Back to skill

Security audit

Zhihu Hot CN

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to fetch and format public Zhihu hot-list data, with some overstated documentation but no evidence of credential access, persistence, or destructive behavior.

Install only if you are comfortable with a script fetching mutable public data from GitHub and formatting it locally. Do not rely on its JSON output for security-sensitive automation without adding proper JSON escaping and input validation, and expect some advertised features to be missing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get-hot.sh:52
Finding

Unsafe Serialization of Remote Content into JSON

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

该代码的核心功能与“获取知乎热门话题、问题”部分基本相关,但声明存在明显夸大和资源来源不一致。实际代码只是从 GitHub 仓库的 README 中抽取热榜条目并格式化输出,不是直接从知乎获取数据;同时没有实现任何趋势分析、历史对比、监控或告警逻辑。因此描述未准确反映真实行为,属于部分但实质性不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description and usage documentation are entirely in Chinese, and the title explicitly includes 'CN', which suggests a fixed language/locale experience. The file does not offer an English alternative, user opt-in, or a clear justification that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill metadata and user-facing documentation are entirely in Chinese, and the skill name includes a locale marker ('cn'), which indicates a language/locale constraint. The file does not mention that Chinese is optional or that alternative languages are supported, so this appears to impose a locale choice without explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The package description is entirely in Chinese, which indicates the skill is presented in a specific language without offering user opt-in or documenting that it is intentionally limited to Chinese-speaking users. Under the policy, language-specific behavior should either offer a choice or clearly justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language comments and user-facing output strings are written in Chinese, and the skill does not indicate any language choice or opt-in. Under the policy, forcing a specific language without user selection can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs an HTTP request with curl to retrieve remote content, but the operation is silent (-s) and there is no user-facing notice before or during the fetch. For code files, network calls that transmit or retrieve data should have some visible disclosure unless the behavior is clearly communicated elsewhere in the skill description, which is not available here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.