Back to skill

Security audit

news-impact-analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned, but it sends news text and an API key to a remote service with insecure transport defaults that could expose them.

Install only if you are comfortable sending submitted news text to the EasyAlpha backend or a configured server. Avoid using confidential research or sensitive prompts, do not configure an arbitrary remote HTTP URL, and require corrected HTTPS certificate validation before trusting it with important credentials or investment workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze_news.js:38
Finding

API credentials and news content exposed through insecure transport defaults

Content
View full analysis

Vulnerability Details

File Location: scripts/analyze_news.js, lines 38–64
Vulnerability Type: Improper TLS certificate validation and permitted plaintext transport
Risk Level: High

Vulnerable Code

javascript
async function analyzeNews(content) {
    console.log(`Analyzing news impact... (this may take a few seconds)`);

    // 确定是使用 HTTP 还是 HTTPS
    const isHttps = NEWS_EXTRACTOR_SERVER_URL.startsWith('https://');
    const httpModule = isHttps ? https : http;

    try {
        // 构建请求选项
        const serverUrl = new URL(NEWS_EXTRACTOR_SERVER_URL);
        const requestData = JSON.stringify({ news_content: content });

        const endpoint = '/api/v1/analyze';

        const options = {
            hostname: serverUrl.hostname,
            port: serverUrl.port || (isHttps ? 443 : 80),
            path: endpoint,
            method: 'POST',
            headers: {
                'Content-Type': 'application/json',
                'Content-Length': Buffer.byteLength(requestData),
                'X-EasyAlpha-API-Key': EASYALPHA_API_KEY,
                'Authorization': `Bearer ${EASYALPHA_API_KEY}`
            },
            // 默认跳过 SSL 验证以简化用户操作 (尤其是针对 duckdns 等自动证书可能导致的验证问题)
            // 如果用户显式设置了 ALLOW_INSECURE_SSL='false',则开启验证
            rejectUnauthorized: process.env.ALLOW_INSECURE_SSL === 'false' ? true : false
        };

Technical Analysis

The HTTPS request configuration disables certificate validation by default. The rejectUnauthorized option becomes false unless ALLOW_INSECURE_SSL is explicitly set to the exact string false. Consequently, the client does not reliably authenticate the remote server, defeating a primary security guarantee of TLS.

The server URL is configurable and the implementation explicitly selects Node.js's plaintext http module for URLs that do not start with https://. No validation prevents API credentials and ...[truncated 2588 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the rejectUnauthorized override and rely on Node.js's secure default certificate validation:

    javascript
    const options = {
        hostname: serverUrl.hostname,
        port: serverUrl.port || 443,
        path: endpoint,
        method: 'POST',
        headers: {
            'Content-Type': 'application/json',
            'Content-Length': Buffer.byteLength(requestData),
            'Authorization': `Bearer ${EASYALPHA_API_KEY}`
        }
    };
    
  2. Enforce HTTPS before constructing the request:

    javascript
    const serverUrl = new URL(NEWS_EXTRACTOR_SERVER_URL);
    if (serverUrl.protocol !== 'https:') {
        throw new Error('NEWS_EXTRACTOR_SERVER_URL must use HTTPS');
    }
    
  3. If local plaintext development is necessary, restrict it to loopback hosts through a separate, explicit development option. Do not permit arbitrary remote HTTP destinations.

  4. For private or development certificates, accept a user-provided trusted certificate authority through the ca option rather than disabling certificate validation globally.

  5. Send the API key in only the authentication header required by the service. Remove the duplicate credential header to reduce exposure through middleware and access logs.

  6. Add automated tests confirming that:

    • invalid or self-signed certificates are rejected by default;
    • arbitrary http:// server URLs are rejected;
    • only an explicitly approved loopback development configuration can use plaintext transport; and
    • credentials are emitted through only one required header.
  7. Update the documentation's claim of secure communication only after secure TLS validation and HTTPS enforcement are implemented.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates materially sensitive behavior: the skill sends user-provided news and an API credential to a configurable remote server, and the finding indicates TLS certificate verification may be disabled by default. A configurable endpoint plus insecure transport handling creates a credible path for credential interception, data exfiltration, or redirection to an attacker-controlled backend.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- Run `node scripts/analyze_news.js "<news text content>"`

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script permits NEWS_EXTRACTOR_SERVER_URL to use plain HTTP and then transmits the news content plus both X-EasyAlpha-API-Key and Authorization: Bearer credentials over that channel. An attacker on the network path can read or modify the request and response, exposing secrets and potentially tampering with analysis results.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code disables TLS certificate verification by default via rejectUnauthorized: ... ? true : false, which means HTTPS connections will accept invalid or forged certificates unless the user explicitly opts in to verification. This enables man-in-the-middle interception of both the news content and the API key, which is especially risky because the script sends authentication headers to the backend.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Although the URL may be HTTPS, disabling certificate validation by default removes the core protection HTTPS is meant to provide. This effectively allows active attackers to impersonate the backend and capture API credentials or alter returned market-impact analysis without obvious detection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states that news content is sent to a centralized remote analysis engine and requires an API key, but it provides no warning about what data is transmitted, how it is stored, retained, or shared. In an agent context, users may pass sensitive or proprietary news, research, or prompts to the tool, so the absence of privacy and data-handling disclosures creates a real risk of unintended data exfiltration or misuse.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares environment-variable requirements but does not define an explicit tool scope or permissions boundary. That omission can cause agents or users to invoke a capability-bearing skill without clear consent around secret access and related execution behavior, increasing the chance of unintended secret exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill text does not clearly warn that user-supplied news content and an authentication token are transmitted to an external backend service. This lack of disclosure undermines informed consent and can lead users to expose sensitive market research, proprietary text, or credentials to an untrusted third party.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file contains Chinese comments alongside English user-facing console output, reflecting an implicit language choice without documented opt-in or locale handling. The policy requires avoiding forced language or locale assumptions unless the constraint is explicit and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.