Back to skill

Security audit

RSS News Aggregator

Security checks for vulnerabilities and agentic risk

Overview

This RSS skill is a normal news-fetching tool, but it allows arbitrary feed URLs without safeguards, which can make it risky in shared or server-side environments.

Install only if you trust the feed URLs you will use. Avoid exposing this skill to arbitrary user-submitted URLs until it validates schemes and hosts, blocks private/internal/metadata addresses, enforces timeouts and response-size limits, and pins dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rss_engine.py:82
Finding

Unrestricted Server-Side Feed Retrieval Enables SSRF

Content
View full analysis

Vulnerability Details

File Location: scripts/rss_engine.py:41-43 and scripts/rss_engine.py:82-86
Vulnerability Type: Server-Side Request Forgery (SSRF) and missing network resource controls
Risk Level: High

Vulnerable Code

python
def add_feed(self, url: str, name: str) -> None:
    """添加 RSS 订阅源"""
    self.feeds[name] = url
python
def fetch_feed(self, name: str, url: str, limit: int = 10) -> List[Dict[str, Any]]:
    """抓取单个 RSS 源的文章"""
    articles = []
    try:
        feed = feedparser.parse(url, request_headers={"User-Agent": "RSSAggregator/1.0"})

Technical Analysis

Caller-controlled feed locations are stored without validation and passed directly to the network-capable feedparser.parse() function. The implementation does not restrict URL schemes, destinations, ports, DNS results, or redirects.

An attacker who can configure a feed can therefore cause the runtime host to request loopback, private-network, link-local, or cloud metadata addresses. This constitutes an SSRF primitive when the aggregator is exposed through an application or Agent that accepts untrusted feed URLs.

Although the constructor accepts a timeout value, that value is not used by fetch_feed(). The implementation also lacks response-size limits. A slow or unusually large endpoint could consequently consume worker time, memory, or network resources.

Attack Path

  1. An attacker supplies a feed URL targeting an internal service, a cloud metadata endpoint, or a hostname resolving to a private address.
  2. add_feed() stores the URL without validating its scheme, hostname, port, or resolved IP address.
  3. The application invokes fetch_all() or directly invokes fetch_feed().
  4. feedparser.parse() initiates the request from the victim environment and its trusted network position.
  5. If the response is parseable as RSS or Atom, internal response data may be exposed through article f ...[truncated 861 chars]
Remediation
View remediation

Remediation Suggestions

  • Permit only explicitly supported URL schemes, preferably https, with http enabled only when necessary.
  • Reject URLs containing embedded credentials, malformed hosts, unsupported ports, or non-network schemes.
  • Resolve hostnames before connecting and reject loopback, private, link-local, multicast, reserved, and unspecified IP address ranges for both IPv4 and IPv6.
  • Repeat destination validation after every redirect and protect against DNS rebinding by ensuring the validated address is the address actually contacted.
  • Explicitly block cloud metadata destinations, including link-local metadata addresses.
  • Use a controlled HTTP client with separate connection and read timeouts, then pass the bounded response body to feedparser.parse().
  • Disable redirects or impose a small redirect limit.
  • Enforce maximum response and decompressed-body sizes.
  • Consider an allowlist of trusted feed domains where the deployment permits it.
  • Add tests covering private and loopback addresses, IPv6 literals, redirects to internal destinations, DNS rebinding protections, slow responses, and oversized responses.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned Dependencies Permit Non-Reproducible and Unreviewed Package Resolution

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-3
Vulnerability Type: Insecure dependency version constraints and missing integrity verification
Risk Level: Low

Vulnerable Code

text
feedparser>=6.0.0
requests>=2.31.0
html2text>=2024.2.26

Technical Analysis

All dependencies use open-ended minimum-version constraints. No lock file or package hashes are present. Consequently, separate installations can resolve to different, unreviewed future package versions.

This does not establish that any listed package is currently malicious. The weakness is that installation is neither reproducible nor integrity-pinned, increasing exposure to a future compromised release, an unexpected behavioral change, or an incompatible transitive dependency.

