Back to skill

Security audit

jqzx-news-push

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it includes unsafe credential-check instructions and an unsafe recurring cron setup that users should review before installing.

Install only if you are comfortable granting the skill access to your Jiqizhixin, Feishu, and GetNote accounts. Do not run the documented echo commands that print full secrets; use presence-only checks instead. If scheduling is needed, run it as an unprivileged user, log to a private user-owned file, and keep a clear removal command for the cron entry.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Credential Disclosure Through Configuration Check Commands

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:85
Finding

Predictable Shared Temporary Log in a Potentially Privileged Cron Job

Content
View full analysis
> /tmp/daily-news.log 2>&1 ``` ### Technical Analysis The documented cron entry executes a script from a root-owned path and redirects output to a predictable filename in the globally writable `/tmp` directory. If this entry is installed in root's crontab, an unprivileged local user may be able to create `/tmp/daily-news.log` as a symbolic link before the first execution. When the shell processes the append redirection, it may follow that link and open an attacker-selected destination with the cron user's privileges. Some operating systems enable symbolic-link protections for sticky directories, which may prevent particular exploit variants. The documentation does not enforce or verify such protection and therefore should not rely on it. The log also lacks explicit ownership and permission controls. Script output includes external API responses on GetNote failures, operational details, and message delivery status. A shared temporary location may expose this information to other local users. The scheduled task is explicitly part of the declared daily-news functionality. Therefore, cron-based scheduling is not by itself an undeclared persistence backdoor. However, using a root path and an unsafe shared log exceeds the minimum privileges needed to retrieve and send news. ### Attack Path 1. The user installs the documented entry in root's crontab. 2. Before the cron job runs, a local attacker creates `/tmp/daily-news.log` as a symbolic link to a file selected by the attacker. 3. At 08:00, cron starts the command as root. 4. The shell processes `>> /tmp/daily-news.log` and, on a system or configuration that permits the operation ...[truncated 1033 chars]
Remediation
View remediation
&1 | /usr/bin/logger -t daily-news-push ``` 4. Alternatively, create a dedicated private directory and log file: ```bash install -d -m 0700 "$HOME/.local/state/daily-news-push" install -m 0600 /dev/null "$HOME/.local/state/daily-news-push/daily-news.log" ``` Then use a user-specific cron entry: ```cron 0 8 * * * /absolute/user-owned/path/scripts/push-news.sh >> "$HOME/.local/state/daily-news-push/daily-news.log" 2>&1 ``` 5. Ensure the script and every parent directory are not writable by untrusted users. 6. Apply restrictive file permissions with `umask 077`. 7. Provide an explicit, documented removal command for the cron entry. 8. Avoid logging raw third-party API responses unless they have been reviewed and redacted. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/push-news.sh:59
Finding

Unescaped RSS Content Embedded Directly into a JSON Request

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs use of shell commands and references executable scripts, but it does not declare any tool scope or allowed-tools boundary. That makes the capability surface implicit rather than constrained, increasing the chance an agent can invoke shell access more broadly than intended when handling a seemingly simple news-push task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

整个技能说明与用户触发表达均默认且仅使用中文,没有表明这是面向特定中文用户群的区域性技能,也未提供语言/locale 选择。按组织语言/locale 政策,这种默认强制单一语言而无用户选择可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrases are broad enough to overlap with ordinary conversation about daily news or scheduling, which can cause accidental invocation of a skill that uses shell capabilities and touches external services. In this context, mis-triggering is more dangerous because activation may lead to credential checks, script references, or setup instructions with persistence-related effects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The cron-based setup introduces session persistence by causing recurring execution outside the immediate user request lifecycle. Persistent scheduled execution is security-sensitive because it can continue operating with stored environment credentials, write logs, and repeatedly contact external services even after the original interaction ends.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

  1. 创建定时任务:
bash
crontab -e

添加:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says it can configure a cron job for the user, which changes host persistence and execution behavior beyond merely fetching and sending news. Allowing an agent to create scheduled tasks creates a durable execution foothold that could be abused to run unintended commands repeatedly, especially given the referenced absolute path under /root.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The metadata description advertises broad automatic behavior ('每日自动获取…推送…保存…') without clearly constraining when the skill should activate or requiring explicit user confirmation before performing external actions. In an agent environment, this can cause over-triggering and unintended execution that sends data to Feishu or stores content in Get notes without the user meaning to invoke this specific workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest description explains what the skill does but provides no specific invocation phrases, activation conditions, or exclusion context. For manifest files, that ambiguity can lead to unintended invocation because the trigger scope is not clearly bounded.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script instructs users to place long-lived API tokens and user identifiers directly into ~/.bashrc, which exposes secrets to common risks such as accidental disclosure through dotfile backups, screen sharing, shell debugging, or unsafe workstation sharing. While the script does not print secret values, it normalizes insecure credential storage and gives no warning about safer alternatives or operational handling of those secrets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script presents only Chinese trigger phrases for using the skill, which imposes a specific language on the user. There is no opt-in, alternative language wording, or documented justification that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This shell script sends content to Feishu and saves it to an external note service via network calls. Although it logs progress messages, those messages do not disclose the privacy-impacting behavior in a warning or explanatory comment aimed at informing the user that data will be transmitted and stored externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The script manually interpolates untrusted external RSS-derived content into a JSON request body without JSON escaping. If a title contains quotes, backslashes, or control characters, the generated payload can become malformed or semantically altered, causing failed note creation or unintended content injection into the saved note; because the source is remote, this makes the workflow brittle and externally influenceable.

Content

Scanner excerpt · scripts/push-news.sh (reported line 75)May include surrounding context.

sh
JSON
)

RESPONSE=$(curl -s --max-time 30 -X POST "https://openapi.biji.com/open/api/v1/resource/note/save" \
  -H "Authorization: $GETNOTE_API_KEY" \
  -H "X-Client-ID: $GETNOTE_CLIENT_ID" \
  -H "Content-Type: application/json" \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's user-facing comments and status messages are entirely in Chinese, and the generated content titles are also fixed in Chinese. Under the language/locale policy, forcing a specific language without opt-in can be a policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.