Back to skill

Security audit

News Daily Local

Security checks for vulnerabilities and agentic risk

Overview

The skill’s news-to-Feishu purpose is coherent, but Review is warranted because its script disables HTTPS certificate checks while using a Feishu webhook token and can run on a schedule.

Install only if you are comfortable with this skill fetching external RSS feeds and posting the resulting digest to your Feishu group. Before using it, restore normal HTTPS certificate verification, replace or remove the plaintext HTTP RSS source, avoid storing the webhook token in a broadly readable file, and rotate the Feishu webhook if this version has already run on an untrusted network.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/fetch_and_send.py:24
Finding

TLS Certificate and Hostname Verification Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_and_send.py:24-27, with the unsafe context used at lines 145 and 268
Vulnerability Type: Improper TLS certificate validation
Risk Level: High

Vulnerable Code

python
ssl_context = ssl.create_default_context()
ssl_context.check_hostname = False
ssl_context.verify_mode = ssl.CERT_NONE

The unsafe context is subsequently used for both RSS retrieval and webhook delivery:

python
with urllib.request.urlopen(req, timeout=15, context=ssl_context) as response:
    content = response.read().decode('utf-8', errors='ignore')
    return parse_rss(content, limit)
python
with urllib.request.urlopen(req, timeout=30, context=ssl_context) as response:
    result = json.loads(response.read().decode('utf-8'))

Technical Analysis

Setting check_hostname to False and verify_mode to ssl.CERT_NONE disables both certificate-chain verification and hostname validation. The client will therefore accept a certificate presented by any server, including a self-signed or attacker-controlled certificate.

The same insecure TLS context is used for two security-sensitive operations:

  1. Retrieving news titles and links from external RSS providers.
  2. Sending the generated card to the configured Feishu webhook.

The Feishu webhook URL contains a secret token that authorizes message delivery. Because the complete URL is transmitted as part of the HTTPS request, a network attacker who successfully intercepts the connection can recover this credential. The flaw is unnecessary for the declared functionality because Python's default TLS context already supports secure HTTPS communication.

Attack Path

  1. An attacker obtains a network interception position, such as through a compromised router, malicious proxy, hostile wireless network, or DNS manipulation.
  2. The attacker redirects an RSS or Feishu connection to an attacker-controlled T ...[truncated 1251 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the custom context that disables certificate validation:
    python
    ssl_context = ssl.create_default_context()
    
  2. Do not modify check_hostname or verify_mode; retain their secure defaults.
  3. Prefer omitting the context argument entirely so that urllib uses the platform's trusted certificate store:
    python
    with urllib.request.urlopen(req, timeout=15) as response:
        ...
    
  4. Apply the same correction to the Feishu webhook request:
    python
    with urllib.request.urlopen(req, timeout=30) as response:
        ...
    
  5. Fail closed when certificate verification fails. Do not retry using an insecure context.
  6. Avoid logging the complete webhook URL or token. The current output exposes only the final path component, but even that component may be sensitive and should be redacted.
  7. Rotate the Feishu webhook credential if the script has previously operated over an untrusted network with TLS verification disabled.
  8. Optionally restrict webhook destinations to an allowlisted HTTPS hostname such as open.feishu.cn before transmitting the payload.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_and_send.py:48
Finding

RSS Feed Retrieved over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_and_send.py:48
Vulnerability Type: Unencrypted external content retrieval
Risk Level: Medium

Vulnerable Code

python
"http://www.chinanews.com.cn/rss/scroll-news.xml",

Technical Analysis

The configured RSS source uses plaintext HTTP. HTTP provides neither server authentication nor transport integrity. Any attacker capable of intercepting or modifying the connection can replace the feed response.

Even if the server normally redirects the URL to HTTPS, the initial HTTP response remains unauthenticated. An attacker can intercept that response and prevent the legitimate redirect.

Feed titles and links are treated as untrusted data to a limited extent, but they are still incorporated into Feishu markdown cards. Title cleanup removes HTML tags and replaces a few markdown characters, yet the destination URL is inserted directly into the generated markdown. Consequently, a modified feed can introduce attacker-selected links into a message that appears to originate from the trusted news bot.

Attack Path

  1. An attacker gains visibility into the network path used to access the plaintext RSS URL.
  2. The attacker intercepts the HTTP request or manipulates its DNS resolution.
  3. The attacker returns a forged RSS response instead of the legitimate feed.
  4. The script parses the forged titles and links as normal news entries.
  5. The entries are formatted into a Feishu interactive card and sent through the legitimate configured webhook.
  6. A group member clicks an attacker-controlled link presented as a news article.
  7. The attacker can then conduct phishing, credential theft, malware delivery, or tracking through the destination site.

Impact Assessment

Exploitation does not directly provide local system access or access to the Feishu webhook credential. The primary impact is loss of integrity for the affected news feed and the messages de ...[truncated 489 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext URL with a verified HTTPS endpoint supplied by the same publisher.
  2. If the publisher does not provide a reliable HTTPS feed, remove this source or replace it with a trusted alternative.
  3. Do not rely on an HTTP-to-HTTPS redirect, because the initial HTTP exchange can be modified.
  4. Enforce an https scheme for every configured RSS source before making a request.
  5. Validate extracted article URLs before adding them to cards. Permit only expected schemes such as https and reject malformed or dangerous schemes.
  6. Consider maintaining an allowlist of expected feed and article hostnames where operationally practical.
  7. Preserve normal TLS certificate and hostname validation for every HTTPS feed, as described in the preceding finding.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill documents behavior that reads configuration/environment variables, accesses local files, fetches RSS content over the network, and sends data to an external Feishu webhook, but it does not declare an explicit tool scope or permissions boundary. This creates a transparency and least-privilege problem: users and the platform cannot easily evaluate or constrain what the skill is allowed to access, increasing the risk of unintended data exposure or overbroad execution if the implementation changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language content of the skill is entirely in Chinese, including the description, headings, and usage guidance, with no indication that this language constraint is optional or region-specific. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script globally disables TLS certificate and hostname verification, so every HTTPS request to RSS feeds and the Feishu webhook becomes vulnerable to man-in-the-middle interception or tampering. In this skill's context, that can let an attacker alter fetched news content, redirect links, or capture the webhook destination and transmitted payload, which is more dangerous because the skill is explicitly network-facing and relies on untrusted external sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code sends collected news content to an external Feishu webhook endpoint, which is a network transmission, but the only user-facing messaging is operational status like '正在发送...' and success/failure output. There is no explicit warning in code comments, prompts, or user-facing text that data will be transmitted to a third-party service, which fits the missing user disclosure criterion for code files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file documents behavior that fetches RSS content and sends messages to a Feishu group using a configured webhook. Although sending is part of the skill's purpose, the setup instructions do not clearly warn users that running the skill will transmit content to an external service and post into a shared chat destination.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says the skill fetches news and sends it to Feishu, but it does not present an explicit privacy or external-transmission warning in the high-level metadata. Users may enable or schedule the skill without realizing that fetched content and possibly related metadata are transmitted to a third-party webhook, which weakens informed consent and can cause accidental external sharing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The top-level documentation presents the script as a straightforward RSS fetch-and-send tool. In reality, both RSS retrieval and webhook submission use an SSL context configured with CERT_NONE and hostname checking disabled, which is a meaningful behavioral divergence affecting connection security.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and runtime output are entirely in Chinese, which imposes a specific language on users without any opt-in or alternative locale path. Under the policy rule, this is a natural-language locale constraint that is not presented as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.