Back to skill

Security audit

Baidu Hot Cn

Security checks for vulnerabilities and agentic risk

Overview

The skill appears non-destructive, but it advertises live Baidu trend monitoring while actually returning hardcoded mock results.

Install only if you want a demo or template. Do not rely on this skill for real Baidu hot-search monitoring or business decisions unless it is updated to fetch live data and clearly label freshness and source in every output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims live monitoring of Baidu hot searches, trend analysis, and keyword popularity, but the content only describes mock data and hypothetical API use without implementing those capabilities. This mismatch can mislead users and downstream agents into trusting fabricated or stale data as real-time intelligence, which is especially risky for monitoring, research, or business decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very broad everyday terms like '百度' and '热搜', which are likely to activate during ordinary conversation unrelated to explicit skill invocation. Overbroad activation can cause unintended routing, surprising behavior, and accidental disclosure of user intent to a skill that may fetch or fabricate external-topic data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module documentation presents the script as a Baidu hot list fetcher, but the code only serves simulated entries. Misleading documentation increases the chance that users trust the output as authentic external intelligence, creating integrity and decision-making risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises live Baidu hot topics, trends, and keyword popularity, but the implementation always returns hardcoded mock data instead of querying a real Baidu source. This is dangerous because downstream users or agents may make decisions based on fabricated or stale information while believing it is current external data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The user-facing output strings are fixed to Chinese text and the script provides no option to select another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.