Back to skill

Security audit

weibo realhot

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Weibo hot-search scraper, but it allows arbitrary browser navigation and disables browser sandboxing, which is broader than its stated purpose.

Review this skill before installing. Use it only in an isolated environment, avoid the custom URL option, and prefer fixed Weibo category URLs. The publisher should restrict navigation to approved Weibo hosts, remove anti-detection/proxy guidance, and avoid disabling browser sandboxing during normal use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/weibo_hot_search.py:93
Finding

Unrestricted URL Navigation Enables Server-Side Request Forgery

Content
View full analysis
2: url = sys.argv[2] ``` ### Technical Analysis The application accepts a caller-controlled URL and passes it directly to Selenium's `driver.get()` method. It does not validate: - The URL scheme - The destination hostname - The destination port - Embedded credentials - DNS resolution results - Loopback, private, link-local, or metadata-service addresses - Redirect destinations Although the documented purpose is limited to scraping `s.weibo.com`, the implementation allows the browser to navigate to arbitrary network and local resources. This creates an SSRF primitive from the environment where the skill runs. A reachable attacker-controlled or internal page can reproduce the selectors expected by the scraper, such as elements under `#pl_top_realtimehot`, causing selected page content to be returned in the scraper's result. Non-HTTP schemes supported by the browser, including local-resource schemes, are also not explicitly rejected. ### Attack Path 1. An attacker or untrusted caller supplies a crafted value through `--url` or calls `get_weibo_hot_search()` with an arbitrary URL. 2. The URL targets a loopback service, private network service, cloud metadata endpoint, local resource, or attacker-controlled page. 3. Selenium navigates to the target from the skill host's network context. 4. The target receives a request that may ...[truncated 1010 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/weibo_hot_search.py:50
Finding

Browser Sandbox Disabled While Loading Network Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation explicitly recommends evading anti-bot protections by changing browser fingerprints or using proxies, even though the stated purpose is only to fetch public hot-search data. Guidance that normalizes anti-detection behavior can facilitate scraping that bypasses platform safeguards, increasing the risk of abuse, account/IP blocking, and policy or legal violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script accepts a user-supplied URL and passes it directly to Selenium's browser automation, which causes outbound network access to an arbitrary destination. In an agent/skill context, this can be abused for server-side request behavior, internal network probing, access to sensitive internal web apps, or unreviewed data disclosure via browser requests, even though the original purpose is benign scraping.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README states the skill requires access to Weibo and specifies a China-mainland context, while the examples and instructions are primarily Chinese-centric without any opt-in or alternative locale guidance. This can be a language/locale policy issue because the skill appears to assume a specific regional/language setting rather than explicitly letting users choose or documenting the constraint as a region-specific tool in the activation/use guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The command-line interface and examples require category values in Chinese terms such as '实时/生活/文娱/社会' and present the user-facing interaction in Chinese only. This imposes a specific language choice without any opt-in or alternative locale, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.