Back to skill

Security audit

Last 30 Days—CN版

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its social-media research purpose, but it automatically sends queries to external services and opens locally generated HTML that is not safely sanitized.

Review before installing. Use this only for topics you are comfortable sending to WebSearch and RedFox, avoid confidential brand/customer/investigation terms, and prefer not to open generated HTML automatically until the report generator escapes content and validates links. Configure a revocable RedFox API key and watch where reports are saved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:132
Finding

Mandatory Response Hijacking and Promotional Content Injection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cn_last30days.py:506
Finding

Stored HTML and Attribute Injection in Automatically Opened Reports

Content
View full analysis
str: import re text = text.replace("&", "&").replace("<", "<").replace(">", ">") text = re.sub(r'\[([^\]]+)\]\(([^)]+)\)', r'\1', text) text = re.sub(r'\*\*(.+?)\*\*', r'\1', text) return text ``` API- or JSON-controlled URLs are directly concatenated into HTML attributes: ```python item_url = item.get("url", "") url_attr = 'href="' + item_url + '"' if item_url else 'href="#"' author_link = item.get("author_link", "") author_html = ('' + author_escaped + '') if author_link else ('' + author_escaped + '') ``` The keyword is read from input data and inserted directly into the generated document: ```python keyword = data["keyword"] ``` ```html cn-last30days · {keyword}
{keyword}
``` The generated report is written to disk without sanitizing the completed document: ```python html_content = format_as_html(data, max_items=args.max_items, report_html=report_html) output_dir = Path(args.output_dir) output_dir.mkdir(parents=True, exist_ok=True) base_name = json_path.stem html_file = output_dir / f"{base_name}.html" html_file.write_text(html_content, encoding="utf-8") ``` The Skill then instructs the agent to open that file automatically: ```bash open "HTML file path" ``` ### Technical Analysis The report generator constructs HTML through direct string interpolation and concatenation. Several values can originate ...[truncated 3437 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Enabling implicit invocation without precise activation constraints makes it likely the skill will auto-trigger based on loosely related phrases, causing the system to perform cross-platform social-media analysis when the user did not clearly request it. In this context, the skill targets real discussions on major Chinese platforms, so accidental activation can lead to unnecessary handling of sensitive reputational, political, or personal-topic research and increase privacy, compliance, and misuse risks.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The script accesses environment variables and local configuration files to obtain API credentials, but that capability is not reflected in the declared skill behavior. In an agent setting, undeclared access to ambient credentials expands the trust boundary and can surprise users who expect a search-only tool.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cn_last30days.py (reported line 704)May include surrounding context.

python
</div>'
            )

        xhs_notice = (
            '<div style="background:#fff3cd;border:1px solid #ffc107;border-radius:8px;padding:10px 14px;margin-bottom:14px;color:#664d03;font-size:13px;line-height:1.6">'
            '⚠️ 受小红书风控规则限制,部分作品链接可能无法正常跳转,您可复制对应作品标题前往小红书搜索查看,感谢理解🙇‍♀️🙇‍♀️'
            '</div>'
        ) if pkey == "xhs" else ""
        no_data_html = "<div class='no-data-hint'><p>未查询到相关内容,建议更换关键词重试。</p></div>" if not items else ""
        panels_html += (
            '\n        <div class="tab-panel" id="panel-' + pkey + '" style="display: ' + display + '">\n'
            '            ' + error_html + '\n'
            '            ' + xhs_notice + '\n'
            '            <div class="card-list">\n'
            '                ' + cards + '\n'
            '            </div>\n'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.en.md (reported line 36)May include surrounding context.

md
### Highlights

- **Pre-research mechanism**: Automatically runs WebSearch to extract trending terms before calling the engine, optimizing query strategy.
- **Smart merging**: Automatically merges related keywords into a single call to reduce API invocations.
- **Signal interpretation**: Automatic interpretation of key metrics like Xiaohongshu save/like ratio, Douyin share count, and WeChat read count.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that the skill automatically runs WebSearch and generates reports, but it does not warn users that their prompts, derived keywords, and possibly research targets may be transmitted to external services and persisted in output artifacts. In a social-media research context, this can leak sensitive topics, internal brand-monitoring objectives, or regulated data to third parties without explicit consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly advertises a built-in free public API key, which normalizes shared credential use and implies the skill may embed reusable third-party access. Even if the key is low-privilege, public/shared credentials enable abuse, quota exhaustion, attribution problems, and can expose users to an untrusted external service without informed consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation gives conflicting security guidance by claiming the skill ships with a built-in public key while also warning users not to hard-code or expose keys. This contradiction can mislead users and reviewers about actual secret-handling practices, increasing the chance of insecure deployment, accidental