Back to skill

Security audit

知乎热榜选题

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches public Zhihu hot-topic data and prints a local analysis, with no evidence of credential use, persistence, exfiltration, or destructive behavior.

Before installing, be aware that running the skill contacts Zhihu over the network and may expose normal request metadata such as IP address and User-Agent to Zhihu. Install Python dependencies in a virtual environment, preferably from pinned requirements if the publisher adds them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
scripts/zhihu_topics.py:4
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis

Vulnerability Details

File Location: scripts/zhihu_topics.py, lines 4-7
Vulnerability Type: Unpinned dependency installation from the default package registry
Risk Level: Low

Vulnerable Code

python
try:
    import requests
except ImportError:
    print("请安装 requests: pip3 install requests")
    sys.exit(1)

Technical Analysis

When the requests module is unavailable, the script instructs the user to install it using pip3 install requests. This command retrieves the package and its transitive dependencies from the environment's default Python package index without constraining the version or validating package hashes.

The dependency name is legitimate and is not itself evidence of a malicious package. However, the installation guidance provides no reproducibility or integrity controls. A compromised package release, compromised package-index account, unsafe custom package index, or maliciously configured package mirror could therefore supply code that was not reviewed with this project.

The issue requires a separate installation action by the user and does not cause the Skill itself to download or execute a remote payload automatically.

Attack Path

  1. A user runs the Skill in an environment where requests is not installed.
  2. The script prints an instruction to run pip3 install requests.
  3. The user executes that command against the configured default package index or mirror.
  4. The selected package version or one of its dependencies has been compromised, substituted, or maliciously served.
  5. Package-controlled code is installed into the Python environment.
  6. The malicious code can execute through installation behavior, imported package initialization, or later use of the dependency.

This exploitation path is conditional on both user action and compromise or malicious configuration of the applicable package supply chain.

Impact Assessment

A malicious dependency could execute with the privileges of the us ...[truncated 555 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare requests in a version-controlled dependency file rather than displaying an unconstrained installation command.
  2. Pin the dependency to a reviewed version, for example:
text
requests==<reviewed-version>
  1. For stronger integrity protection, generate and verify cryptographic hashes and install with:
bash
python3 -m pip install --require-hashes -r requirements.txt
  1. Pin and hash all transitive dependencies, not only the direct dependency.
  2. Use a reviewed package index or trusted internal mirror and ensure package-index configuration cannot silently redirect installations to an untrusted source.
  3. Install dependencies inside a dedicated virtual environment with no administrative privileges.
  4. Replace the current message with instructions referencing the project's reviewed requirements file, such as:
python
try:
    import requests
except ImportError:
    print("Install the audited dependencies with: python3 -m pip install --require-hashes -r requirements.txt")
    sys.exit(1)
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a Python script that appears to require network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a transparency and policy-enforcement gap: an agent may execute network-capable code without an explicit declaration, making review, sandboxing, and user consent harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases like '搜一下知乎' or '知乎有什么热点' are broad enough to match ordinary user conversation, which can cause the skill to activate unexpectedly. Unintended activation may launch networked code and fetch external data without clear user intent, increasing the risk of surprise actions and privilege misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is entirely presented in Chinese and is explicitly targeted at Zhihu content analysis, but it does not state that the language/locale is a user choice or a justified region-specific constraint. This can violate language or locale policy when the skill is used in broader environments without clear opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This code makes HTTP requests to zhihu.com at L15 and L20, which transmits system/network metadata such as IP address and the specified User-Agent. While the behavior is central to the script's purpose, the file itself provides only terse Chinese docstrings and no explicit user-facing notice that external network access will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is entirely in Chinese ("知乎选题分析器"), which indicates a fixed language choice without any visible user opt-in or alternative locale support. This can violate language/locale policy when users are not informed that the skill is Chinese-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.