Back to skill

Security audit

PANews Creator

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate PANews publishing helper, but it handles account sessions and deletion or publishing actions with insufficient built-in safeguards.

Install only if you are comfortable giving an agent authenticated PANews creator authority. Prefer a secure credential source instead of command-line session arguments, keep the session narrowly controlled, and manually confirm article IDs before any delete, submit, update, upload, or column-application action.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/workflow-manage.md:7
Finding

Session Token Exposure Through Command-Line Arguments

Content
View full analysis
--take 50 --session ``` Similar command-line token usage appears throughout the publishing and revision workflows: ```bash node cli.mjs validate-session --session ``` ```bash node cli.mjs upload-image --session ``` The CLI explicitly accepts the session as a command-line option: ```javascript session:{type:`string`,description:`PA-User-Session token`} ``` ### Technical Analysis `PA-User-Session` is an authenticated browser session credential. Passing it through `--session` places the secret in the process argument vector. Depending on the operating system and execution environment, command arguments may be exposed through: - Shell history files. - Process inspection utilities. - Agent or tool invocation logs. - Terminal recording and observability systems. - CI/CD job logs or debugging output. - Local users with permission to inspect processes. The CLI sends this token in the `PA-User-Session` header to the fixed PANews endpoint at `https://universal-api.panewslab.com`. This transmission is necessary for the declared functionality and no unrelated receiver was found. The vulnerability is the local handling of the credential before transmission. `references/workflow-apply-column.md:21-22` correctly warns that command-line tokens may be exposed and recommends environment variables or a credential store. The other workflows contradict that guidance by repeatedly demonstrating `--session `. ### Attack Path 1. A user or agent follows one of the documented examples and invokes the CLI with ...[truncated 1145 chars]
Remediation
View remediation
` from every workflow example. 2. Consistently use a protected credential source, such as: - An operating-system credential store. - A dedicated secret manager. - Standard input with echo disabled. - A narrowly scoped environment variable when stronger storage is unavailable. 3. Prefer stdin or an OS credential store over environment variables because environment values may also be observable in some process and diagnostic environments. 4. Deprecate the `--session` option or require an explicit unsafe-compatibility flag before accepting credentials through process arguments. 5. Ensure agent and tool integrations redact values associated with `session`, `PA-User-Session`, `PANEWS_USER_SESSION`, `PA_USER_SESSION`, and `PA_USER_SESSION_ID`. 6. Add automated documentation checks that reject examples containing `--session` followed by a token placeholder. 7. Document session revocation and rotation procedures for users who may already have exposed a token. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cli.mjs:86
Finding

Article Deletion Does Not Enforce Explicit Target Confirmation

Content
View full analysis
Remediation
View remediation
\ --article-id \ --confirm-delete ``` 2. Reject the operation unless `--confirm-delete` exactly equals `--article-id`. 3. Before deletion, retrieve the target article and display its title, identifier, column, and current status. 4. In interactive use, require a clear confirmation that includes the exact article title or ID. 5. In non-interactive use, require both an explicit confirmation flag and the matching target identifier. 6. Add a `--dry-run` mode that resolves and displays the target without sending a DELETE request. 7. Verify that the target status is eligible for deletion before asking for confirmation. 8. Add automated tests proving that: - Deletion fails without confirmation. - A mismatched confirmation value fails. - An ineligible status fails. - No DELETE request is emitted when any guard fails. 9. Keep the server-side authorization and status checks in place; client-side confirmation must supplement rather than replace them. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
- `scripts/cli.mjs`: unified entrypoint for PANews creator commands

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/cli.mjs (reported line 16)May include surrounding context.

js
`),process.exit(1)}}const de=`https://universal-api.panewslab.com`;async function fe(e,t={}){let{lang:n,session:r,method:i=`GET`,body:a}=t,o={"Content-Type":`application/json`};n&&(o[`PA-Accept-Language`]=n),r&&(o[`PA-User-Session`]=r);let s=await fetch(`${de}${e}`,{method:i,headers:o,body:a===void 0?void 0:JSON.stringify(a)});if(s.status===401&&(console.error(JSON.stringify({error:`Session is expired or invalid. Please obtain a new PA-User-Session.`})),process.exit(1)),!s.ok){let e=await s.text().catch(()=>``);console.error(JSON.stringify({error:`HTTP ${s.status}`,detail:e})),process.exit(1)}return s.status===204?null:s.json()}function pe(e){let t=[e,process.env.PANEWS_USER_SESSION,process.env.PA_USER_SESSION,process.env.PA_USER_SESSION_ID];for(let e of t){let t=e?.trim();if(t)return t}}var me=l(((e,t)=>{t.exports=n,n.CAPTURING_PHASE=1,n.AT_TARGET=2,n.BUBBLING_PHASE=3;function n(e,t){if(this.type=``,this.target=null,this.currentTarget=null,this.eventPhase=n.AT_TARGET,this.bubbles=!1,this.cancelable=!1,this.isTrusted=!1,this.defaultPrevented=!1,this.timeStamp=Date.now(),this._propagationStopped=!1,this._immediatePropagationStopped=!1,this._initialized=!0,this._dispatching=!1,e&&(this.type=e),t)for(var r in t)this[r]=t[r]}n.prototype=Object.create(Object.prototype,{constructor:{value:n},stopPropagation:{value:function(){this._propagationStopped=!0}},stopImmediatePropagation:{value:function(){this._propagationStopped=!0,this._immediatePropagationStopped=!0}},preventDefault:{value:function(){this.cancelable&&(this.defaultPrevented=!0)}},initEvent:{value:function(e,t,n){this._initialized=!0,!this._dispatching&&(this._propagationStopped=!1,this._immediatePropagationStopped=!1,this.defaultPrevented=!1,this.isTrusted=!1,this.target=null,this.type=e,this.bubbles=t,this.cancelable=n)}}})})),he=l(((e,t)=>{var n=me();t.exports=r;function r(){n.call(this),this.view=null,this.detail=0}r.prototype=Object.create(n.prototype,{constructor:{value:r},initUIEvent:{value:function(e,t,n,
...[truncated 28 chars]

