T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_feed.py:43- Finding
Unrestricted RSS URL Fetching Enables Server-Side Request Forgery and Resource Exhaustion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This RSS skill is mostly coherent, but it allows broad RSS URL fetching and describes AI rewrite/publishing workflows without enough scoping, confirmation, or untrusted-content safeguards.
Install only if you are comfortable with the skill making outbound requests to configured RSS URLs from your machine. Use trusted feeds, avoid internal or sensitive URLs, review generated text before any Feishu save or social posting, and require an explicit final confirmation for every external write or publication.
scripts/fetch_feed.py:43Unrestricted RSS URL Fetching Enables Server-Side Request Forgery and Resource Exhaustion
SKILL.md:17Untrusted RSS Content Crosses Into an AI Workflow Without Prompt-Injection Isolation
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README states that drafts may be written to Feishu documents or directly handed off to publishing tools, but it does not warn users about external writes, account usage, or content-distribution side effects. In a content automation skill, lack of disclosure increases the risk of users unintentionally authorizing actions that create records or distribute generated material to third-party platforms.
The trigger phrases include broad everyday expressions such as '我需要内容灵感', which can cause the skill to activate when a user did not intend to invoke RSS ingestion and downstream content-generation behavior. In this skill, accidental invocation is more concerning because the workflow can lead to fetching external content and potentially saving drafts or publishing through connected tools.
The workflow explicitly includes '直接发布' without stating that publication is gated by human review or disabled by default. Because this skill transforms external RSS content into platform-ready posts, automatic publishing could amplify accidental, inaccurate, or policy-violating content across public channels.
The skill documents capabilities that read a local config file, write subscription data, and fetch remote RSS content, but it declares no explicit tool scope or permission boundaries. This increases the chance of over-privileged execution or unintended tool access because an agent may infer broader file and network permissions than the skill actually needs.
The documentation claims the skill is only for RSS fetching, but the quick-start workflow instructs the agent to perform AI rewriting after user confirmation. This mismatch can cause an agent or user to grant trust and permissions under a narrower data-fetching assumption while the actual workflow expands into content transformation, potentially invoking additional models, data handling, or publication chains.
The activation phrase '帮我找今天的选题' is broad enough to overlap with ordinary user requests, which can trigger the skill unexpectedly in contexts where the user did not intend RSS fetching, local file reads, or network access. Over-broad triggers are risky because they can cause unintended tool invocation and data flow without sufficiently explicit user intent.
The quick-start section says the user-confirmed next step is AI rewriting, but later sections assert the skill does not perform content generation or rewriting. Contradictory security-relevant documentation can mislead users, reviewers, and orchestrators about what actions the skill may take, weakening consent and policy enforcement.
The module docstring presents the skill description and usage entirely in Chinese, and the rest of the script's CLI help and output also use Chinese-only text. This imposes a specific language on users without offering any language selection or documenting a justified locale restriction.
该技能的自然语言说明、触发词和输出平台描述均以中文为唯一默认语言,但文档没有说明这是用户可选项,或该技能仅面向中文内容运营场景。按照语言/locale 政策,若未提供选择或正当范围说明,可能构成不必要的语言强制。
The skill name and all user-facing instructions are presented only in Chinese, and the related integrations also target Chinese platforms, but the document does not state that the skill is China-specific or offer any user language choice. This can constitute a locale-policy issue because the skill appears to assume a fixed language environment without explicit opt-in or justification.
The config enumerates only Chinese-language publication names and feeds, which implies a locale/language restriction. In a config file, this can constitute a natural-language policy issue when no user opt-in or justification is provided for forcing a specific language or region.
This code file contains natural-language instructions and interface text exclusively in Chinese, including the top-level docstring usage examples. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.
User-facing stderr/stdout messages and argparse help strings are all hard-coded in Chinese, which enforces a single locale for operation. The file does not provide any language selection mechanism or documented justification for the locale restriction.
No suspicious patterns detected.