Back to skill

Security audit

Ai News Zh.Bak

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese AI-news collection and delivery workflow, with no hidden code, credential handling, or destructive behavior found.

Install this if you want a Chinese-language AI news briefing workflow. Before enabling scheduled delivery, manually run it once, check the generated content, and confirm the exact Feishu, Telegram, or Discord destination to avoid posting to the wrong place.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L03 明确将英文资讯“自动翻译整理为中文”,整体描述将中文作为固定输出语言,但文档没有提供用户选择其他语言或显式中文 opt-in 的机制。根据语言/locale 政策要求,强制固定语言输出而无选择属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises automatic delivery to external messaging platforms without clearly warning that content will be sent outside the local agent context. This can lead to unintended disclosure, spam, or posting to the wrong destination if channels are misconfigured or if the skill is triggered without the user's immediate awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manual trigger phrase is a very generic natural-language request that overlaps with ordinary user intents, making accidental invocation plausible. In a skill that performs web collection and can later push content to external channels, broad trigger wording increases the chance of unintended data fetching or workflow execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The formatting rules explicitly require headlines to be in Chinese, and the template content is entirely Chinese-oriented. This is a natural-language locale constraint with no user opt-in or documented justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The note states that all English-language content is automatically translated to Chinese. This is a natural-language locale policy concern because it forces a specific output language without indicating any user choice, opt-in, or context justifying the restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.