Back to skill

Security audit

Trend Scope Report

Security checks for vulnerabilities and agentic risk

Overview

TrendScope appears to generate the promised public-opinion reports, but it sends API keys and report queries over unencrypted HTTP and creates unsafe HTML reports.

Review before installing. Do not use this skill with sensitive searches or production API keys unless the API endpoint is changed to verified HTTPS and generated reports safely escape all untrusted data. If used anyway, treat saved reports as sensitive files and be aware that opening HTML reports contacts a third-party CDN.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_cli.py:32
Finding

API Credential and Sensitive Query Data Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_cli.py:659
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
📰 {platform} 👤 {author} 🕐 {pub_time}
摘要:{summary[:100]}{"..." if len(summary) > 100 else ""}
''' ``` The user-provided query is also embedded directly in the document: ```python html = f''' 舆情分析报告 - {query[:30]} ``` ```python

📊 舆情分析报告

查询关键词: {query} | 生成时间: {now}

``` API data is inserted directly into an executable JavaScript context using Python list formatting rather than safe JSON serialization: ```python # Time trend data trend_data = aggregation.get("publishTimeTrend") or [] trend_labels = [item.get("key", "") for item in trend_data[-24:]] trend_values = [item.get("docCount", 0) for item in trend_data[-24:]] ``` ```python
Remediation
View remediation
`, `&`, and especially the `` - `">` - `javascript:alert(1)` - `` - Quotes, angle brackets, and ampersands in titles and URLs 12. Treat all API-returned article and aggregation fields as untrusted even after HTTPS is implemented. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/report_cli.py:722
Finding

Generated Reports Load Executable JavaScript from an External CDN without Integrity Verification

Content
View full analysis
``` The same dependency appears in the bundled report template: ```html 江苏省医疗卫生舆情分析报告 ``` ### Technical Analysis Every time a generated report is opened with network connectivity, the browser retrieves and executes JavaScript from jsDelivr. Although a specific ECharts version is selected, the document does not provide a Subresource Integrity hash. Therefore, the browser verifies the CDN's TLS certificate but does not verify that the returned file is the exact artifact reviewed by the Skill author. This makes the report dependent on executable content delivered after the Skill itself was audited. Compromise of the CDN, package distribution path, or served artifact could change report behavior without modifying the local Skill package. Opening the report also discloses network metadata, such as the viewer's IP address and request headers, to the external CDN. The report is not fully functional offline. ### Attack Path 1. The CLI generates an HTML report containing the external script reference. 2. The user opens the report in a browser while connected to the network. 3. The browser requests ECharts from jsDelivr. 4. The CDN response is executed because no integrity hash constrains the accepted content. 5. If the dependency delivery path or artifact is compromised, malicious JavaScript executes in the report's browser context. 6. The script may read or modify the rendered ...[truncated 611 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tainted flow: 'DEFAULT_API_KEY' from os.getenv (line 34, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
97% confidence
Finding

The script sends an API key loaded from environment/.env in an HTTP request header to a hard-coded plain-HTTP endpoint. Because the transport is unencrypted, any network observer or intermediary can recover the credential and query contents, enabling credential theft and unauthorized use of the reporting service.

Content

Scanner excerpt · scripts/report_cli.py (reported line 403)May include surrounding context.

python
try:
        print("\n🔄 正在调用API...")
        response = requests.post(
            f"{API_BASE_URL}{REPORT_ENDPOINT}",
            json=payload,
            headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

在宿主环境设置 FEEDAX_REPORT_API_KEY,或使用项目内 .env(勿在对话中粘贴密钥):

bash
cp .env.example .env
# 编辑 .env,设置 FEEDAX_REPORT_API_KEY=你的密钥

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 26)May include surrounding context.

python
import requests
from dotenv import load_dotenv

# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 355)May include surrounding context.

python
import requests
from dotenv import load_dotenv

# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 29)May include surrounding context.

python
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

# 固定 API 根地址
API_BASE_URL = "http://221.6.15.90:18011"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The install trigger phrase is broad natural language ('帮我安装并学习这个技能'), which increases the chance an agent will invoke installation behavior from ordinary conversation rather than explicit user intent. In an agent ecosystem, overly generic activation language can cause unintended execution of repository installation or onboarding flows, especially when paired with a remote Git URL.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="zh-CN", which hard-codes a specific language/locale for the rendered report. Under the policy, locale restrictions should either offer user choice or be clearly justified as region-specific; this file does not include such an explanation or opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill transmits user queries and filters to an external service. External transmission is expected for this CLI, but it remains security-relevant because the destination is a fixed third-party IP over HTTP, so sensitive search terms and analysis parameters may be exposed in transit or sent to an endpoint users did not explicitly approve.

Content

Scanner excerpt · scripts/report_cli.py (reported line 403)May include surrounding context.

python
try:
        print("\n🔄 正在调用API...")
        response = requests.post(
            f"{API_BASE_URL}{REPORT_ENDPOINT}",
            json=payload,
            headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool automatically writes JSON, Markdown, and HTML reports containing returned article data, metadata, and request parameters to local disk without an explicit warning or consent step. In this skill context, the reports may include sensitive search topics, article URLs, author names, and summaries, creating unintended local data retention and exposure to other local users, backups, or sync services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are very broad and overlap with ordinary business terms like '报告', '分析报告', '市场分析', and '趋势分析'. This can cause unintended skill activation, leading the agent to process user inputs with this skill when the user did not intend to invoke it, potentially sending sensitive business queries or personal data to an external API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that reports are written to a Desktop directory but does not clearly warn users before execution that local files will be created automatically. This can lead to unexpected data persistence, privacy exposure, or clutter on shared systems, especially because report contents may contain sensitive query topics or analyzed content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This JSON dataset is entirely labeled in Chinese, which can impose a specific language/locale on downstream consumers without any visible opt-in or alternative. Under the stated policy, forcing a specific language without user choice is a natural-language policy concern even in data/config files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template loads executable JavaScript from a third-party CDN at runtime, which introduces a supply-chain and integrity risk: if the CDN, package, or network path is compromised, malicious code will execute in every generated report. In the context of a report template, this is unnecessary external trust and expands the attack surface beyond static content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description and top-level instructions present the skill entirely as a Chinese-language experience for generating reports, with no indication that users may choose another language or locale. This is a natural-language policy concern when a skill implicitly enforces a single language without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

L025-L036 将未配置条件和用户指引都限定为 FEEDAX_REPORT_API_KEY,且 manifest 的 requires.env 也只声明该变量;但 L543 又说明 CLI 会尝试读取旧名 FEEDAX_SEARCH_API_KEY。虽然这不一定是安全问题,但属于文档与实现意图描述不一致,可能导致运维配置预期混乱。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L062-L064 说明返回摘要并将完整报告保存到桌面目录;L365-L366 仅明确列出 JSON 和 Markdown 文件,而 L520-L533 又声明会生成可视化 HTML 报告。该技能文件内部的输出格式说明存在主动不一致,容易让调用者误判实际产物类型。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.