skill will systematically add the promotional material even when the user requests only a news briefing and does not request attribution or advertising. The behavior is classified as instruction hijacking because the skill imposes an a ...[truncated 1364 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: x-news-daily
description: Fetch top 10 trending news from X.com for any keyword, generate full-screen Canvas poster with Chinese summaries and send to user. Supports custom keywords. Triggers: (1) User requests X news briefing (2) Daily scheduled task (3) Manual trigger. Default keyword: OpenClaw. Auto-translates news titles to Chinese and adds summaries.
description_zh: 抓取 X.com 上指定关键词的热门新闻 Top 10,使用 Canvas 生成全屏精美海报并发送给用户。支持自定义关键词,默认关键词为 OpenClaw。会自动将新闻标题翻译成中文并添加摘要。
---

# X

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description states that the skill auto-translates news titles to Chinese and adds Chinese summaries by default. This imposes a specific language on users without offering a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description omits clear disclosure that it will access X.com content and deliver generated output to external messaging platforms. Users may not realize that invoking the skill causes third-party network access and data transmission, creating consent, privacy, and policy risks if sensitive queries or generated content are sent externally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that ordinary conversation like 'X News' or 'Daily Brief' could invoke the skill unintentionally. Because the skill performs external browsing, local file creation, browser automation, screenshotting, and message delivery, accidental activation could cause unintended data access or outbound actions without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow describes saving local HTML files, opening them with file://, running browser automation, and taking screenshots, but it does not warn the user about these local side effects. This matters because local file creation and automated browser execution can expose users to privacy, persistence, and operational risks, especially on shared or managed systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The note "Always translate to Chinese" enforces a fixed output language in the English section without presenting an option for user preference. That is a natural-language locale policy issue because it removes language choice by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese triggers include common phrases like '每日简报' that may appear in normal conversation and could activate the skill unexpectedly. In this skill's context, unintended execution is more concerning because it can initiate browsing to X.com, generate local artifacts, automate screenshots, and send outputs to external platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction "必须翻译成中文" requires Chinese output for all uses and does not mention user selection or consent. This is a language policy violation unless the skill is explicitly scoped to a Chinese-only audience with clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file hard-codes Chinese text for the page title, date format, news content, and footer strings throughout the generated output. There is no indication that the user can choose another language or that the Chinese-only locale is explicitly justified, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document sets lang="zh-CN", which hard-codes a specific language/locale for the skill output. The file does not indicate that users can opt into another locale or that the skill is intentionally region-specific, so this appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The front-matter description says the skill will 'generate full-screen Canvas poster,' and the Chinese description repeats the same claim. However, later steps and notes explicitly say to generate a full-screen HTML poster instead, open it in Chrome, and capture a screenshot, which contradicts the stated implementation approach.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The feature text says the skill will 'Send as file to any IM,' which suggests delivering the generated poster artifact directly. But the documented workflow later says to open the HTML in Chrome, take a screenshot, and send that screenshot to the user, which is a different output artifact and contradicts the earlier claim.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese overview and feature list describe the output as a 'Canvas 海报'. But the execution steps and design section explicitly switch to 'HTML 海报' and describe screenshot-based delivery, creating the same intent/documentation contradiction in the Chinese section.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.