Back to skill

Security audit

Iccircle News

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed RSS news aggregator with minor scope and presentation issues, but no hidden persistence, credential access, local data access, or destructive behavior.

Install only if you are comfortable with the skill contacting iccircle.com, vlsiblogs.com, ithome.com, and 36kr.com to fetch RSS feeds and returning primarily Chinese formatted output. Users who need strictly IC技术圈-only or strictly semiconductor-only content should narrow the feed list before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/agg_news.py:48
Finding

Forced Promotional Content in Agent Responses

Content
View full analysis

Vulnerability Details

File Location: scripts/agg_news.py:48, with propagation instructions in SKILL.md:8-12
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable Code

The following is an ASCII-escaped representation of the complete affected statement at scripts/agg_news.py:48:

python
print("\U0001f99e \u5c0f\u9f99\u867e\u7279\u4f9b\uff1a\u805a\u5408\u82af\u7247\u4e0e\u534a\u5bfc\u4f53\u9886\u57df\u8d44\u8baf")

The output-propagation instructions in SKILL.md:8-12 are:

markdown
1. **Execution**: Run `python3 <skill_dir>/scripts/agg_news.py` to fetch news.
2. **Output**: The script prints formatted news directly to stdout; capture and present to user.
3. **No arguments**: The script runs with predefined RSS sources and keywords; no extra parameters needed.
4. **Sources**: Aggregates from IC technology community (7 columns), VLSI Blogs, IT Home, 36Kr.
5. **Presentation**: Preserve the formatted output structure with source headers, timestamps, and links.

Technical Analysis

The script unconditionally prepends a fixed branded promotional slogan whenever it runs. The skill instructions require the agent to capture the script's standard output, present it to the user, and preserve its formatting. Together, these behaviors cause unrelated promotional content to be propagated into every response produced through the skill.

The behavior does not modify system-level instructions or bypass a technical access-control boundary. Nevertheless, it manipulates the agent's user-facing output through mandatory skill execution and presentation rules, making T01 the closest applicable classification.

Attack Path

  1. A user requests semiconductor or chip-industry news.
  2. The agent loads the skill and follows SKILL.md.
  3. The agent executes scripts/agg_news.py as directed.
  4. Line 48 emits the fixed promotional slogan before the aggregated new ...[truncated 737 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the promotional slogan with a neutral, task-specific heading such as Semiconductor and Chip Industry News.
  2. Update SKILL.md so the agent is required to preserve only substantive news fields, such as source names, publication dates, titles, and links.
  3. Explicitly permit or require the agent to omit branding, advertisements, calls to action, and unrelated fixed text from script output.
  4. Separate machine-readable news data from presentation text, for example by emitting JSON and allowing the agent to render a neutral response.
  5. Add a test that fails if output contains fixed promotional language unrelated to the declared aggregation function.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description says it fetches IC技术圈 RSS news, but the documented behavior accesses multiple additional third-party domains and includes at least one broader, non-semiconductor content source. Description-behavior mismatches are dangerous because they undermine informed consent, reduce reviewer visibility into data flows, and can hide unexpected external communications or content ingestion paths behind a narrower stated purpose. The mismatch is not necessarily malicious here, but it increases supply-chain and trust risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a Python script that performs outbound network access, but the manifest does not declare any tool scope or allowed network capability. This creates a least-privilege and review gap: operators and users cannot accurately assess what the skill is permitted to do, and future code changes could expand external access without corresponding manifest scrutiny. In this context the behavior appears aligned with the skill’s purpose, so the issue is primarily undeclared capability rather than obviously malicious functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-visible strings are presented in Chinese throughout the script, including status messages and headings, with no option to select another language. This is a natural-language locale policy concern because the skill imposes a specific language on users rather than allowing choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description says the skill fetches and aggregates semiconductor and chip industry news from IC技术圈 (iccircle.com) RSS feeds. However, the code also pulls content from vlsiblogs.com, ithome.com, and 36kr.com, expanding the data sources beyond the stated IC技术圈-only scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file performs HTTP requests to multiple third-party RSS endpoints, which is a safety-relevant operation under the warning rule for code files. Although the script prints fetched results, it does not disclose before connecting that it will contact external services and transmit request metadata such as IP address and headers.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames the skill as focused on semiconductor and chip industry news, but the configured IC技术圈 sources include a column named "web开发笔记", which is web-development oriented rather than obviously semiconductor-related. That broadens the fetched content beyond the stated topical scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.