Back to skill

Security audit

今日头条运营助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Toutiao publishing assistant, but it asks for account credentials and supports browser-based public posting without enough safety guidance or scoping.

Review this skill before installing if you plan to use it with a real Toutiao account. Use a dedicated low-privilege account if possible, avoid putting passwords in plain text, and require human confirmation before any browser automation publishes public content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document assigns an agent to perform browser automation publishing and post-publication data tracking, but it provides no warning, approval gate, scope restriction, or credential-safety guidance for actions that can affect real user accounts and external platforms. In an agent skill, this omission is risky because an implementation may autonomously log in, post content, or interact with third-party services without explicit user confirmation or operational safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is entirely written as a China-platform-specific content guide and does not offer any language or locale choice. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises automated browser-based publishing and account-backed operations, but provides no warning about privacy, credential exposure, account lockout, or unintended posting risks. In a skill that can act on a live publishing account, omission of these warnings increases the chance that users will supply sensitive credentials and authorize impactful actions without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prerequisite instructs users to configure a Toutiao account with username and password, but does not explain how those secrets are stored, protected, or avoided. This is dangerous because users may enter production credentials into an insecure local setup or agent memory, exposing the account to theft, misuse, or unauthorized publishing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents its instructions entirely in Chinese, starting with the title on L01, and does not mention any user language preference or alternative locale. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing instructions, examples, and descriptions are presented only in Chinese, and the example commands assume Chinese-language prompts. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.