Back to skill

Security audit

hackernews-digest

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Hacker News digest generator, with some operational caveats around file cleanup and web-browsing fallback but no evidence of malicious behavior.

Install only if you want a Chinese Hacker News daily digest. Configure BASE_DIR to a dedicated folder, because the skill may overwrite the dated digest file and clear temporary files under that dated output path. Treat the browser fallback as broader web access for article retrieval and avoid using it on sensitive or unrelated sites.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation description includes "技术日报" and says the skill should trigger even when the user only says "看看今天 HN 有什么". "技术日报" is a broad everyday topic phrase rather than a narrowly scoped command, which makes it unclear when this skill should activate versus other tech-news or summarization skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented workflow instructs the skill to delete an existing output file and all temporary files in the target directory without warning or confirmation. Because the base directory is configurable via CLI or environment variable, a mistaken or manipulated path could lead to unintended data loss outside the narrow scope of a single digest run.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Twitter/X template explicitly requires "使用简体中文", and the notes section states "语言:中文撰写" as a blanket requirement. This forces a specific language/locale without offering user opt-in or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill expands from a narrowly scoped content-fetching workflow to a broader browsing capability via agent-browser without clear necessity or constraints. That increases the attack surface: a malicious article, redirect, or prompt-injection page could cause the agent to access unrelated content or perform unintended browsing beyond the stated Hacker News digest purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation under '依赖' states only autocli and WebFetch are used, but L121 instructs the skill to use agent-browser if other fetching methods fail. This is an active contradiction between the declared dependencies and the documented execution behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.