Back to skill

Security audit

topic-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its feed feature accepts unrestricted URLs and the documentation understates the resulting network and data-flow risks.

Review before installing. Use only trusted public HTTPS feed and discovery URLs, avoid importing OPML from untrusted sources, and do not monitor sensitive internal topics if alerts may be delivered through Telegram, Discord, email, or another agent tool. Prefer the bundled vendored dependency or a pinned virtual environment instead of the unpinned pip command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/monitor.py:113
Finding

Unrestricted Feed URLs Allow SSRF and Local Resource Access

Content
View full analysis
List[str]: """Try to discover RSS/Atom feeds from a regular webpage URL.""" url = (url or "").strip() if not url: return [] if url.endswith((".rss", ".xml", ".atom")) or url.endswith("/feed"): return [url] request = Request( url, headers={ "User-Agent": "topic-monitor/1.5 (+feed-discovery)", "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8", }, ) try: with urlopen(request, timeout=timeout) as response: content_type = response.headers.get("Content-Type", "") final_url = response.geturl() body = response.read(250_000) except Exception: return [] ``` Feed URLs are subsequently fetched without destination validation: ```python for feed_url in all_feeds: headers = feed_cache_headers(state, topic_id, feed_url) if verbose: print(f" 📰 Fetching feed: {feed_url}") parsed = feedparser.parse(feed_url, request_headers=headers) update_feed_cache(state, topic_id, feed_url, parsed) ``` Directly supplied and discovered URLs are stored without validation: ```python feeds = split_csv(args.feeds) if args.discover_feeds: discovered = [] for candidate in split_csv(args.discover_feeds): discovered.extend(discover_feed_urls(candidate)) feeds = list(dict.fromkeys(feeds + discovered)) ``` OPML URLs are also accepted without validation: ```python for outline in outlines: xml_url = outline.attrib.get("xmlUrl") or outline.attrib.get("xmlurl") title = outline.attrib.get("title") ...[truncated 3077 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:296
Finding

