Back to skill

Security audit

Trend Scope

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated report-generation purpose, but it sends API keys and report queries over plaintext HTTP and creates unsafe HTML reports, so users should review it before installing.

Install only if you trust the Feedax service and accept that API keys, search terms, and filters are currently sent over unencrypted HTTP. Avoid sensitive queries, prefer json-only output when possible, be cautious opening generated HTML reports, and ask the publisher to switch to HTTPS, escape HTML output, validate links, bundle or integrity-protect chart JavaScript, and narrow auto-trigger terms.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_cli.py:29
Finding

API Credential and Sensitive Query Data Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_cli.py:640
Finding

Stored Script Injection in Generated HTML Reports

Content
View full analysis
0 else 0 channel_rows += f'{key}{count:,}{pct:.2f}%
' ``` Article URLs and text fields are also inserted without escaping or URL validation: ```python article_items = "" for i, article in enumerate(articles[:20], 1): title = article.get("title") or "No title" summary = article.get("summary") or "" author = article.get("authorName") or "Unknown" platform = article.get("platformName") or "Unknown" pub_time = format_timestamp(article.get("publishTime")) url = article.get("originalUrl") or "#" article_items += f'''
📰 {platform} 👤 {author} 🕐 {pub_time}
Summary: {summary[:100]}{"..." if len(summary) > 100 else ""}
''' ``` The user-controlled query is inserted into the document title and body: ```python html = f''' Public Opinion Analysis Report - {query[:30]} ...

📊 Public Opinion Analysis Report

Search query: {query} | Generated at: {now}

``` ### Technical ...[truncated 3363 chars]
Remediation
View remediation
``` 7. Add `rel="noopener noreferrer"` to links opened with `target="_blank"`. 8. Add regression tests for payloads including: ```text javascript:alert(1) " onmouseover="alert(1) ``` 9. Treat all API response fields as untrusted even if the upstream service is normally trusted. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/report_cli.py:722
Finding

Generated Reports Execute Third-Party CDN JavaScript without Integrity Verification

Content
View full analysis
``` The same external dependency is present in the bundled report asset: ```html ``` ### Technical Analysis Every generated HTML report retrieves and executes JavaScript from jsDelivr when opened with network access. Although the ECharts version is pinned to `5.4.3`, the script tag does not include a Subresource Integrity hash. The browser therefore has no project-defined cryptographic check that the downloaded content matches the reviewed library artifact. This creates a runtime supply-chain dependency whose effective code is not fully contained in the audited project. A compromise affecting the CDN, package artifact, publishing account, or dependency-delivery path could cause arbitrary JavaScript to execute in every opened report. The external request also discloses network metadata to the CDN, including the user's IP address, access time, browser characteristics, and potentially referrer information depending on browser policy. Interactive charts are part of the declared HTML-report functionality, but remote runtime retrieval is not necessary. The library can be bundled locally or protected with integrity verification. ### Attack Path 1. An attacker compromises the CDN delivery path, the hosted package artifact, or an upstream publishing account. 2. The attacker causes malicious JavaScript to be served at the referenced resource. 3. A user opens a generated HTML report while connected to the network. 4. The browser requests the script from jsDelivr. 5. Because no ...[truncated 911 chars]
Remediation
View remediation
``` 2. Verify the bundled file against the official release checksum during the build or release process. 3. If CDN use must remain, add a verified Subresource Integrity hash and CORS mode: ```html ``` The hash must be calculated from and compared against a trusted official artifact before release. 4. Configure a Content Security Policy that permits scripts only from the required local source or explicitly approved CDN. 5. Add `referrerpolicy="no-referrer"` to external resources where supported to reduce metadata disclosure. 6. Provide an offline report mode and make it the default. 7. Document all network activity performed when a generated report is opened, not only the network activity performed by the CLI. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Tainted flow: 'DEFAULT_API_KEY' from os.getenv (line 34, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/report_cli.py (reported line 403)May include surrounding context.

python
try:
        print("\n🔄 正在调用API...")
        response = requests.post(
            f"{API_BASE_URL}{REPORT_ENDPOINT}",
            json=payload,
            headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

在宿主环境设置 FEEDAX_REPORT_API_KEY,或使用项目内 .env(勿在对话中粘贴密钥):

bash
cp .env.example .env
# 编辑 .env,设置 FEEDAX_REPORT_API_KEY=你的密钥

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 26)May include surrounding context.

python
import requests
from dotenv import load_dotenv

# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 355)May include surrounding context.

python
import requests
from dotenv import load_dotenv

# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/report_cli.py (reported line 29)May include surrounding context.