Attack Path

  1. A future release of a declared dependency or one of its transitive dependencies is compromised or contains unsafe behavior.
  2. A user runs pip install -r requirements.txt.
  3. The package resolver selects the newer version because the >= constraint permits it.
  4. Package installation hooks or imported runtime code execute in the user's environment.
  5. The compromised package operates with the privileges and data access of the installing or running process.

Impact Assessment

Exploitation depends on compromise or unsafe behavior in a future dependency release. If that occurs, package code could execute with the privileges of the installation or application process and may access the same files, environment variables, credentials, and network resources as that process.

The affected scope includes environments that install dependencies from this unconstrained requirements file. The current audit found no evidence that the named packages themselves are malicious.

Remediation
View remediation

Remediation Suggestions

  • Pin each direct dependency to an exact reviewed version.
  • Generate and commit a lock file that includes resolved transitive dependencies.
  • Record cryptographic hashes and install with pip --require-hashes.
  • Retrieve packages only from an approved package index over authenticated TLS.
  • Use automated dependency scanning and review updates before changing pinned versions.
  • Rebuild the lock file in a controlled environment and verify package provenance where supported.
  • Remove the unused requests dependency if it is not required after network retrieval is redesigned.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is written as a Chinese-only natural-language instruction line, while the document otherwise includes English headings and examples. This creates a language/locale constraint without opt-in or justification, which matches the policy-violation rule for forced language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and all user-facing print strings in this example are written in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. Under the policy, language-specific behavior is only acceptable when the skill offers a choice or clearly documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly centers on RSS aggregation and news fetching, which necessarily involves outbound network access to third-party sources, but the description does not warn users that external HTTP requests will be made. This can mislead users about data flow, privacy exposure, and network behavior, especially in restricted or monitored environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency specification uses a lower-bound constraint (feedparser>=6.0.0) instead of pinning an exact version, which makes builds non-reproducible and can cause the environment to resolve to a vulnerable or untested release in the future. In a skill context, this increases supply-chain uncertainty because security posture depends on whatever version is installed at deploy time rather than a reviewed version.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
feedparser>=6.0.0
requests>=2.31.0
html2text>=2024.2.26

Unverifiable Dependency: feedparser has 10 known advisory(ies) (CVE-2011-1157 (feedparser Cross-site Scripting vulnerability); CVE-2009-5065 (feedparser Cross-site Scripting vulnerability); CVE-2011-1158 (feedparser Cross-site Scripting vulnerability) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

feedparser has known historical advisories, and because the manifest does not pin a specific version, it is impossible to verify from this file alone whether deployment will use a fixed or affected release. The main danger here is uncertainty: the skill may resolve to a version with known flaws depending on installation time and environment.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The requirement requests>=2.31.0 is not pinned to a single reviewed version, so dependency resolution may install different releases over time, including ones later found vulnerable or behaviorally incompatible. Because requests is often used for network access, leaving version selection open adds avoidable supply-chain and maintenance risk.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
feedparser>=6.0.0
requests>=2.31.0
html2text>=2024.2.26

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

requests has multiple published advisories, and the use of a non-exact version specifier prevents verification that the installed release includes necessary fixes. Since requests commonly handles outbound HTTP and may process attacker-influenced URLs or credentials, unresolved version ambiguity can materially increase exposure.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency html2text>=2024.2.26 is unpinned, which means future installations may silently pull newer versions that have not been tested or security-reviewed for this skill. This is a classic dependency hygiene issue that weakens reproducibility and increases supply-chain exposure.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
feedparser>=6.0.0
requests>=2.31.0
html2text>=2024.2.26

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file includes user-facing natural-language descriptions such as the module docstring and class docstring entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This test file includes human-facing natural-language text in Chinese ("RSS News Aggregator 单元测试") rather than offering a language choice or documenting that the skill is intentionally locale-specific. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The comment at L094 is a natural-language instruction in Chinese, and the final status message at L109 also forces Chinese output for human readers. Because no locale choice or justification is provided, this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.