Back to skill

Security audit

Personal Toutiao Pub

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Toutiao auto-publisher that is mostly disclosed, but it can post publicly through an authenticated Chrome session without a final approval step.

Install only if you are comfortable with an automation tool that can publish to a live Toutiao account through your logged-in browser. Use a dedicated Chrome profile, close unrelated tabs, disable remote debugging after use, review the full final text yourself, avoid running it with no content, and prefer a virtual environment with pinned dependencies instead of the documented system-wide pip command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:136
Finding

Unpinned Dependency Installation Bypasses System Package Protections

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
toutiao_publish.py:229
Finding

Publishing Workflow Exposes an Authenticated Primary Browser Through Chrome DevTools Protocol

Content
View full analysis
Remediation
View remediation

other

Note
Location
toutiao_publish.py:213
Finding

Short User Posts Are Silently Modified Before Automatic Publication

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates the actual behavior: the skill can publish default content without explicit user-provided text, upload images, and attach to an existing Chrome remote-debugging session to reuse the user's authenticated state. That mismatch is dangerous because users and reviewers may authorize what appears to be a simple posting tool without realizing it can perform live account actions through an already logged-in browser session.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script performs a real publish action on the user's logged-in Toutiao account by directly clicking the final 发布 button, but it does not require an explicit user confirmation immediately before posting. Because it reuses an existing Chrome session via CDP on localhost:9222, any invocation of this skill can cause unintended account actions under the user's identity, making accidental or unauthorized posting significantly easier.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope or permissions even though its documented behavior includes reading local files via the -f/--file option. Missing scope declarations reduce transparency and safety review effectiveness, making it easier for a publishing skill to access local content without a clearly declared boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description does not prominently warn that it will perform a real external side effect: publishing content to a live Toutiao account and optionally uploading images. Without an explicit live-action warning, users may invoke the skill casually and trigger irreversible or reputationally harmful account activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to enable Chrome remote debugging and reuse an existing login session, but does not provide a clear privacy or security warning about the risks of exposing an authenticated browser context. Remote debugging can grant broad access to browsing state, cookies, and authenticated actions, so omission of this warning materially increases the chance of unsafe use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default content explicitly states that the AI is freely exploring and has successfully published using the owner's account, which normalizes autonomous posting under someone else's identity. In the context of an auto-publishing skill that reuses the local logged-in browser session, this language increases concern because it evidences and encourages non-consensual or insufficiently supervised account use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.