Back to skill

Security audit

Editorial Topic Portfolio

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed editorial topic review workflow with cautious Notion preview/readback rules and no working bundled writeback implementation.

Before installing, confirm that any standing Notion auto-sync instruction is explicit, current, and limited to the intended database and fields. Keep Notion credentials in private environment/config only, review generated change previews carefully, and use a separate reviewed write adapter if enabling real writeback.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
- Writing the body directly; hand the primary topic to `industry-deep-dive-pipeline`.
- Generating WeChat layout, summaries, covers, social assets, or publish content directly.
- Writing to Notion without confirmation (unless the current workspace has an explicit, persistent standing instruction authorizing routine-review auto-sync).
- Ranking purely by热度, a single number, or headline spreadability.

## Inputs
Confidence
93% confidence
Finding
The skill permits Notion writeback based on a persistent standing instruction for routine-review auto-sync, which weakens the explicit per-run human confirmation boundary. If that standing authorization is stale, mis-scoped, or mistakenly present, the agent could make unauthorized or incorrect changes to a Notion database, especially because the workflow includes autonomous evaluation and change-set generation before writeback.

Static analysis

No suspicious patterns detected.