python
# 加载 .env 文件(从脚本所在目录向上两级找到项目根目录)
SCRIPT_DIR = Path(__file__).parent
PROJECT_ROOT = SCRIPT_DIR.parent
load_dotenv(dotenv_path=PROJECT_ROOT / ".env", override=True)

# 固定 API 根地址
API_BASE_URL = "http://221.6.15.90:18011"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skill.md (reported line 376)May include surrounding context.

md
- `assets/area_codes.json` - 国标区域编码数据

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

All user-facing instructions and descriptions in the file are presented only in Chinese, and the document does not indicate that the language is optional or region-specific. Under SQP-3, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. Under the policy rule, locale constraints should either offer user opt-in/choice or be explicitly documented as justified for a region-specific tool; that justification is not present in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a skill that automatically generates professional public-opinion analysis reports according to user needs across brand, market, competitor, and trend scenarios. This file is instead a prefilled HTML report for a specific domain and case set ('江苏省医疗卫生舆情分析报告') with fixed dates, metrics, keywords, risk conclusions, and article entries, indicating a narrowly hard-coded output rather than a general-purpose report generator.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool's docstring, help text, status messages, and generated report content are all hard-coded in Chinese, and the HTML output explicitly sets lang="zh-CN". There is no indication that users can select another language or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames this skill as a舆情趋势洞察/report-generation capability. While calling an API is expected for that purpose, reading secrets from a project .env file and environment variables introduces a separate credential-discovery/access capability that is not described as part of the skill's scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI sends user queries, filters, and an API key to a hard-coded remote endpoint over plain HTTP. Because there is no transport encryption, anyone on the network path could observe or tamper with sensitive query content and steal the API key, which is especially concerning for a tool handling potentially sensitive monitoring topics.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes automatic generation of professional public-opinion analysis reports, but does not disclose that the implementation persistently saves JSON, Markdown, and HTML outputs to a desktop directory. Persisting artifacts to disk is a broader behavior than transient report generation and can affect user data handling expectations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This file performs external transmission of user-provided query data and report filters to a remote server, and in this implementation the destination is a fixed plaintext HTTP endpoint. The skill context makes this more dangerous because report queries may reveal sensitive investigations, brands, incidents, or monitoring interests, and the lack of secure transport enables interception or manipulation.

Content

Scanner excerpt · scripts/report_cli.py (reported line 403)May include surrounding context.

python
try:
        print("\n🔄 正在调用API...")
        response = requests.post(
            f"{API_BASE_URL}{REPORT_ENDPOINT}",
            json=payload,
            headers={"Content-Type": "application/json; charset=UTF-8", "x-api-key": DEFAULT_API_KEY},

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool persists report outputs containing returned article content and request parameters to local disk by default, without an explicit warning or consent step. In the context of a sentiment/intelligence reporting skill, those files may contain sensitive keywords, monitoring targets, and collected content that can later be exposed through local compromise, backups, or shared workstations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is very broad and overlaps with common business terms such as '报告', '分析报告', '市场分析', and '趋势分析'. That increases the chance the skill activates in unrelated contexts and causes unintended external API queries and local report generation, potentially sending user-provided content to a third party and writing files without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill writes full reports to local storage, but the description and activation context do not prominently warn users about persistent file output. In a skill that handles potentially sensitive search queries and aggregated results, undisclosed local storage increases privacy and data handling risk, especially on shared machines or managed agent hosts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file states that JSON, Markdown, and HTML reports are saved by default to ~/Desktop/舆情分析报告/, which affects the user's local filesystem. While the output location is documented, there is no explicit caution or warning that running the skill will create files on disk, which is the kind of user-impacting behavior SQP-2 asks markdown files to disclose clearly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON asset represents all region names exclusively in Chinese, which imposes a specific language/locale across the dataset. Under the stated policy, forcing a language without user opt-in can be a natural-language locale policy violation when no alternative or documented justification is present in the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The inline comment report_info = API调用参数 suggests this field is limited to request parameters. In practice, the code mutates that structure by adding report_time and total, so the documentation actively misdescribes the stored content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest description and the entire skill instructions are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience for compliance reasons. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

L027-L036 将 API Key 配置严格描述为 FEEDAX_REPORT_API_KEY,且 manifest 的 requires/env 也只声明该变量;但 L543 又声称 CLI 还会读取旧名 FEEDAX_SEARCH_API_KEY。虽然这是兼容逻辑,但文档前后对实际读取的环境变量集合描述不一致,属于意图与实现说明分歧。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

L362-L366 的“输出结果”明确列出仅保存 JSON 和 Markdown 报告文件,而 L520-L533 又说明会生成 HTML 格式可视化报告。这属于文档内部对实际输出行为的直接矛盾,可能误导调用方对产物类型和联网需求的判断。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.