Back to skill

Security audit

PANews

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed PANews crypto-news reader; the main caution is that remote articles, comments, and editorial picks may contain text that could mislead an agent if treated as instructions.

Install only if you want an agent to answer crypto and blockchain news questions from PANews. Treat article text, comments, event links, and hook payloads as untrusted source content, and do not let them authorize tool use, policy changes, secret sharing, or financial decisions. For generic news or events, ask explicitly for PANews or crypto coverage to avoid source-limited answers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/cli.mjs:93
Finding

Untrusted PANews Content Is Exposed to the Agent Without Prompt-Injection Boundaries

Content
View full analysis
({ author:e.user?.profile?.name, text:e.text, createdAt:e.createdAt })); console.log(_i(e)) ``` ```js let i=(await ar( `/hooks?${new URLSearchParams({ category:r.join(`,`), onlyValid:`true`, take:String(n) })}`, {lang:t} )).map(e=>{ let n=e.targets.find(e=>e.lang===t)??e.targets[0]; return { id:e.id, category:e.category, text:n?.text, link:n?.link, payload:e.payload, group:e.group } }); console.log(_i(i)) ``` The supporting workflow encourages using remote hook content to guide Agent behavior: ```markdown ### Get AI-recommended questions node cli.mjs get-hooks --category ai-search-issues --lang Returns editorially preset exploratory questions to guide users into deeper topics. ``` ### Technical Analysis The CLI retrieves article bodies, community comments, editorial hook text, links, and hook payload objects from `https://universal-api.panewslab.com`. It then emits these values as plain Markdown-like text for subsequent Agent processing. The implementation does not establish a trust boundary between Skill instructions and API-derived content. In particular, it does not: - Label remote content as untrusted data. - Instruct the Agent to ignore commands or policy statements embedded in retrieved content. - Quote or isolate community comments from operational instructions. - Restrict hook payloads to documented identifier fields. - Validate retrieved links against an allowlist of schemes and domains. - Require confirmation before acting on instructions or links found in remote content. Article bodies and com ...[truncated 2057 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (16)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- `scripts/cli.mjs`: unified entrypoint for PANews reader commands

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cli.mjs (reported line 15)May include surrounding context.

js
efine=t=>e.check(rr(t)),e.overwrite=t=>e.check(Lt(t)),e.optional=()=>Rn(e),e.exactOptional=()=>Bn(e),e.nullable=()=>Hn(e),e.nullish=()=>Rn(Hn(e)),e.nonoptional=t=>Jn(e,t),e.array=()=>On(e),e.or=t=>An([e,t]),e.and=t=>Mn(e,t),e.transform=t=>Qn(e,In(t)),e.default=t=>Wn(e,t),e.prefault=t=>Kn(e,t),e.catch=t=>Xn(e,t),e.pipe=t=>Qn(e,t),e.readonly=()=>er(e),e.describe=t=>{let n=e.clone();return Dt.add(n,{description:t}),n},Object.defineProperty(e,`description`,{get(){return Dt.get(e)?.description},configurable:!0}),e.meta=(...t)=>{if(t.length===0)return Dt.get(e);let n=e.clone();return Dt.add(n,t[0]),n},e.isOptional=()=>e.safeParse(void 0).success,e.isNullable=()=>e.safeParse(null).success,e.apply=t=>t(e),e)),wn=k(`ZodNumber`,(e,t)=>{nt.init(e,t),Cn.init(e,t),e._zod.processJSONSchema=(t,n,r)=>qt(e,t,n,r),e.gt=(t,n)=>e.check(jt(t,n)),e.gte=(t,n)=>e.check(Mt(t,n)),e.min=(t,n)=>e.check(Mt(t,n)),e.lt=(t,n)=>e.check(Y(t,n)),e.lte=(t,n)=>e.check(At(t,n)),e.max=(t,n)=>e.check(At(t,n)),e.int=t=>e.chec

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/cli.mjs (reported line 18)May include surrounding context.

