Back to skill

Security audit

Hot Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill fetches public trending-topic data and generates market-analysis reports, with disclosed but somewhat broad local file-writing and script-execution side effects.

Install only if you are comfortable with the skill making public web requests and creating or overwriting several working-directory files. Run it in a new empty folder, review compute.py if you rely on the output, and treat generated market analysis as informational rather than investment advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:649
Finding

External trending-topic content can indirectly hijack LLM processing

Content
View full analysis
", "platform": "zhihu", "rank": 27, "score": 0.06 } ], "multi_member_groups": [] } ``` ### Technical Analysis The Skill directs the LLM to read and interpret titles obtained from five external APIs. Those titles cross a trust boundary: they originate outside the Skill package and may be influenced by platform users, advertisers, compromised API responses, or a compromised upstream service. The workflow does not explicitly instruct the LLM to treat every title as inert data, ignore commands embedded in titles, or restrict its response to a validated schema. A title containing language such as an instruction to disregard the grouping task, alter output files, or disclose unrelated context could therefore be interpreted as an instruction rather than as content to classify. Although `compute.py` does not execute title text as Python or shell code, the vulnerable interpreter is the LLM itself. This is an indirect prompt-injection condition. ### Attack Path 1. An attacker causes a crafted title to appear in one of the supported trending-topic API responses, or compromises an upstream response. 2. The fetch workflow writes the response to a `raw_*.json` file. 3. `compute.py prepare` extracts the title and places it in `pending.json`. 4. The Skill directs the LLM to read the title and perform semantic grouping and financial analysi ...[truncated 818 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:564
Finding

Predictable output paths can overwrite existing files in the working directory

Content
View full analysis
/compute.py {cwd}/compute.py ``` ```python os.chdir("{cwd}") req = urllib.request.Request( 'https://www.toutiao.com/hot-event/hot-board/?origin=toutiao_pc', headers={ 'User-Agent': UA, 'Referer': 'https://www.toutiao.com/' } ) with urllib.request.urlopen(req, timeout=15) as r: with open('raw_toutiao.json', 'w', encoding='utf-8') as f: json.dump(json.loads(r.read()), f, ensure_ascii=False) req = urllib.request.Request( 'https://top.baidu.com/api/board?tab=realtime', headers={ 'User-Agent': UA, 'Referer': 'https://top.baidu.com/' } ) with urllib.request.urlopen(req, timeout=15) as r: with open('raw_baidu.json', 'w', encoding='utf-8') as f: json.dump(json.loads(r.read()), f, ensure_ascii=False) req = urllib.request.Request( 'https://weibo.com/ajax/side/hotSearch', headers={ 'User-Agent': UA, 'Referer': 'https://weibo.com/' } ) with urllib.request.urlopen(req, timeout=15) as r: with open('raw_weibo.json', 'w', encoding='utf-8') as f: json.dump(json.loads(r.read()), f, ensure_ascii=False) req = urllib.request.Request( 'https://www.iesdouyin.com/web/api/v2/hotsearch/billboard/word/', headers={ 'User-Agent': UA, 'Referer': 'https://www.douyin.com/' } ) with urllib.request.urlopen(req, timeout=15) as r: with open('raw_douyin.json', 'w', encoding='utf-8') as f: json.dump(json.loads(r.read()), f, ensure_ascii=False) req = urllib.request.Request( 'https://www.zhihu.com/api/v4/search/preset_words', headers={ 'User-Agent': UA, 'Referer': 'https://www.zhihu.com/hot' } ) with urllib.request.urlopen(req, timeout=15) as r: with open('raw_zhihu.json', 'w', encoding='utf-8') ...[truncated 2127 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill directs the agent to read and write multiple local files (pending.json, groups.json, state.json, HTML outputs) and to copy and execute a local script, yet it declares no explicit tool scope or permissions. That mismatch weakens containment and reviewability: a host agent may grant broader file access than users expect, making unintended filesystem interactions more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are broad and common (e.g. '热点分析', '今天热点', '舆情分析'), so the skill may auto-activate for ordinary requests that do not imply consent to network fetching, local file creation, or script execution. Because this skill performs higher-risk side effects, overbroad activation materially increases the chance of surprising or unauthorized operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs copying compute.py from the skill installation directory into the working directory, creating fetch_all.py, and executing local Python scripts. Even if intended for analysis, this introduces arbitrary local file creation and code-execution behavior beyond the obvious user-facing task of hot-topic analysis, expanding the attack surface if the bundled script or target paths are unsafe or tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs writing several local files, generating and modifying HTML, and persisting intermediate state without clearly warning about these side effects in the manifest or trigger surface. Users asking for market-hot-topic analysis would not reasonably expect multi-file local persistence and document mutation, which raises transparency and consent concerns and can expose local data handling risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest says the skill grabs hot lists and analyzes sentiment impact on bonds, industries, securities, and futures. Injecting LLM-produced content into an HTML file is an additional artifact-editing capability that is not part of the stated purpose of data collection and market analysis.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · compute.py (reported line 324)May include surrounding context.

python
raw_counts = {}

    for name in ["toutiao", "baidu", "weibo", "douyin", "zhihu"]:
        filepath = getattr(args, name, None)
        if not filepath or not os.path.exists(filepath):
            print(f"[WARN] {name}: file not found, skipping", file=sys.stderr)
            continue

Static analysis

No suspicious patterns detected.