Unpinned Runtime Dependency Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (111)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is a low-level feed parsing component, not a complete monitoring-and-alerting skill. Its main function is to retrieve feed data from URLs/files/streams and parse RSS/Atom/XML into structured results. While feed polling/parsing could support part of a monitoring system, this chunk does not implement the declared primary behaviors: proactive monitoring, scheduled searches, topic filters, scoring, sentiment analysis, alerts, digests, or memory-aware summaries. It also supports local file and raw string parsing, which is not reflected in the description. Therefore the description materially overstates and misrepresents what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full-featured automated monitoring and alerting skill. The supplied code chunk does not implement monitoring behavior or any user-facing alerting features. Instead, it is a low-level helper module for parsing dates from feed content using various format-specific handlers. While date parsing could be a supporting implementation detail inside a feed-monitoring system, this chunk alone does not reflect the declared primary purpose and contains none of the core capabilities described. Therefore, the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk is a narrow, low-level date parsing helper from feedparser. It maps Hungarian month names and converts a matching timestamp string into a normalized format for parsing. While such a utility could support feed ingestion indirectly, this chunk does not implement the declared skill’s primary behavior: monitoring topics, polling feeds, searching the web, filtering topics, scoring importance, tracking sentiment, or sending alerts/digests. Therefore, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk is a low-level date parsing helper, not a monitoring/alerting implementation. While such a parser could be a supporting dependency in a feed-processing system, the chunk itself only converts a specific date format ('yyyy/mm/dd hh:mm:ss TTT' with weekday) into a UTC time value. It does not monitor topics, fetch feeds, search the web, score importance, track sentiment, or generate alerts/digests. Therefore the declared description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement the declared skill behavior. It is a low-level date parsing helper used for interpreting feed timestamps, not a monitoring or alerting workflow. While RFC 822 date parsing could be a supporting component inside a feed polling system, this chunk alone only converts date strings to UTC tuples and does not perform any of the user-facing capabilities described. Therefore the declared description materially overstates and misrepresents what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code is a small support module containing exception definitions for feed parsing. While such a module could be a minor dependency of a feed-monitoring system, the chunk itself does not implement the declared skill behavior. Its primary purpose is library error taxonomy, which is materially different from the described end-user functionality. Therefore the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code does not implement topic monitoring, scheduling, feed polling orchestration, alert generation, boolean filtering, AI importance scoring, sentiment tracking, digesting, or memory-aware summaries. Instead, it is a low-level helper used to process HTML content safely within feed parsing. While such parsing could be a supporting component inside a feed-monitoring skill, this specific chunk's actual behavior is purely HTML processing and is not an accurate representation of the declared end-user functionality. Therefore, this chunk materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code does not implement a monitoring or alerting workflow. It only provides low-level parsing support for feed formats by handling XML namespace/feed element callbacks and storing parsed feed metadata. Feed polling support is only indirectly related: this library could be used as one component of a monitoring skill, but by itself it does not schedule checks, monitor topics, perform searches, score importance, track sentiment, manage memory/context, or send alerts/digests. Therefore the declared description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk does not implement the declared monitoring/alerting functionality. Instead, it is a helper from a feed parsing library that recognizes Creative Commons namespaces and stores license links found in feed metadata. While feed parsing could be a supporting detail within a broader monitoring skill, this specific chunk’s behavior is narrowly focused on license metadata extraction and is not representative of the declared primary purpose. Therefore, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a high-level automated topic monitoring and alerting system with scheduling, filtering, scoring, sentiment analysis, and notification behavior. The supplied code chunk does none of those things. Instead, it is a low-level feed parsing helper that specifically handles GeoRSS and GML spatial elements inside feeds. While feed polling is mentioned in the description, this code does not implement monitoring, polling, alerting, topic filters, AI scoring, sentiment tracking, digests, or memory-aware summaries. Its primary purpose is materially different from the declared skill behavior, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code does not implement the declared monitoring/alerting functionality. Instead, it is a low-level parsing helper from a third-party feed parsing library, specifically for handling iTunes namespace tags in RSS/Atom-like feeds. While feed polling could conceptually rely on feed parsing as a supporting detail, this chunk by itself only parses metadata fields and does not perform monitoring, scheduling, search, filtering, scoring, alerts, digests, or memory/context handling. Therefore the supplied code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a full monitoring and alerting skill with automation, filtering, AI analysis, and notifications. The supplied code does none of that. It is a narrow helper module inside feedparser that recognizes the Podlove Simple Chapters namespace, collects chapter entries, and parses chapter start times. This is not merely a supporting implementation detail for the claimed behavior in this chunk; the code’s primary purpose is low-level feed metadata parsing, and it lacks any monitoring, triggering, alerting, or AI-analysis functionality. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk does not implement the declared skill behavior. Instead of monitoring topics and generating alerts, it provides low-level sanitization utilities for feed/HTML/XML content, likely as a supporting dependency for safe feed parsing. While feed sanitization could be part of a broader feed-monitoring system, this chunk itself has a materially different purpose and exposes none of the core declared capabilities. Therefore, the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk is a general-purpose SGML parser implementation (sgmllib.py) with methods for feeding text, parsing start/end tags, comments, declarations, and entity references. Its only concrete executable behavior beyond parsing is a local test function that reads a file or stdin and prints parse events. It does not implement the declared skill’s core purpose of automated topic monitoring, feed polling, search, alert generation, summarization, sentiment tracking, or memory-aware context. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 273)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 274)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 275)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 304)May include surrounding context.

md
python3 scripts/monitor.py --dry-run --verbose

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/monitor.py (reported line 296)May include surrounding context.

python
capture_output=True,
                text=True,
                timeout=45,
                env={k: v for k, v in os.environ.items() if k in (
                    "PATH", "HOME", "LANG", "TERM",
                    "SERPER_API_KEY", "TAVILY_API_KEY", "EXA_API_KEY",
                    "YOU_API_KEY", "SEARXNG_INSTANCE_URL", "WSP_CACHE_DIR",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes automated monitoring and multi-channel alerts, but the feature description does not clearly disclose that user-supplied topic queries may be sent to third-party search providers and that findings or summaries may be relayed through external messaging platforms. In a monitoring skill, users may include sensitive competitive, research, or internal-interest topics, so incomplete disclosure can lead to unintentional data exposure and privacy/compliance issues.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents behavior that requires network access, environment-variable access, file reads/writes, and shell execution, but it does not declare any explicit tool scope or permissions boundary. That creates an avoidable least-privilege failure: when installed in a permissive runtime, the skill may receive broader capabilities than users or reviewers expect, increasing the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.