T09 · Insecure Skill Coding Practices
- Location
scripts/news-monitor.py:375- Finding
Untrusted News Content Is Injected into Agent Instructions
- Content
View full analysis
None: ts = datetime.now().strftime("%Y-%m-%d %H:%M:%S") source_name = SOURCE_DISPLAY.get(item["source"], item["source"]) content = item.get("content", "").strip() link = item.get("link", "") msg = ( f"[NEWS_ALERT triggered - judgment required]\n\n" f"Matched keywords: {', '.join(matched_keywords)}\n" f"Source: {source_name}\n" f"Title: {item['title'][:200]}\n" f"{'Link: ' + link if link else ''}\n" f"Trigger time: {ts}\n\n" f"{'Article content:' + chr(10) + content[:2000] + chr(10) if content else ''}\n" f"Alert context:\n{alert.get('context_summary', '(not recorded)')}\n\n" f"Your task:\n" f"1. Read the complete news content and determine whether it is relevant to the alert context.\n" f"2. Keyword matching is only preliminary filtering; ignore irrelevant or unimportant content.\n" f"3. If it is relevant and important, contact the user with analysis and recommendations.\n" f"4. If uncertain, do not send it to avoid noise." ) log.info(f"NEWS_ALERT: [{item['source']}] {item['title'][:60]} | kw={matched_keywords}") deliver_message(alert, msg) ``` The displayed wording above is an English rendering of the original message strings; the executable data flow and formatting operations are unchanged. ### Technical Analysis The monitor retrieves article titles and bodies from external RSS feeds and unofficial news APIs. The remote `title` and `content` fields are inserted directly into the same natural-language message that contains instructions for the receiving OpenClaw agent. Removing HTML does not provide prompt-injection protection. Plain tex ...[truncated 2011 chars]- Remediation
View remediation
