Back to skill

Security audit

BBC News

Security checks for vulnerabilities and agentic risk

Overview

This BBC News skill is a straightforward RSS reader with expected network access and only routine dependency-installation caution.

Before installing, use a virtual environment if possible and consider pinning feedparser to a reviewed version. Expect the skill to make outbound HTTPS requests to BBC RSS feed URLs when you ask it for news.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Unpinned Third-Party Python Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:87-91; also documented in README.md:23-30 and README.md:69-72
Vulnerability Type: Unpinned dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:87-91:

markdown
## Dependencies

Requires `feedparser`:
```bash
pip3 install feedparser
text

Equivalent unpinned installation instructions also appear in `README.md`:

```bash
pip3 install feedparser

Technical Analysis

The installation instructions retrieve feedparser without specifying a reviewed version or validating an integrity hash. Consequently, the package resolved at installation time can differ from the version originally assessed with the Skill.

Python packages may execute installation-time build logic and are later imported directly by scripts/bbc_news.py. A compromised or unexpectedly changed package release could therefore execute code during installation or whenever the news script imports feedparser.

This is a supply-chain hardening issue. The audit found no evidence that the current feedparser package or configured package name is malicious.

Attack Path

  1. An attacker compromises the upstream package, its publisher account, or the package-distribution path.
  2. The attacker publishes a malicious release under the expected package name.
  3. A user follows the documented pip3 install feedparser instruction.
  4. Pip resolves and downloads the uncontrolled release because no version or hash is pinned.
  5. Malicious code executes during package installation or when scripts/bbc_news.py imports feedparser.

Impact Assessment

Malicious dependency code would run with the privileges of the user invoking pip or the news script. It could access files, environment variables, credentials, and network resources available to that account, modify the Python environment, or execute additional commands. The scope does not inherently exceed ...[truncated 481 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin feedparser to a specifically reviewed version in a requirements file, for example:

    text
    feedparser==REVIEWED_VERSION
    
  2. Generate and verify package hashes, then install with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use a dependency-locking workflow that records exact transitive dependency versions and hashes.

  4. Recommend installation in a dedicated virtual environment rather than the system Python environment.

  5. Avoid running pip as root or with unnecessary administrative privileges.

  6. Periodically review and update the pinned dependency after checking release provenance, security advisories, and integrity information.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code file performs an HTTP fetch via feedparser.parse against external BBC endpoints, but there is no confirmation prompt or explicit user-facing notice that running the command will contact a remote service. Although fetching news implies network access, the code itself does not disclose that behavior beyond the general description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.