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cli.mjs (reported line 16)May include surrounding context.

js
:function(){for(var e=this.rooted?this.ownerDocument:null,t=this.firstChild,n;t!==null;)n=t,t=n.nextSibling,e&&e.mutateRemove(n),n.parentNode=null;this._childNodes?this._childNodes.length=0:this._firstChild=null,this.modify()}}})})),Ee=l((e=>{e.isValidName=h,e.isValidQName=g;var t=/^[_:A-Za-z][-.:\w]+$/,n=/^([_A-Za-z][-.\w]+|[_A-Za-z][-.\w]+:[_A-Za-z][-.\w]+)$/,r=`_A-Za-zÀ-ÖØ-öø-˿Ͱ-ͽͿ-῿‌-‍⁰-↏Ⰰ-⿯、-퟿豈-﷏ﷰ-�`,i=`-._A-Za-z0-9·À-ÖØ-öø-˿̀-ͽͿ-῿‌‍‿⁀⁰-↏Ⰰ-⿯、-퟿豈-﷏ﷰ-�`,a=`[`+r+`][`+i+`]*`,o=r+`:`,s=i+`:`,c=RegExp(`^[`+o+`][`+s+`]*$`),l=RegExp(`^(`+a+`|`+a+`:`+a+`)$`),u=/[\uD800-\uDB7F\uDC00-\uDFFF]/,d=/[\uD800-\uDB7F\uDC00-\uDFFF]/g,f=/[\uD800-\uDB7F][\uDC00-\uDFFF]/g;r+=`\ud800-󯰀-\udfff`,i+=`\ud800-󯰀-\udfff`,a=`[`+r+`][`+i+`]*`,o=r+`:`,s=i+`:`;var p=RegExp(`^[`+o+`][`+s+`]*$`),m=RegExp(`^(`+a+`|`+a+`:`+a+`)$`);function h(e){if(t.test(e)||c.test(e))return!0;if(!u.test(e)||!p.test(e))return!1;var n=e.match(d),r=e.match(

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The delete command is documented as 'Delete a DRAFT or REJECTED article', but its control flow is inverted by placing the delete request after the comma expression in the falsy-session branch. As written, the deletion API call is only reached when the session check fails, contradicting the documented intent and making the command not behave as described.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a local script and describes authenticated platform operations that inherently require network access and likely access to sensitive session material, yet it declares no explicit tool scope such as allowed-tools or permissions. This creates an overbroad-trust situation where an agent may run code with undeclared capabilities, making review and containment of data access and outbound requests harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill enables implicit invocation without any visible activation constraints, so the agent may trigger PANews creator actions based on ambiguous user requests. Because this skill can manage authenticated content operations such as draft edits, submissions, deletions, and uploads, unintended invocation could cause unauthorized or surprising actions in a live user session.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger 'User wants to check submission status or see their articles' is a broad natural-language activation condition without specific invocation phrases, scope limits, or exclusion conditions. This could overlap with many ordinary requests about articles or status checks and makes it unclear when this skill should activate versus other workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases for this workflow are broad, conversational, and likely to appear in ordinary user interactions, which increases the chance of unintended invocation. In a skill that can chain into publishing actions, accidental routing into article-polishing behavior could cause confusing automation, unwanted content handling, or progression toward higher-impact workflows without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow specifies Language | No | Default: zh, which imposes a locale default in natural-language instructions. Under the policy, forcing a specific language without explicit user choice or opt-in is a violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The implemented subcommands at L84 are validate-session, list-articles, create-article, update-article, delete-article, upload-image, search-tags, and apply-column. The manifest describes additional capabilities such as revising and resubmitting rejected articles plus polishing or reviewing article content, but no dedicated polish/review functionality exists, while validate-session and list-owned-columns behavior are present instead.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI exposes a destructive delete operation that immediately issues a DELETE request using only provided identifiers and a session token, with no confirmation prompt, dry-run mode, or force flag. In an agent/automation context, this increases the chance of accidental or prompt-induced destructive actions against a user’s PANews content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The CLI exposes a destructive delete operation that immediately issues a DELETE request using only provided identifiers and a session token, with no confirmation prompt, dry-run mode, or force flag. In an agent/automation context, this increases the chance of accidental or prompt-induced destructive actions against a user’s PANews content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tag-search flow derives language from the user's explicit argument if present, but otherwise falls back to Intl.DateTimeFormat().resolvedOptions().locale and normalizes it into a forced language header. This imposes a locale choice without explicit opt-in, which conflicts with the stated policy for language selection.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.obfuscated_code

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/cli.mjs:13

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
scripts/cli.mjs:17