credential disclosure, and unsafe trust in embedded access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can 'Simply describe the topic you want to research in natural language—no fixed commands to memorize,' then gives broad everyday-style example phrases such as 'Research AI video tools for me' and 'Compare the reputation of Product A and Product B.' This leaves activation scope underspecified and increases the chance of unintended invocation from ordinary conversational requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to invoke the skill with very broad natural-language phrases such as generic research or trend-analysis requests, without clearly delimiting when this skill should activate versus when a normal conversation should continue. In an agentic environment, this can cause unintended tool invocation on loosely related prompts, potentially sending user queries to external social-media research services and expanding data exposure beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to automatically generate an HTML file, write it to disk, and open it locally without asking the user first. This creates an unsafe side effect boundary: even if the HTML is locally generated, it may contain untrusted content derived from external data sources, and auto-launching it can surprise the user, trigger browser execution of active content, or expose local environment behavior without consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and default prompt are broadly phrased to research 'any topic' across major Chinese social platforms, but they do not define clear scope, safety boundaries, or activation criteria. This increases the chance of over-broad triggering and use on sensitive subjects, enabling unintended collection, summarization, or amplification of contentious social or reputational content without sufficient user intent verification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file requires the assistant to always begin with a Chinese-language badge and continue with a Chinese-only output template, without considering the user's preferred language. This can cause unauthorized language steering, degrade usability, and mislead users who expect answers in another language, especially in multilingual or accessibility-sensitive contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rule enforces fixed Chinese phrasing and response structure for general queries, leaving no option to adapt to the user's language or communication needs. In a user-facing research skill, this creates a systematic policy-quality issue by overriding user intent and potentially reducing transparency and trust.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill reads secrets from REDFOX_API_KEY/X_API_KEY and from ~/.qoder/apis/redfox.json, which goes beyond a purely topical research function and relies on ambient credentials. This is dangerous in agent environments because a caller may trigger credential use without realizing the tool will inspect host secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The tool sends the user-provided keyword and source metadata to an external service at redfox.hk. If users enter confidential brand, customer, incident, or investigation terms, those sensitive queries are disclosed to a third party without an explicit runtime warning or consent step.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated report explicitly declares zh-CN and all visible interface text is fixed in Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

In from-json mode, the script creates an output directory and writes an HTML file to disk. Persistent writes are a real side effect that exceeds a narrow 'analysis' expectation and may expose searched topics or generated reports on shared systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Normal execution persistently saves JSON and/or HTML reports under the user's Downloads-derived directory. This can leak potentially sensitive research topics or collected content into a broadly accessible location without strong user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Advertising automatic daily updates without warning about recurring external access and ongoing report/output generation creates a transparency and privacy risk. Users may unknowingly authorize repeated data transmission, repeated scraping/search activity, or accumulation of generated files that reveal their monitoring interests over time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description is entirely in Chinese and frames the skill for Chinese-language use without indicating any option for the user to choose another language. Under the policy for natural-language constraints, forcing a specific language without opt-in can be a locale/language policy issue unless explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The operational instructions and output requirements are presented only in Chinese, and no opt-in or language-selection mechanism is described. Because the skill is user-invocable, this can amount to forcing a specific language/locale experience without giving the user a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This function accesses REDFOX_API_KEY and X_API_KEY from the environment and also reads a local credential file under ~/.qoder/apis/redfox.json. Although this is functionally necessary, the file does not clearly disclose to users that it will inspect those credential sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This path creates directories and writes HTML output, and similar write behavior also appears later for JSON and HTML exports. The code reports successful saves after writing, but it does not warn up front that running the tool will create files under ~/Downloads/CnLast30Days by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.