Back to skill

Security audit

科技新闻日报

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a coherent tech-news report workflow, but it mandates sending every report to a fixed Feishu group without per-run user confirmation.

Review this skill before installing. It is suitable only if you intentionally want generated reports saved locally, written to Feishu, and sent to the specific embedded Feishu group. Do not use it for private or organization-specific report content unless the destination identifiers are replaced with user-selected, confirmed targets and external sending is made optional.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:345
Finding

Forced Transmission of Reports to a Hard-Coded External Feishu Group

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/feishu-doc.md:15
Finding

Hard-Coded Feishu Account and Knowledge-Base Identifiers

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:250
Finding

Mandatory Third-Party Branding Injected into Generated Reports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires direct transmission of the final report to a fixed Feishu group ID and frames that send as mandatory for task completion, with no safety warning or approval step. This creates a clear unauthorized-sharing risk and turns normal skill execution into automatic external dissemination.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using an open-ended trigger such as 'or similar expressions' makes invocation boundaries ambiguous and raises the risk of accidental activation. In this skill, accidental activation is more dangerous because execution includes network searches, local persistence, document creation, and outbound messaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level description says the report will be sent to a Feishu group but does not clearly warn users that generated content leaves the local session and is transmitted externally. Because the skill aggregates content and may include generated summaries, this creates a meaningful risk of unintended disclosure to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow automatically writes reports to local storage and creates Feishu documents without a clear persistence notice or consent checkpoint. This can retain data longer than users expect and duplicate it across multiple storage locations, expanding exposure in the event of misuse or account compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill hardcodes a specific Feishu group ID and instructs mandatory delivery to that target, creating a fixed exfiltration path for generated content. If the skill is triggered in normal use, reports may be sent to an unintended or overbroad audience without per-run verification of destination or consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description and output examples are centered on Chinese-language operation and a GMT+8 timestamp format, but do not indicate that users may choose another language or locale. This can amount to a locale/language constraint without explicit opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The late-stage execution note introduces a mandatory Feishu group broadcast that is more sensitive than the earlier workflow presentation and can materially change the data-flow of the skill. Burying an external broadcast requirement deep in documentation increases the chance that operators or users trigger the skill without understanding that generated content will be sent to a group chat.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language instructions and labels throughout the file are exclusively in Chinese, which can amount to a language-policy issue if the skill is expected to support broader users without forcing a specific language. There is no note that the Chinese locale is intentional, optional, or limited to a specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file includes an example for writing content to a document via the write action, which can change user data in an external system. The surrounding documentation does not warn that this operation edits existing document contents or advise users to verify the target document before running it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.