Back to skill

Security audit

AI 热点工作台

Security checks for vulnerabilities and agentic risk

Overview

This skill collects public AI news feeds and guides an agent to prepare a Chinese briefing, with no evidence of credential access, persistence, destructive behavior, or hidden execution.

Reasonable to install if you want a Chinese daily AI-news briefing. Treat collected feed items as untrusted leads: verify important claims with primary sources, avoid using --insecure except for one-off local debugging, and prefer HTTPS/primary-source links for anything consequential.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/collect_ai_hot_news.py:33
Finding

External Feed Integrity Can Be Bypassed Through Plaintext HTTP and Disabled TLS Verification

Content
View full analysis
bytes: request = urllib.request.Request( url, headers={"User-Agent": "Codex AI hot news collector/1.0"}, ) context = ssl._create_unverified_context() if insecure else None with urllib.request.urlopen(request, timeout=timeout, context=context) as response: return response.read() ``` ```python for feed, region in selected_feeds(region_filter): try: payload = fetch(feed, insecure=insecure) for candidate in iter_items(feed, payload, region): published = published_dt(candidate) if published is None or published >= cutoff: candidates.append(candidate) ``` The documented workflow also exposes the insecure mode: ```markdown 1. Get current candidates from live sources. Prefer the bundled collector: python scripts/collect_ai_hot_news.py --hours 24 --region all --limit 40 --output /tmp/ai-hot-news.json 2. If the local Python certificate store is broken, fix the certificate store first. For a one-off local debug run only, use `--insecure` and ...[truncated 2452 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is clearly related to AI hotspot monitoring and China/global AI news collection, so the topic domain matches the description. However, the declared purpose describes a full daily briefing workflow that sends a concise Chinese briefing to the user's Codex workbench. The actual script only collects candidate items from RSS/Atom feeds, applies keyword-based scoring and China-specific heuristics, deduplicates/ranks them, and emits JSON. Its own docstring explicitly says it performs collection and coarse filtering only, and that an agent should still verify, rank, and summarize the final briefing. There is no code for Chinese summarization, workbench delivery, or scheduling. Therefore the description overstates the implemented behavior in materially important ways.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill when the user asks for 'daily AI news', 'AI briefings', or 'AI hotspot monitoring', which are broad natural-language phrases rather than tightly scoped activation conditions. Without explicit exclusions or narrower trigger constraints, these phrases could cause unintended invocation for general conversation about AI news.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file description requires 'sending a concise Chinese briefing' and later instructions repeatedly require output in Chinese. This imposes a language choice by default without indicating that the user can opt into another language or that the locale restriction is mandatory for a documented regional purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The overview says the workflow 'returns a Chinese briefing' as a fixed behavior. This is a natural-language locale constraint that does not provide user choice or explain a necessary policy/compliance basis for forcing Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt hard-codes Chinese output regardless of the user's language preference or explicit consent. This can override user intent, create privacy or usability issues in multilingual contexts, and is a prompt-quality/security concern because the skill imposes behavior not clearly scoped by the user's request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L61 explicitly instructs that the final output must 'Use Chinese.' This is a natural-language locale policy constraint that forces a specific language without indicating user opt-in or allowing alternative language preferences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The --insecure flag causes fetch() to use ssl._create_unverified_context(), disabling certificate validation for all HTTPS feed requests. This enables man-in-the-middle tampering of fetched RSS/Atom content, so an attacker on the network path could inject spoofed news items or malicious links into the generated briefing output. In a news-collection skill, even though the script does not execute remote code, integrity of upstream content is central, so weakening TLS materially increases risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/collect_ai_hot_news.py:230