js
Set the \`cycles\` parameter to \`"ref"\` to resolve cyclical schemas with defs.`)}for(let n of e.seen.entries()){let r=n[1];if(t===n[0]){a(n);continue}if(e.external){let r=e.external.registry.get(n[0])?.id;if(t!==n[0]&&r){a(n);continue}}if(e.metadataRegistry.get(n[0])?.id){a(n);continue}if(r.cycle){a(n);continue}if(r.count>1&&e.reused===`ref`){a(n);continue}}}function Ut(e,t){let n=e.seen.get(t);if(!n)throw Error(`Unprocessed schema. This is a bug in Zod.`);let r=t=>{let n=e.seen.get(t);if(n.ref===null)return;let i=n.def??n.schema,a={...i},o=n.ref;if(n.ref=null,o){r(o);let n=e.seen.get(o),s=n.schema;if(s.$ref&&(e.target===`draft-07`||e.target===`draft-04`||e.target===`openapi-3.0`)?(i.allOf=i.allOf??[],i.allOf.push(s)):Object.assign(i,s),Object.assign(i,a),t._zod.parent===o)for(let e in i)e===`$ref`||e===`allOf`||e in a||delete i[e];if(s.$ref&&n.def)for(let e in i)e===`$ref`||e===`allOf`||e in n.def&&JSON.stringify(i[e])===JSON.stringify(n.def[e])&&delete i[e]}let s=t._zod.parent;if(s&&s!==o){r(s);let t=e.seen.get(s);if(t?.schema.$ref&&(i.$ref=t.schema.$ref,t.def))for(let e in i)e===`$ref`||e===`allOf`||e in t.def&&JSON.stringify(i[e])===JSON.stringify(t.def[e])&&delete i[e]}e.override({zodSchema:t,jsonSchema:i,path:n.path??[]})};for(let t of[...e.seen.entries()].reverse())r(t[0]);let i={};if(e.target===`draft-2020-12`?i.$schema=`https://json-schema.org/draft/2020-12/schema`:e.target===`draft-07`?i.$schema=`http://json-schema.org/draft-07/schema#`:e.target===`draft-04`?i.$schema=`http://json-schema.org/draft-04/schema#`:e.target,e.external?.uri){let n=e.external.registry.get(t)?.id;if(!n)throw Error("Schema is missing an `id` property");i.$id=e.external.uri(n)}Object.assign(i,n.def??n.schema);let a=e.external?.defs??{};for(let t of e.seen.entries()){let e=t[1];e.def&&e.defId&&(a[e.defId]=e.def)}e.external||Object.keys(a).length>0&&(e.target===`draft-2020-12`?i.$defs=a:i.definitions=a);try{let n=JSON.parse(JSON.stringify(i));return Object.defineProperty(n,`~standard
...[truncated 28 chars]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill exposes a CLI-based capability set that appears to fetch PANews content, implying network access, but it does not declare any explicit tool scope such as allowed tools or permissions. This creates a policy gap: an agent may be able to invoke network-capable code without clear restriction, review, or least-privilege boundaries, increasing the chance of unintended external access or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad and map to common conversational requests such as asking what is happening this month or whether any important events are coming up. In an agent routing system, this can cause over-triggering, where ordinary user prompts are captured by this skill even when the user did not clearly intend crypto event-calendar behavior, leading to misrouting and potentially irrelevant or misleading responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text says the skill triggers when a user 'needs to explore a column or browse articles from a column,' which is a broad intent description rather than a constrained invocation condition. The example phrases are also generic content-discovery requests, increasing the chance of unintended invocation when a user is simply asking casual questions about columns or articles.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match generic requests such as 'Any upcoming events' or 'Any free events,' which may cause the skill to activate outside clearly crypto-specific intent. In an agent setting, this can route unrelated user queries into this skill, producing irrelevant results or suppressing better-matched skills, which is a genuine prompt/skill-routing weakness even though it is not code-execution dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section activates on generic phrases like "Latest news," "What's in the news recently," and "What just happened," which are common conversational requests and not narrowly scoped to this specific workflow. The file also lacks exclusion conditions or negative examples to clarify when this skill should not activate versus other news-related skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text says the skill applies whenever a user wants to search for a keyword, project, event, or topic, and the example phrases are generic search requests. This scope is broad enough to overlap with many everyday requests and does not provide clear boundaries or exclusion conditions for when this workflow should be used instead of other skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation text says the skill triggers when a user wants to 'explore a long-running topic or a series of reports,' and examples like 'What series are there' are broad enough to match ordinary browsing requests. The file does not define clearer scope boundaries, exclusions, or negative examples to distinguish when this skill should activate instead of other search or reading workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger is broad enough to activate on generic research-oriented queries about popular topics like Bitcoin or Ethereum, which can cause this skill to intercept requests beyond a narrowly scoped PANews article-reading function. Overbroad activation can misroute user intent, suppress more appropriate skills, and increase the chance that users receive partial or source-constrained answers without realizing the limitation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad, generic conversational requests that can easily match ordinary user queries unrelated to this specific PANews workflow. In an agent-routing context, that increases the chance of inappropriate invocation, causing the system to answer from this skill when a more suitable tool or safer default behavior should apply.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The request helper supports sending a PA-User-Session credential header over network requests, but the CLI provides no visible warning, consent flow, or guidance on handling sensitive session material. In an agent skill, silent credential transmission is risky because users may supply reusable session tokens without understanding they are being forwarded to a remote API.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The get-hooks subcommand exposes generic hook/injection-point data from /hooks, including text, links, payloads, and grouping metadata, which exceeds a news-reading skill’s stated purpose. Even if intended for content discovery, this broad retrieval surface can leak internal platform configuration or promotional/control metadata that may later be abused for reconnaissance or prompt/content manipulation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Fetching platform hook/injection-point configuration is not justified by the PANews reader functionality described in the metadata, so it creates an unnecessary data-access capability. In agent contexts, unnecessary capabilities increase risk because hidden or loosely governed metadata may contain links, copy, or payload structures that influence downstream behavior or expose internal business logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown repeatedly instructs use of a language parameter but never explains acceptable values, whether the user should choose the locale, or whether a default language is imposed. Under the language/locale policy rule, undocumented locale handling can be a natural-language policy concern when the skill appears to force or assume a language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.obfuscated_code

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
scripts/cli.mjs:19