Back to skill

Security audit

news-homepage-fetcher

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only news collection and Chinese digest skill with disclosed public-web browsing and translation behavior, but users should mind source terms and language expectations.

Install this if you want an agent to browse public news sites and produce Chinese news digests. Use it within each source's access and reuse terms, avoid paywalled or login-restricted content, and prefer summaries or internal-use documents unless you have rights to redistribute full translated articles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hard-codes a Chinese-translation workflow as the default interpretation of the task, which can override or bias the agent away from the user's actual language and output preferences. This is not code execution or data exfiltration, but it can cause unauthorized transformation of content, fidelity loss in summaries/translations, and user-intent misalignment in downstream deliverables.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The required output schema mandates Chinese-language fields such as title_zh, summary_zh, body_zh, and keywords_zh regardless of user preference, which can force unnecessary translation and reshape content even when the user asked for original-language extraction. In a news-ingestion skill, this is especially risky because translation is a lossy transformation that may alter nuance, create inconsistencies, or break downstream systems expecting source-language preservation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.