Back to skill

Security audit

news-aggregator

Security checks for vulnerabilities and agentic risk

Overview

This news aggregation skill is purpose-aligned and disclosed, but users should understand that queries and search results are sent to SkillBoss for search and summarization.

Install only if you are comfortable using SkillBoss as the search and summarization provider. Avoid confidential or regulated queries, because queries and retrieved result content may be processed by that external API. Treat generated summaries as drafts and verify important claims and links against the cited sources.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Untrusted Search Results Passed Directly to an LLM Prompt

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly sends collected search results to a remote SkillBoss chat endpoint for summarization, but the documentation does not warn users that retrieved content will be transmitted to a third-party service. This creates a privacy and data-governance risk because search results may include sensitive queries, internal topics, or regulated data, and users are not given an opportunity to consent or minimize what is shared.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
import requests, os

SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The code performs an authenticated outbound POST request to a remote API and can transmit arbitrary request bodies, including search queries and collected results. In this skill's context, that means external data transfer is part of normal operation, but without explicit safeguards it can expose sensitive user-provided or retrieved content to a third party.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
API_BASE = "https://api.skillboss.co/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that the skill automatically searches, filters, and organizes news, which implies network access and possible transmission of queries or metadata, but it does not warn users about that behavior. While network access is expected for a news aggregation skill, the lack of disclosure can mislead users about privacy and operational behavior, especially in environments with restricted outbound access or logging concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description and operational guidance are presented entirely in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. There is no indication that the skill is intended only for a Chinese-language audience or region-specific use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.