Back to skill

Security audit

Security News Feed

Security checks for vulnerabilities and agentic risk

Overview

This security-news skill mostly matches its stated purpose, but it can automatically change Notion records and publish AI-generated content with unclear safeguards.

Review before installing. Use a dedicated Notion database and a least-privilege Notion integration, disable or patch the automatic 90-day archival, keep Tistory disabled unless you intend browser-session publishing, pin dependencies, and require review before publishing AI-generated summaries from crawled content.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
security_news_aggregator.py:446
Finding

Undocumented Automatic Archival of Remote Notion Records

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
security_news_aggregator.py:366
Finding

Indirect Prompt Injection Through Crawled News Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
modules/crawlers/skshieldus.py:30
Finding

TLS Certificate Verification Disabled in Multiple Crawlers

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:2
Finding

Unpinned Runtime Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (199)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

md
### Tistory API (선택)
1. https://www.tistory.com/guide/api/register 접속
2. 앱 등록
3. Access Token 발급

## 라이선스

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 13)May include surrounding context.

python
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 17)May include surrounding context.

python
from typing import Optional, List, Dict, Any
from dotenv import load_dotenv

# .env 파일 로드 (상위 디렉토리 탐색)
import sys
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
76% confidence
Finding

Automatically loading the first .env found while walking up parent directories can cause the application to trust configuration and secrets from an unintended location. In a shared filesystem, mispackaged deployment, or attacker-influenced directory structure, this could inject malicious API keys, webhook URLs, or service endpoints and redirect sensitive operations.

Content

Scanner excerpt · config.py (reported line 21)May include surrounding context.

python
current_path = Path(__file__).resolve()
search_paths = [current_path]  # 현재 디렉토리
for _ in range(4):  # 최대 4단계 상위 경로 검색
    env_file = current_path / '.env'
    if env_file.exists():
        load_dotenv(env_file)
        break

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · modules/prompts/blog_generation.py (reported line 193)May include surrounding context.

python
\`\`\`markdown
\`\`\`bash
# 패치 적용
sudo apt update && sudo apt upgrade
\`\`\`
\`\`\`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · all_crawlers_final.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · check_notion.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · final_8_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · final_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · full_pipeline.py (reported line 17)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · integration_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · rss_quick_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · selenium_test.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_13_crawlers.py (reported line 15)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_8_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_9_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_all_active.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_all_crawlers.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_crawlers.py (reported line 14)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_mermaid.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test_notion_publish.py (reported line 13)May include surrounding context.

python
# 환경 변수 로드
from dotenv import load_dotenv
env_file = Path.home() / '.openclaw' / 'workspace' / '.env'
load_dotenv(env_file)

from modules.crawlers.krcert import KRCERTCrawler

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code publishes crawled and LLM-generated content to Notion, an external service, without any available context establishing that publication is within the skill's authorized scope. In a security review context, undeclared exfiltration or outbound publication is dangerous because it can transfer sensitive, copyrighted, or manipulated content to third-party systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases include very broad terms like 'security news' and '뉴스 수집', which can overlap with ordinary user requests and cause the skill to activate unexpectedly. Because this skill performs external collection, summarization, and possible publication, accidental invocation can lead to unintended network activity and data handling beyond the user's intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description explains functionality but does not clearly warn users that collected content is sent to Gemini and may be stored or published to Notion and Tistory. This creates a transparency and consent problem: users may invoke the skill without realizing data will leave the local environment and potentially be posted externally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.