Back to skill

Security audit

CN Trends Aggregator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed public trend-fetching tool with some output-safety caveats, but no evidence of hidden persistence, credential access, destructive behavior, or exfiltration of local data.

Install only if you want a Chinese/global hot-trends aggregator that contacts the listed public services. Prefer JSON output for downstream automation, and treat titles, links, and summaries from trend sources as untrusted content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_trends.py:168
Finding

Untrusted Remote Content Is Emitted Without Markdown Escaping

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises executable shell commands and outbound network access in its documentation, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a least-privilege failure: an agent may invoke shell/network capabilities implicitly without a clear policy boundary, increasing the chance of unintended command execution or external data exfiltration if the skill is triggered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad terms such as 'trending', 'hot', 'what's popular', and 'daily briefing', which can match many unrelated user requests. Over-broad activation can cause the wrong skill to run, leading to unnecessary network access, irrelevant content retrieval, or untrusted external data being injected into responses when the user did not specifically ask for this aggregator.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is presented as '中文+全球热榜聚合器' and titled 'CN Hot Trends', implying a Chinese-language experience while also serving global content. There is no statement that users may choose output language or that the Chinese locale is a justified, explicit limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code issues HTTP requests via curl to Baidu, Toutiao, V2EX, Hacker News, and GitHub, which transmits the user's network metadata and possibly proxy usage to external services. Although the script's purpose is to fetch trends, there is no explicit warning in the code or usage text that running it contacts third-party endpoints.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_trends.py (reported line 26)May include surrounding context.

python
cmd += ["--proxy", proxy]
    cmd.append(url)
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 5)
        return result.stdout
    except Exception:
        return None

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/fetch_trends.py (reported line 125)May include surrounding context.

python
def fetch_github_trending(limit=10, proxy=None):
    """Fetch GitHub repos created in last 7 days, sorted by stars."""
    date = (datetime.now() - timedelta(days=7)).strftime("%Y-%m-%d")
    url = f"https://api.github.com/search/repositories?q=created:>{date}&sort=stars&order=desc&per_page={limit}"
    data = curl_fetch(url, proxy=proxy)
    if not data:
        return []

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings indicating the tool is specifically a Chinese-language trends aggregator, and its output labels are partly fixed in Chinese. Under the language/locale policy, forcing a specific language is a violation unless the user is given an explicit language choice or the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.