Back to skill

Security audit

Hackernews Cn

Security checks for vulnerabilities and agentic risk

Overview

This skill appears low-risk, but it overstates live Hacker News monitoring because the shipped script only returns sample data.

Before installing, understand that this appears to be a lightweight demo or formatter for sample Hacker News-style data, not a real HN monitor. It does not show sensitive access or persistence, but users expecting live Hacker News results may be misled unless the publisher updates the docs or implements real retrieval.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes very broad terms such as "HN", "YC", and "创业", which can match many unrelated user requests and cause the skill to activate unexpectedly. While this is not directly code-execution dangerous, over-broad activation can route conversations to the wrong skill, expose unnecessary external-fetch behavior, and degrade trust or safety controls based on correct skill selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest presents this skill as a Hacker News hot-story monitor that gets HN top content, tech discussions, and startup news. However, the code contains no network access, polling, or live data retrieval; it simply slices and formats a predefined in-memory list, so the actual behavior does not match the claimed operational purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The metadata description includes a Chinese-language localized title alongside English, and the tag list explicitly includes "chinese", which suggests the skill may target or prefer a specific language/locale. There is no indication here that users can opt in to a language preference or that the locale restriction is justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file includes Chinese-only natural-language descriptions such as "获取脚本" and the function docstring "获取 HN Top Stories", with no indication that language is user-selectable or that the skill is intentionally region-specific. This can violate language/locale policy because the skill implicitly constrains its interface/documentation to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function documentation says it gets HN Top Stories 'using mock data', while the skill manifest describes obtaining Hacker News hot stories as an actual monitoring/fetch capability. In practice, the function only returns a hardcoded static list and performs no real retrieval or monitoring, which creates an intent-level mismatch between the documented fetch behavior and the implemented behavior.

Content

No source excerpt is available for this finding.