Back to skill

Security audit

Ai News Zh 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese AI-news briefing workflow that fetches public news, translates it, and can push the result to configured messaging channels.

Install this if you want a Chinese-language AI news digest. Before enabling scheduled delivery or the message tool, set the exact Feishu, Telegram, or Discord destination and use a manual run first to confirm the content and channel.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises automatic pushing to Feishu, Telegram, and Discord but does not present a clear user-facing warning that content may be sent to external messaging platforms. This weakens informed consent and increases the risk of unintended data transfer, spam, or disclosure of translated/generated content to third-party services or group channels.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manual trigger phrase is generic enough to match an ordinary user request for news collection, which can cause the skill to activate unexpectedly without clear user awareness that its specific workflow will run. Because the workflow includes external fetching and possible downstream push behavior, accidental invocation could lead to unintended network activity or content delivery beyond what the user explicitly intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The formatting rules explicitly require headlines to be in Chinese, and the template fields and examples are also Chinese-centric. This creates a language-policy constraint without offering the user a language choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains a natural-language instruction that all English-language source content is automatically translated to Chinese. That imposes a specific output language/locale choice without indicating any user opt-in or configurable language preference, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.