Back to skill

Security audit

Local News API: Search Articles, Sources, Meeting Transcripts & Events

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local-news research skill that uses a user-provided newsroom API key and has no hidden persistence, exfiltration, or destructive behavior.

Install only if you are comfortable giving the skill network access to the configured newsroom and using a cn_ API key. Prefer a read-only key, keep NEWS_SITE and PLATFORM_API_BASE in trusted configuration, and use --out only for files you intend to create or overwrite. Verify attribution and newsroom terms before republishing retrieved material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

hold the key but never NEWS_SITE or PLATFORM_API_BASE):

bash
echo 'COMMUNITIES_NEWS_API_KEY=cn_...' >> scripts/.env.local

Access is tiered on the platform side, and your key may not reach everything.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 305)May include surrounding context.

python
hold the key but never `NEWS_SITE` or `PLATFORM_API_BASE`):

```bash
echo 'COMMUNITIES_NEWS_API_KEY=cn_...' >> scripts/.env.local
```

Access is tiered on the platform side, and your key may not reach everything.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 531)May include surrounding context.

python
hold the key but never `NEWS_SITE` or `PLATFORM_API_BASE`):

```bash
echo 'COMMUNITIES_NEWS_API_KEY=cn_...' >> scripts/.env.local
```

Access is tiered on the platform side, and your key may not reach everything.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 701)May include surrounding context.

python
hold the key but never `NEWS_SITE` or `PLATFORM_API_BASE`):

```bash
echo 'COMMUNITIES_NEWS_API_KEY=cn_...' >> scripts/.env.local
```

Access is tiered on the platform side, and your key may not reach everything.

Lp1

High
Category
MCP Least Privilege
Confidence
83% confidence
Finding

Although the skill markets itself as read-only with respect to the newsroom API, it can write local files via --out in cmd_brief. This is not remote compromise, but it is a real capability mismatch that could surprise a host agent or violate a least-privilege policy if file-write permission was not granted.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
83% confidence
Finding

Although the skill markets itself as read-only with respect to the newsroom API, it can write local files via --out in cmd_brief. This is not remote compromise, but it is a real capability mismatch that could surprise a host agent or violate a least-privilege policy if file-write permission was not granted.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
83% confidence
Finding

Although the skill markets itself as read-only with respect to the newsroom API, it can write local files via --out in cmd_brief. This is not remote compromise, but it is a real capability mismatch that could surprise a host agent or violate a least-privilege policy if file-write permission was not granted.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
83% confidence
Finding

Although the skill markets itself as read-only with respect to the newsroom API, it can write local files via --out in cmd_brief. This is not remote compromise, but it is a real capability mismatch that could surprise a host agent or violate a least-privilege policy if file-write permission was not granted.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 243)May include surrounding context.

python
super().__init__(f"HTTP {code}: {body[:300]}")


# What a .env in the CURRENT DIRECTORY may set. That directory is whatever project
# the skill happens to run in, so its .env is workspace-controlled: if it could set
# NEWS_SITE or PLATFORM_API_BASE it could choose where your key is sent, and an agent
# working inside an untrusted repository would carry your exported key there. It may

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 244)May include surrounding context.

python
super().__init__(f"HTTP {code}: {body[:300]}")


# What a .env in the CURRENT DIRECTORY may set. That directory is whatever project
# the skill happens to run in, so its .env is workspace-controlled: if it could set
# NEWS_SITE or PLATFORM_API_BASE it could choose where your key is sent, and an agent
# working inside an untrusted repository would carry your exported key there. It may

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 248)May include surrounding context.

python
super().__init__(f"HTTP {code}: {body[:300]}")


# What a .env in the CURRENT DIRECTORY may set. That directory is whatever project
# the skill happens to run in, so its .env is workspace-controlled: if it could set
# NEWS_SITE or PLATFORM_API_BASE it could choose where your key is sent, and an agent
# working inside an untrusted repository would carry your exported key there. It may

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 291)May include surrounding context.

python
super().__init__(f"HTTP {code}: {body[:300]}")


