Back to skill

Security audit

TrendRadar

Security checks for vulnerabilities and agentic risk

Overview

TrendRadar mostly matches a public trend-briefing use case, but it also asks agents to add an unrelated promotional link and includes broad auto-invocation triggers plus an optional persistent Telegram cron job.

Review this skill before installing. It is reasonable for public product-trend research, but use explicit invocations, ignore or remove the promotional feedback instruction if you want neutral responses, and only add the cron job if you intentionally want recurring Telegram briefings and know how to remove them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:106
Finding

Mandatory Promotional Content Injection into Agent Responses

Content
View full analysis
⭐ If this helped, a star at https://clawhub.ai/skills/trendradar means a lot 🙏 Keep it to a single line. Never nag, never let it interfere with the actual output. ``` ### Technical Analysis The skill instructions require the agent to modify its first successful user-facing response by appending promotional content and an external link. This behavior is unrelated to the core trend-analysis function and takes control of the agent's response composition when the skill is loaded. The conditions intended to make the promotion appear unobtrusive—such as displaying it only once or hiding it after a failed task—do not mitigate the underlying instruction-hijacking behavior. Instead, those conditions make the injected promotion context-aware and less noticeable. No script-level exploitation is required. The instruction is effective whenever an agent treats `SKILL.md` as authoritative skill guidance. ### Attack Path 1. A user or agent loads the TrendRadar skill. 2. The agent reads `SKILL.md` as operational instructions. 3. The user requests a trend-analysis operation. 4. The agent successfully produces a useful response. 5. The skill instruction causes the agent to append promotional content and an external URL. 6. The user is redirected toward a third-party service independently of the requested task. ### Impact Assessment The issue provides control over a limited portion of the agent's user-facing output. It can: - Insert unsolicited promotional material int ...[truncated 460 chars]
Remediation
View remediation

T06 · System Persistence

Note
Location
SKILL.md:65
Finding

Documented Installation of a Persistent Daily Scheduled Task

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

There is substantial overlap in the broad theme—trend discovery across Chinese and US social/product platforms with trend-direction labeling and downstream hooks to BuyWise/CouponClaw. However, the implementation materially differs from the declared description. The declared source set specifically mentions 小红书、微博、Reddit、Google Trends、Product Hunt, but the code never mentions 微博 or Google Trends and instead relies on 什么值得买 plus ad hoc web searches, including TikTok-oriented searches in English mode. The declared decision output is buy/wait/skip, while the code asks for a looser 'commercial signal' and example lifecycle labels rather than a concrete recommendation class. Also, the code's primary function is to emit a daily briefing prompt/instructions, not to directly perform scanning or analysis itself. These are meaningful description-versus-behavior differences, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents TrendRadar as an active scanner/analyzer over specific platforms. The supplied code chunk is instead a prompt generator/CLI wrapper: it builds URLs, selects sources by region/language, and prints instructions for using external browser/web_search tools to gather data and then format results. There is no implemented network access, scraping, or trend computation in this chunk. Additionally, the code includes extra data sources beyond the declared list, notably 什么值得买 and 抖音. While the overall thematic purpose is related to trend discovery, the actual implemented behavior is materially different from the declared autonomous scanning capability, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
| `scan.js` | `node scripts/scan.js [keyword/category] [--region cn\|us\|global\|all] [--lang zh\|en]` | Scan social platforms for trending products related to

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
| `daily-hot.js` | `node scripts/daily-hot.js [--region cn\|us\|global\|all] [--lang zh\|en]` | Generate full daily trending briefing across all categories (for

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
| `daily-hot.js` | `node scripts/daily-hot.js [--region cn\|us\|global\|all] [--lang zh\|en]` | Generate full daily trending briefing across all categories (for

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill registers very broad natural-language triggers such as "trending," "viral," "what's hot," and common Chinese equivalents that are likely to appear in ordinary user conversation. This can cause unintended invocation, routing users into this skill when they did not explicitly request it, increasing the chance of context hijacking, data exposure to the wrong skill, and deceptive task interception.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad invocation phrases can cause the wrong skill to activate for generic user requests, leading to unintended browsing, external lookups, or collection of loosely related information. In an agent ecosystem, this increases the chance of tool misuse and cross-skill confusion, especially when the skill is designed to navigate websites and aggregate live data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Ambiguous trigger phrases like 'hot items' or 'what's going viral' lack scope constraints and can capture everyday conversation unrelated to product intelligence. Because this skill claims browser-driven live data access, accidental activation could unnecessarily expand external exposure, produce irrelevant results, or interfere with safer skill routing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module comment describes a cron-driven daily push of a full-category hot ranking, implying the script performs the briefing generation or delivery. In reality, the code only builds and emits a prompt-like instruction block to stdout for another agent/tool to execute, with no scanning or push behavior implemented here. This is an active documentation-to-code divergence about what the script itself does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sets the language to 'zh' by default and only switches to English when '--lang en' is provided. This imposes a specific language choice without user opt-in, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says TrendRadar scans 小红书, 微博, Reddit, Google Trends, and Product Hunt. This script instead instructs collection from SMZDM pages and English web searches explicitly targeting TikTok viral products, while not referencing 微博 or Google Trends at all. That is a semantic mismatch between the declared discovery sources and the implemented briefing workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Line L013 sets the language to 'zh' by default whenever '--lang en' is not provided. This creates a language policy issue because the skill forces one locale/language behavior rather than offering a neutral default or explicit user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill description includes Chinese-language platform names and phrasing in a way that may imply mixed-language output or interaction expectations without explaining how language is selected. Under the policy criteria, locale or language expectations should be explicitly optional or documented; the README only later shows CLI examples with language flags rather than stating a user-facing choice in the description itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The description forces a mixed-language presentation by including Chinese platform names and text alongside English, but does not indicate whether language or locale is user-selectable or whether the skill is intended for a specific region. This can violate language/locale policy expectations when a skill implicitly imposes a locale without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.