Back to skill

Security audit

Rss Aggregator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it fetches feeds insecurely and can produce unsafe HTML output, so it should be reviewed before installation.

Install only if you are comfortable reviewing or fixing the helper first. Avoid using HTML output for untrusted feeds, do not run it against feed lists from untrusted sources, and prefer a version that keeps TLS verification enabled and validates feed URLs before fetching.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/aggregator.py:34
Finding

TLS Certificate and Hostname Verification Disabled

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/aggregator.py:38
Finding

Unrestricted Feed URLs Permit Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/aggregator.py:142
Finding

Unescaped Feed Fields Allow Script and Markup Injection in HTML Digests

Content
View full analysis

RSS Digest

    '] for item in items: html.append(f'
  • {item["title"]} ({item["feed"]})
  • ') html.append('
') return '\n'.join(html) ``` ### Technical Analysis The `link`, `title`, and `feed` values originate from remote RSS or Atom documents and are inserted directly into an HTML document. No context-sensitive HTML escaping is applied. A malicious title or feed name can terminate the expected text context and insert arbitrary elements. A malicious link can break out of the quoted `href` attribute by including a quotation mark, or it can use an unsafe scheme such as `javascript:`. The regular expression used elsewhere to remove tags from descriptions does not protect these fields. It also would not be a safe substitute for output encoding. Correct protection requires escaping according to the HTML context and separately validating URL schemes. ### Attack Path 1. An attacker controls a configured feed or compromises its returned content. 2. The feed includes a crafted field, for example a title containing an image element with an event handler, or a link containing a quote followed by an injected attribute. 3. The user runs the aggregator with `--format html`. 4. The application writes the attacker-controlled field directly into the generated document. 5. A victim opens the file in a browser or publishes it through a web server or newsletter system. 6. The browser interprets the injected content as active HTML or JavaScript rather than plain feed text. 7. Script execution occurs in the security context assigned to the generated document. ### Impact Assessment Depending on how the generated digest is consumed, exploitation ma ...[truncated 590 chars]
Remediation
View remediation

RSS Digest

    '] for item in items: link = escape(safe_link(item["link"]), quote=True) title = escape(item["title"], quote=True) feed = escape(item["feed"], quote=True) output.append(f'
  • {title} ({feed})
  • ') output.append('
') return '\n'.join(output) ``` Further hardening should include: 1. Use a maintained template engine with automatic escaping enabled. 2. Permit only `http` and `https` link schemes; reject `javascript:`, `data:`, and malformed URLs. 3. Add a restrictive Content Security Policy when HTML output is served over HTTP. 4. Avoid marking feed content as trusted HTML. 5. Add tests containing quotation marks, angle brackets, event-handler attributes, encoded payloads, and unsafe URL schemes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

TLS verification is intentionally disabled with no user warning or opt-in, so users may believe feeds are being fetched securely when they are not. This permits interception or substitution of feed data over HTTPS, enabling content poisoning, misleading digests, and potentially unsafe links in generated output.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises behavior that involves both network access and writing files, but it does not declare any explicit tool scope or permissions boundary. That makes the capability surface implicit rather than reviewable, increasing the chance an agent invokes the skill in contexts where network fetching or local file writes were not expected by the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is broad enough to trigger on generic monitoring, tracking, digest, or newsletter requests, which can cause the skill to activate outside a narrowly scoped RSS/Atom use case. Over-broad routing increases the chance of unnecessary network access, content collection, and file generation in situations where a more constrained skill or direct user confirmation would be safer.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables TLS hostname and certificate verification before fetching arbitrary feed URLs, which allows a man-in-the-middle attacker to spoof HTTPS feeds and inject untrusted content. In an RSS aggregator, the fetched content is the primary input to downstream processing and output, so losing transport authenticity directly undermines the integrity of all aggregated results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples repeatedly write fetched and aggregated content to user-specified files and temporary paths without warning about overwriting existing files, retaining remote content locally, or exposing sensitive feed data through predictable locations like /tmp. In isolation this is a lower-severity issue, but in an automation context it can lead to unintended data persistence or clobbering of existing files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script writes aggregated remote content to a user-specified file path, but provides no prior disclosure in comments, docstrings, or argument help that local files will be created or overwritten. The post-write "Saved to" message confirms completion, but it does not warn users in advance about the file-write behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.