T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_trends.py:168- Finding
Untrusted Remote Content Is Emitted Without Markdown Escaping
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed public trend-fetching tool with some output-safety caveats, but no evidence of hidden persistence, credential access, destructive behavior, or exfiltration of local data.
Install only if you want a Chinese/global hot-trends aggregator that contacts the listed public services. Prefer JSON output for downstream automation, and treat titles, links, and summaries from trend sources as untrusted content.
scripts/fetch_trends.py:168Untrusted Remote Content Is Emitted Without Markdown Escaping
The skill advertises executable shell commands and outbound network access in its documentation, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege failure: an agent may invoke shell/network capabilities implicitly without a clear policy boundary, increasing the chance of unintended command execution or external data exfiltration if the skill is triggered.
The trigger list includes broad terms such as 'trending', 'hot', 'what's popular', and 'daily briefing', which can match many unrelated user requests. Over-broad activation can cause the wrong skill to run, leading to unnecessary network access, irrelevant content retrieval, or untrusted external data being injected into responses when the user did not specifically ask for this aggregator.
The skill is presented as '中文+全球热榜聚合器' and titled 'CN Hot Trends', implying a Chinese-language experience while also serving global content. There is no statement that users may choose output language or that the Chinese locale is a justified, explicit limitation.
The code issues HTTP requests via curl to Baidu, Toutiao, V2EX, Hacker News, and GitHub, which transmits the user's network metadata and possibly proxy usage to external services. Although the script's purpose is to fetch trends, there is no explicit warning in the code or usage text that running it contacts third-party endpoints.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd += ["--proxy", proxy]
cmd.append(url)
try:
result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 5)
return result.stdout
except Exception:
return None
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
def fetch_github_trending(limit=10, proxy=None):
"""Fetch GitHub repos created in last 7 days, sorted by stars."""
date = (datetime.now() - timedelta(days=7)).strftime("%Y-%m-%d")
url = f"https://api.github.com/search/repositories?q=created:>{date}&sort=stars&order=desc&per_page={limit}"
data = curl_fetch(url, proxy=proxy)
if not data:
return []
This code file contains natural-language strings indicating the tool is specifically a Chinese-language trends aggregator, and its output labels are partly fixed in Chinese. Under the language/locale policy, forcing a specific language is a violation unless the user is given an explicit language choice or the constraint is clearly justified as region-specific.
No suspicious patterns detected.