Back to skill

Security audit

RSS采集器 | RSS Fetcher

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent RSS fetcher, but it needs Review because untrusted feed content can become executable JavaScript in its generated report and feed URLs are not safely constrained.

Install only if you are comfortable with a broad RSS aggregator making outbound requests to many configured feeds. Treat generated reports as untrusted until the HTML escaping issue is fixed, prefer HTTPS-only sources, and avoid adding feed URLs that could point at private networks, localhost, or internal services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_html.py:246
Finding

Stored HTML and JavaScript Injection Through RSS Content

Content
View full analysis
` ${tag} × `).join(''); renderArticles(); } ``` ```javascript if (matches.length > 0) { tagSuggestions.innerHTML = matches.map(tag => `
${tag}
`).join(''); tagSuggestions.style.display = 'block'; } ``` ```javascript container.innerHTML = filtered.map(a => `
${a.category} ${a.date} ${a.time} ${a.tags.map(t => `${t}`).join('')}
${a.title}
📄 ${a.source}
`).join(''); ``` Remote values enter the database through `scripts/fetch.py:364-378`: ```python write_queue.put({ 'id': article_id, 'source_id': source_id, 'category': category, 'title': item['title'], 'url': item['url'], 'author': item['author'], 'published_at': item['published_at'], 'tags': tags }) ``` ### Technical Analysis Article titles, URLs, source identifiers, categories, and tags eventually originate from RSS feeds or editable source ...[truncated 2230 chars]
Remediation
View remediation
`, `&`, U+2028, and U+2029 before embedding it. 6. Alternatively, store the article data in a separate JSON file and parse it at runtime. 7. Apply context-specific escaping to any server-generated option text and attribute value. 8. Add a restrictive Content Security Policy that disallows inline scripts and inline event handlers. 9. Add regression tests using values containing ``, quotes, HTML elements, event attributes, and malicious URL schemes. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/source.py:42
Finding

Unrestricted Source URLs Permit SSRF and Local Resource Access

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
config/sources.json:163
Finding

Enabled RSS Sources Use Unauthenticated Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/list.py:105
Finding

RSS Content Is Printed Without Terminal Control-Character Sanitization

Content
View full analysis
length else s ``` ### Technical Analysis Article titles and URLs originate from remote feeds. Source names and categories may also be supplied through source configuration. These strings are printed directly to an interactive terminal after length truncation. Truncation does not remove the ESC character, C0/C1 controls, bidirectional text controls, carriage returns, or other non-printable characters. A compatible terminal emulator may interpret such sequences as commands affecting colors, cursor position, window titles, hyperlinks, clipboard-related functions, or visible output. The result is an output-injection issue rather than shell command injection: the strings are not passed to a shell, but they can alter how terminal output is rendered or interpreted. ### Attack Path 1. An attacker controls or tampers with an enabled RSS feed. 2. The attacker places terminal escape sequences in an article title or URL. 3. The fetcher stores the value without removing control characters. 4. The operator runs `python3 scripts/list.py`. 5. The terminal interprets the embedded control sequences. 6. The attacker can forge or conceal displayed lines, create misleading terminal hyperlinks, or trigger other emulator-dependen ...[truncated 473 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a full RSS collection and management system with ingestion and management features such as incremental fetch, deduplication, tagging, health checks, and HTML reporting. The supplied code does not perform feed retrieval or management actions; it only reads from an existing SQLite database and a JSON source config, exposes query functions (recent/category/source), computes simple counts, and outputs JSON to stdout. While this could be a supporting component of a larger RSS system, this specific code chunk’s actual purpose is article querying/statistics rather than the declared end-to-end fetcher/manager capabilities. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader unified RSS fetching and management system with key features including incremental fetching, deduplication, auto-tagging, source health monitoring, and HTML reports. The supplied code only covers the source-management/health-monitoring portion plus database-backed source statistics. It does perform source health monitoring, which matches part of the description, but it does not implement feed fetching pipelines, incremental retrieval logic, deduplication, tagging, or HTML report generation in this chunk. It also includes source CRUD/state management capabilities not explicitly mentioned in the declared description. Because the implemented behavior is only a subset of the declared system and introduces a specific undeclared management capability, this is a description-behavior mismatch for this supplied code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON manifest contains natural-language text in Chinese (for example, the description at L002) and many locale-specific Chinese news source labels throughout the enabled feed list, but the file provides no indication that users can choose a language/locale or that the restriction is explicitly justified. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits an HTML document with lang="zh-CN", and the visible UI strings throughout the generated page are also fixed in Chinese. The policy requires flagging language or locale constraints when they are forced without user opt-in or a clearly documented, justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and function docstring use Chinese-only natural-language text ('创建SQLite数据库和表结构', '初始化数据库') with no indication that language selection is optional or that the skill is intentionally region-specific. This can violate language/locale policy because it imposes a specific language on users or maintainers without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains user-facing natural-language text in Chinese in the module description and throughout operational output, while the policy requires flagging language constraints that force a specific language without user opt-in. Although some CLI help strings are in English, the core runtime messaging is Chinese-only and no language selection or opt-in mechanism is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest description is explicitly bilingual and the rest of the document consistently mirrors content in Chinese and English, which suggests a predefined language/locale presentation. Because the file does not state that language is user-selectable or context-dependent, this may conflict with a policy requiring language choice or opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest emphasizes RSS collection/management features such as incremental fetching, deduplication, tagging, health monitoring, and HTML reporting. This file shows the skill is also configured as a broad editorial aggregation system across many domains and platforms, including numerous Reddit feeds, which is somewhat broader than the operational feature-focused description suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", and the visible UI text throughout the page is also fixed in Chinese. This imposes a specific language/locale on all users without offering an opt-in, switcher, or documented region-specific justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The schema file's human-readable comments and headings are written exclusively in Chinese, which imposes a specific language for operators or maintainers reading the file. Under the stated policy, language constraints should either offer user choice or be clearly documented as justified for a region-specific tool, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code embeds user-facing natural language primarily in Chinese in the module description, while also exposing an English CLI description later. The file offers no stated language selection or opt-in, which can conflict with a policy requiring users to choose locale or language rather than having it imposed implicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module title contains Chinese-only natural-language labeling ("查询文章数据"), and the rest of the user-facing docstrings/comments are also Chinese-only. Under the stated policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.