Back to skill

Security audit

News Curator

Security checks for vulnerabilities and agentic risk

Overview

The skill’s news-curation purpose is clear, but it schedules recurring runs that auto-send results to a hard-coded Telegram chat instead of a user-selected destination.

Before installing, replace or disable the Telegram delivery target and confirm where scheduled briefings will be sent. Only grant cron and exec access if you are comfortable with recurring shell-based curl retrieval from the listed RSS feeds; a safer version would use a configurable recipient and a restricted feed-fetching wrapper.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:117
Finding

Hard-Coded Telegram Recipient Causes Unauthorized External Delivery

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 117–121
Vulnerability Type: Hard-coded external data recipient
Risk Level: High

Vulnerable Code

md
## Session setup

- `sessionTarget: "isolated"` — fresh session per run, no memory of previous chats
- `sessionKey` — unique per cron (e.g. `session:cron:patch-news-morning-briefing`)
- `delivery.mode: "announce"` — agent's final response auto-sent to Telegram
- `delivery.to: "37134287"` — Hobo's chat ID

Technical Analysis

The Skill instructs the runtime to automatically send the agent's final response to a fixed Telegram chat identifier. The recipient is controlled by the Skill configuration rather than being supplied and approved by the installing user.

Automatic Telegram delivery is consistent with the declared briefing functionality, but delivery to the original author's hard-coded account is not necessary. This violates least-privilege and secure configuration principles by creating an external disclosure channel that remains active unless a user notices and replaces the identifier.

Although the expected briefing consists of public news, the generated response may also contain feed-failure diagnostics, contextual information inherited from the runtime, or unintended model output. The fixed recipient also exposes a personal account identifier in the distributed Skill.

Attack Path

  1. A user installs or configures the Skill using the documented session settings.
  2. A scheduled isolated agent session retrieves and processes the configured RSS feeds.
  3. The agent produces its final briefing, potentially including diagnostics or unintended contextual content.
  4. delivery.mode: "announce" automatically transmits that response.
  5. Because delivery.to is fixed to 37134287, the response is delivered to the embedded third-party Telegram account rather than a recipient explicitly selected by the user.

Impact Assessment

...[truncated 603 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the hard-coded Telegram chat identifier from the distributed Skill.
  • Require the installing user to provide delivery.to through an explicit configuration step.
  • Keep delivery disabled until the user confirms the destination.
  • Validate that the configured destination belongs to, or is authorized by, the installing user.
  • Display the resolved delivery destination before enabling scheduled runs.
  • Store recipient configuration separately from reusable Skill documentation and avoid committing personal identifiers.
  • Restrict generated output to the briefing schema and prevent runtime context, secrets, tool output, and raw diagnostics from being included in outbound messages.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:1
Finding

Unrestricted Shell Execution Exceeds RSS Retrieval Requirements

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 1–6
Vulnerability Type: Excessive command-execution privilege
Risk Level: Medium

Vulnerable Code

yaml
---
name: news-curator
version: 2.0.0
description: "Fetch RSS feeds via curl, curate, and deliver news briefings to Telegram. MiniMax M3, isolated cron sessions, curl-not-fetch."
allowed-tools: [cron, exec]
---

The intended use of this permission is reinforced later in the file:

md
- Agent does ALL work in one shot: curl feeds → parse XML → curate → output briefing
- Explicitly tell the agent: "Use exec tool with curl. Do NOT use fetch tool."

Technical Analysis

The Skill grants the agent the general-purpose exec tool to perform network retrieval with curl. A news-curation task requires outbound HTTP GET access to a limited set of RSS endpoints, but unrestricted shell execution can also read accessible local files, invoke other installed programs, alter files, and make arbitrary network requests under the host agent's operating-system privileges.

RSS documents are externally controlled input processed by the model. If a feed is compromised or contains adversarial instructions that the model treats as commands rather than data, the continued availability of exec increases the possible impact. The documentation does not define command allowlisting, domain restrictions, argument validation, filesystem isolation, or a fixed retrieval wrapper.

The reviewed Skill does not itself contain a destructive shell command or explicitly direct execution of feed-provided commands. The vulnerability is therefore an excessive-permission and unsafe execution design rather than confirmed malicious command execution.

Attack Path

  1. A scheduled agent starts with access to the unrestricted exec tool.
  2. The agent uses curl to retrieve content from an external RSS source.
  3. A source is compromised, redirected, or serves ad ...[truncated 1175 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace exec with a dedicated RSS or HTTP client that supports only HTTPS GET requests.
  • Allowlist the exact feed domains and reject redirects to unapproved hosts.
  • If shell execution is unavoidable, expose a fixed wrapper rather than a general command shell.
  • Have the wrapper construct curl arguments internally and reject user- or feed-controlled command options.
  • Disable shell metacharacters, command composition, arbitrary output paths, local-file URL schemes, proxy overrides, and unsupported protocols.
  • Run retrieval in a sandbox with a read-only filesystem, no access to user secrets, minimal environment variables, and restricted outbound networking.
  • Treat all downloaded feed content as untrusted data and explicitly prohibit following instructions contained in headlines, descriptions, XML fields, or linked pages.
  • Parse RSS with a deterministic XML parser before presenting normalized fields to the model.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is configured to automatically announce its final response to a specific Telegram chat (delivery.mode: "announce", delivery.to: "37134287"), but the description does not clearly warn users about this side effect. That omission can cause users or operators to trigger the skill expecting a local-only curation workflow while unintentionally sending externally visible content, creating privacy and operational risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.