Back to skill

Security audit

Rss Content Flow

Security checks for vulnerabilities and agentic risk

Overview

This RSS skill is mostly coherent, but it allows broad RSS URL fetching and describes AI rewrite/publishing workflows without enough scoping, confirmation, or untrusted-content safeguards.

Install only if you are comfortable with the skill making outbound requests to configured RSS URLs from your machine. Use trusted feeds, avoid internal or sensitive URLs, review generated text before any Feishu save or social posting, and require an explicit final confirmation for every external write or publication.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_feed.py:43
Finding

Unrestricted RSS URL Fetching Enables Server-Side Request Forgery and Resource Exhaustion

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:17
Finding

Untrusted RSS Content Crosses Into an AI Workflow Without Prompt-Injection Isolation

Content
View full analysis
]+>", "", desc_text) desc_text = re.sub(r"&[^;]+;", "", desc_text) description = desc_text[:300] break ``` `scripts/fetch_feed.py:160-166`: ```python articles.append({ "title": title, "link": link, "description": description, "pub_date": pub_date[:16] if pub_date else "", "source": source_name }) ``` The relevant workflow instructions in `SKILL.md:17-22`, translated into English, direct the agent to: ```text 1. Read the subscription configuration. 2. Use fetch_feed.py to obtain the latest entries. 3. Present available topics for user selection. 4. After user confirmation, use AI to rewrite the content. ``` ### Technical Analysis RSS titles, descriptions, summaries, and content fields are controlled by remote publishers. The parser removes basic HTML-like tags and truncates descriptions, but these transformations do not neutralize natural-language instructions. The Skill subsequently directs an AI agent to present, analyze, and rewrite this remote content. It does not establish a trust boundary stating that feed fields are untrusted data, must never be interpreted as instructions, and cannot authorize tool use. An attacker-controlled feed entry can therefore contain text such as instructions to ignore the user's re ...[truncated 2158 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README states that drafts may be written to Feishu documents or directly handed off to publishing tools, but it does not warn users about external writes, account usage, or content-distribution side effects. In a content automation skill, lack of disclosure increases the risk of users unintentionally authorizing actions that create records or distribute generated material to third-party platforms.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include broad everyday expressions such as '我需要内容灵感', which can cause the skill to activate when a user did not intend to invoke RSS ingestion and downstream content-generation behavior. In this skill, accidental invocation is more concerning because the workflow can lead to fetching external content and potentially saving drafts or publishing through connected tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly includes '直接发布' without stating that publication is gated by human review or disabled by default. Because this skill transforms external RSS content into platform-ready posts, automatic publishing could amplify accidental, inaccurate, or policy-violating content across public channels.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents capabilities that read a local config file, write subscription data, and fetch remote RSS content, but it declares no explicit tool scope or permission boundaries. This increases the chance of over-privileged execution or unintended tool access because an agent may infer broader file and network permissions than the skill actually needs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation claims the skill is only for RSS fetching, but the quick-start workflow instructs the agent to perform AI rewriting after user confirmation. This mismatch can cause an agent or user to grant trust and permissions under a narrower data-fetching assumption while the actual workflow expands into content transformation, potentially invoking additional models, data handling, or publication chains.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrase '帮我找今天的选题' is broad enough to overlap with ordinary user requests, which can trigger the skill unexpectedly in contexts where the user did not intend RSS fetching, local file reads, or network access. Over-broad triggers are risky because they can cause unintended tool invocation and data flow without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick-start section says the user-confirmed next step is AI rewriting, but later sections assert the skill does not perform content generation or rewriting. Contradictory security-relevant documentation can mislead users, reviewers, and orchestrators about what actions the skill may take, weakening consent and policy enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring presents the skill description and usage entirely in Chinese, and the rest of the script's CLI help and output also use Chinese-only text. This imposes a specific language on users without offering any language selection or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

该技能的自然语言说明、触发词和输出平台描述均以中文为唯一默认语言,但文档没有说明这是用户可选项,或该技能仅面向中文内容运营场景。按照语言/locale 政策,若未提供选择或正当范围说明,可能构成不必要的语言强制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill name and all user-facing instructions are presented only in Chinese, and the related integrations also target Chinese platforms, but the document does not state that the skill is China-specific or offer any user language choice. This can constitute a locale-policy issue because the skill appears to assume a fixed language environment without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The config enumerates only Chinese-language publication names and feeds, which implies a locale/language restriction. In a config file, this can constitute a natural-language policy issue when no user opt-in or justification is provided for forcing a specific language or region.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language instructions and interface text exclusively in Chinese, including the top-level docstring usage examples. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

User-facing stderr/stdout messages and argparse help strings are all hard-coded in Chinese, which enforces a single locale for operation. The file does not provide any language selection mechanism or documented justification for the locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.