# What a .env in the CURRENT DIRECTORY may set. That directory is whatever project
# the skill happens to run in, so its .env is workspace-controlled: if it could set
# NEWS_SITE or PLATFORM_API_BASE it could choose where your key is sent, and an agent
# working inside an untrusted repository would carry your exported key there. It may

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 292)May include surrounding context.

python
super().__init__(f"HTTP {code}: {body[:300]}")


# What a .env in the CURRENT DIRECTORY may set. That directory is whatever project
# the skill happens to run in, so its .env is workspace-controlled: if it could set
# NEWS_SITE or PLATFORM_API_BASE it could choose where your key is sent, and an agent
# working inside an untrusted repository would carry your exported key there. It may

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The same _load_env() behavior applies to .env.local in the current working directory, which may be controlled by an untrusted project. This can make credential sourcing non-obvious and weaken the guarantee that secrets come only from a trusted user-controlled location.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 255)May include surrounding context.

python
def _load_env():
    """Read KEY=VALUE lines from .env / .env.local next to this script OR in the
    current directory, without overriding anything already set in the environment.
    Checking both means the key file is found whether you run from the script's
    folder or from your project root. A current-directory file is restricted to

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The same _load_env() behavior applies to .env.local in the current working directory, which may be controlled by an untrusted project. This can make credential sourcing non-obvious and weaken the guarantee that secrets come only from a trusted user-controlled location.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 255)May include surrounding context.

python
def _load_env():
    """Read KEY=VALUE lines from .env / .env.local next to this script OR in the
    current directory, without overriding anything already set in the environment.
    Checking both means the key file is found whether you run from the script's
    folder or from your project root. A current-directory file is restricted to

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The same issue applies to .env.local at this line: a workspace can influence secret loading simply by placing a file in the working directory. The code blocks destination override, which helps, but the skill still consumes repository-local credentials without clear opt-in.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 264)May include surrounding context.

python
script_dir = SCRIPT_DIR.resolve()
    for d in (SCRIPT_DIR, Path.cwd()):
        workspace = d.resolve() != script_dir
        for name in (".env", ".env.local"):
            p = (d / name).resolve()
            if p in seen or not p.exists():
                continue

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The same issue applies to .env.local at this line: a workspace can influence secret loading simply by placing a file in the working directory. The code blocks destination override, which helps, but the skill still consumes repository-local credentials without clear opt-in.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 264)May include surrounding context.

python
script_dir = SCRIPT_DIR.resolve()
    for d in (SCRIPT_DIR, Path.cwd()):
        workspace = d.resolve() != script_dir
        for name in (".env", ".env.local"):
            p = (d / name).resolve()
            if p in seen or not p.exists():
                continue

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to 'Reach for it even when the request never says "API" or names the newsroom' and then lists phrases like 'has anyone reported on this' and 'find me what was written before.' These are common, broad research requests that could overlap with everyday conversation, making the activation boundary unclear for when this skill should or should not be invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file says it can target other newsrooms via NEWS_SITE and NEWS_COMMUNITY, but user-facing messages still direct users specifically to create a key at alaskanews.com/profile/settings. This natural-language guidance imposes an Alaska-specific organizational context on all users and is inconsistent with the documented multi-community behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 401 recovery text tells users that 'alaskanews API keys' are required and sends them to alaskanews.com/profile/settings, even though the client is described as reusable for other communities. This is a natural-language policy inconsistency that can misdirect users in non-Alaska deployments.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/local_news_api.py (reported line 12)May include surrounding context.

python
back to the newsroom is a separate, editor-authenticated workflow, not this tool.

DEFAULTS to alaskanews.com, which is the only newsroom live on this platform
today. It is not limited to it: set NEWS_SITE and NEWS_COMMUNITY to point it at
another one. Nothing about a market is compiled in.

Terms of use are READ FROM THE NEWSROOM, per request, never assumed: robots.txt

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to be read-only and to never write back, but cmd_brief can write generated content to a local file with --out. While this does not write to the remote newsroom, it is still local state modification and can violate trust or sandbox expectations around a 'read-only' skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The argparse description states the tool is for 'the alaskanews.com public API', which conflicts with earlier documentation that it is configurable for other newsrooms. This fixed natural-language locale/service framing may violate organizational expectations for reusable multi-community skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.