Back to skill

Security audit

Noticias Cangrejo

Security checks for vulnerabilities and agentic risk

Overview

This skill openly fetches GNews articles for a user topic and optionally saves a Markdown digest, with no hidden persistence or destructive behavior found.

Install only if you are comfortable providing a GNews API key and allowing requests to GNews. Use --output only with a path you intend to create or replace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a functional news retrieval and summarization skill, but the provided code chunk is only an empty package initializer with a docstring. There is no evidence of network access, GNews integration, user-topic handling, summarization logic, or Markdown output generation. This is a material mismatch between declared purpose and actual behavior of the supplied code.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares capabilities that involve environment access, network access, and file writing, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent setting, this weakens containment and reviewability because the runtime may permit broader actions than a user or operator expects, especially when the skill can read secrets like GNEWS_API_KEY and write arbitrary output files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly requires a Greeting line in Spanish, which imposes a specific language in the skill's behavior. The policy allows locale constraints only when the user is given a language choice or the constraint is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rendered Markdown always uses Spanish phrases like "Buenos dias" and "No se encontraron articulos" regardless of user preference or the --lang argument. This creates a language/locale policy issue because the skill imposes a specific output language without offering opt-in or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown shows an --output example that writes the generated summary to a local file, which affects user data on disk. The README does not include any caution about file creation or possible overwriting, so users are not explicitly warned about this side effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises writing Markdown to a user-specified path via --output without any warning or safeguards about overwriting existing files. In an agent workflow, this can lead to unintended modification of local files, especially if a user or upstream prompt supplies a sensitive or important path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description focuses on fetching and summarizing recent news into a Markdown digest, but does not mention filesystem write behavior. The script accepts an arbitrary output path and later writes the generated digest to disk, which is additional behavior beyond a pure fetch-and-summarize operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.