Back to skill

Security audit

全网热点聚合

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a hot-news briefing purpose, but it automatically sends generated content to Feishu and forces unreviewed third-party links and remote-supplied Markdown into that message.

Review this skill before installing. It does not appear to steal secrets or persist on the system, but it is designed to post generated reports to Feishu and includes fixed external footer links plus unsanitized links from remote hot-list sources. Use it only where Feishu posting is intended, and prefer a version that previews the exact message, validates links, and asks for approval before sending.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/format.js:91
Finding

Forced Third-Party Link Injection Through Mandatory Skill Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/format.js:85
Finding

Untrusted Remote Titles and URLs Are Embedded in Markdown Without Validation

Content
View full analysis
({ title: item.Title || item.title || item.word || '', url: item.Url || item.url || '', rank: i + 1, platform: '头条' })).filter(item => item.title); ``` `scripts/index.js:103-106`: ```js return hotList.slice(0, 50).map((item, i) => ({ title: item.word || item.raw_word || '', url: item.appUrl || `https://www.baidu.com/s?wd=${encodeURIComponent(item.word || '')}`, rank: i + 1, platform: '百度' })).filter(item => item.title); ``` `scripts/index.js:128-133`: ```js const rawUrl = m[1]; const title = m[2].trim(); const url = rawUrl.startsWith('http') ? rawUrl : `https://tophub.today${rawUrl}`; if (title && !title.includes('href')) { results.push({ title, url, rank: count + 1 }); count++; } ``` `scripts/format.js:85-87`: ```js topics.slice(0, 5).forEach((t, i) => { const platStr = t.topics.map(tp => `${tp.platform.replace('今日头条','头条')}#${tp.rank}`).join(' · '); lines.push(`### ${i+1}. [${t.title}](${t.url})`); ``` ### Technical Analysis Titles and URLs received from remote APIs or scraped HTML are stored and subsequently interpolated directly into Markdown. The formatter does not escape Markdown control characters in titles and does not parse, normalize, or validate URLs before placing them in link destinations. A malicious or compromised upstream source could supply a title containing characters such as `]`, `(`, newlines, or other Markdown syntax to alter the intended message structure. An upstream source could also provide a deceptive URL, an unexpected hostname, or a non-HTTPS scheme. The `startsWith('http')` check used for TopHub content is not a sufficient URL validation mechanism because it neither verifies ...[truncated 1383 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill’s declared purpose is to fetch and summarize hot topics, but the instructions also entail undeclared external network access, local file creation, and downstream transmission behavior not clearly surfaced in the metadata. This mismatch reduces user visibility into what the skill actually does and can lead to unintended data handling or execution of broader actions than the user expects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
1. 抓取数据:`node ./scripts/index.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
2. 读取并聚类:`node ./scripts/format.js`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs sending generated hot-topic output to Feishu, which is an external transmission step, but does not require explicit user consent or provide a warning before exfiltrating content. Even if the data appears public, automatic outbound delivery can leak sensitive context such as user prompts, derived summaries, or organizational usage patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description and operational instructions are entirely in Chinese and constrain the model to a fixed output process without indicating that users may choose another language. This can violate language/locale policy when no user opt-in or documented locale limitation is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file contains user-facing natural language in Chinese in its header comments and generated markdown output, such as the title and platform labels. Under the policy, forcing a specific language without user opt-in can be a locale policy violation unless the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTTP request headers hard-code Accept-Language: zh-CN,zh;q=0.9, which imposes a specific locale preference in all requests. This is a natural-language/locale policy concern because the skill does not offer user opt-in or explain why a Chinese locale is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.