Back to skill

Security audit

Indie Maker News

Security checks for vulnerabilities and agentic risk

Overview

This skill is a public news/RSS aggregator with some documentation inconsistencies but no evidence of credential access, persistence, destructive behavior, or hidden data collection.

Before installing, expect the skill to make outbound requests to public news/RSS/API sources and to present output in Chinese. The publisher should clean up the stale local-only/no-external-API claims so users understand exactly which sources are contacted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README presents all user-facing natural language exclusively in Chinese and does not state that the skill is region-specific or that another language can be used. Under the policy for natural-language violations, forcing a specific language without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable scripts that fetch data from multiple external RSS/API sources, but the manifest declares no explicit tool scope or permissions. This creates an authorization and review gap: users and platforms cannot clearly see that the skill requires network access, increasing the chance of silent outbound requests or future expansion of remote data collection without adequate scrutiny.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents all user-facing text exclusively in Chinese, including the title, descriptions, and source labels. That imposes a specific language/locale on users without offering any choice or documenting a justified region-specific constraint, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring is entirely in Chinese and presents the skill as a fixed-language experience, with no indication that users can choose another language or locale. This matches the policy category for language/locale constraints expressed in natural language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The SKILL.md text presents the skill as '安全可靠、零配置' and 'Python标准库实现,零外部依赖' for the advertised standalone path, yet later states that a separate script can use a locally deployed NewsNow container to obtain more data sources. This creates intent-level inconsistency inside the documentation about whether the skill is purely standalone or can depend on an external local service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The package description is entirely in Chinese and presents the skill as a Chinese-language news/radar experience, but the file does not indicate that language selection is optional or that the skill is explicitly limited to a Chinese-speaking audience. Under the policy, fixed language behavior without opt-in or clear justification can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes a narrowly focused news skill centered on '一人公司、副业、创业变现资讯' with intelligent categorization and action orientation. However, the configured sources include broad front pages and general technical/community feeds such as Hacker News, GitHub Trending, V2EX programmers, and Juejin, which are not inherently monetization-focused and expand the skill into general tech-news aggregation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description states the tool's purpose entirely in Chinese, and later runtime output is also Chinese-only. This creates a language/locale policy issue because the skill forces a specific language without user opt-in or justification that it is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script prints operational messages and labels such as progress, startup text, and result fields only in Chinese. Because there is no language selection or explicit region-specific justification, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language strings and user-facing output are entirely in Chinese, including the program description and runtime messages. Because the script does not offer any language selection or indicate that it is intentionally limited to a Chinese-speaking or region-specific audience, it presents a locale-policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s docstrings and user-facing output context are written entirely in Chinese, indicating a fixed language choice rather than offering localization or user opt-in. Under the policy rule, forcing a specific language without documented choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.