Back to skill

Security audit

Ai News Aggregator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed AI and technology news helper with low security impact, though its package appears to omit the scripts it tells the agent to run.

Before installing, confirm you want a Chinese-language AI news workflow that fetches public web/RSS sources. Also verify the referenced scripts are actually included by the package you install, because this reviewed artifact only contains the instruction file.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The natural-language content, including the description, usage guidance, and trigger phrases, is presented only in Chinese. This can amount to a language policy violation when the skill effectively forces a specific language without user opt-in or an explicit region/language limitation.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad, everyday phrases such as requests for 'AI news' or 'what news is there today', which can cause the skill to activate in situations broader than intended. Over-broad activation increases the chance of unintended invocation, context hijacking, or routing user requests into a network-fetching skill without clear user intent.

Static analysis

No suspicious patterns detected.