Back to skill

Security audit

Creator Alpha Feed

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent AI-content briefing workflow, but it needs review because it can use browser sessions, write durable reports, post to a Feishu group, and delete old local pipeline data without strong confirmation or scoping.

Install only if you are comfortable with an automated Chinese-language creator briefing workflow. Confirm Feishu chat IDs and Obsidian paths before use, review generated reports before posting, avoid collecting a logged-in X/Twitter homepage unless intended, and run scripts as a least-privileged user. Treat cleanup as destructive unless a dry run or backup exists.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/analyze.sh:47
Finding

Indirect Prompt Injection Through Untrusted Feed Content

Content
View full analysis
"$FILTERED_DIR/extracted-items.json" ``` ```bash # Append the extracted content to the analysis task cat >> "$FILTERED_DIR/analysis-task.md" << EOF Total content items: $TOTAL_RAW EOF jq -r '.[] | "### \(.title)\n- Link: \(.url)\n- Source: \(.source)\n- Popularity: \(.hotness)"' \ "$FILTERED_DIR/extracted-items.json" >> "$FILTERED_DIR/analysis-task.md" ``` The default collector obtains these fields directly from external services: ```bash ITEMS=$(jq '[.hits[] | select(.points >= 10)] | map({ title: .title, url: (.url // ("https://news.ycombinator.com/item?id=" + .objectID)), author: .author, points: .points, comments: .num_comments, source: "Hacker News", hn_url: ("https://news.ycombinator.com/item?id=" + .objectID) })' "$HN_FILE") ``` ### Technical Analysis Titles, URLs, authors, and descriptions obtained from Hacker News, Reddit, TechCrunch, Nitter, and RSSHub are attacker-controlled external data. The scripts place these values into Markdown files that are explicitly intended to be processed by an OpenClaw agent. No prompt-level trust boundary distinguishes system instructions from collected content. The generated analysis task does not instruct the model to treat feed fields solely as quoted data, ignore embedded commands, refrain from tool calls, or produce schema-constrained output. Markdown formatting does not neutralize model-directed instructions. A ...[truncated 1672 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/collect-v4.sh:12
Finding

Unvalidated Path Components Allow Writes Outside Intended Data Directories

Content
View full analysis
"$RAW_FILE" cat > "$MARKDOWN_FILE" << EOF # AI content collection report - $DATE EOF ``` A similar pattern appears in the analysis script: ```bash DATE="${1:-$(date +%Y-%m-%d)}" COLLECTED_DIR="$PIPELINE_DIR/collected/$DATE" FILTERED_DIR="$PIPELINE_DIR/filtered/$DATE" mkdir -p "$FILTERED_DIR" RAW_JSON="$COLLECTED_DIR/raw-content.json" OUTPUT_JSON="$FILTERED_DIR/analyzed-content.json" OUTPUT_MD="$FILTERED_DIR/wechat-worthy.md" LOG_FILE="$FILTERED_DIR/analysis.log" ``` ### Technical Analysis The scripts describe the argument as a date, but do not enforce the documented `YYYY-MM-DD` format. A value containing `../` is concatenated directly into output paths. Shell quoting prevents command injection but does not prevent filesystem path traversal. After path normalization, a constructed path such as: ```text /collected/../../target ``` resolves outside the intended `collected` directory. The scripts then create the selected directory and write predictable filenam ...[truncated 1646 chars]
Remediation
View remediation
&2 exit 2 fi ``` 2. Parse `collect-v4.sh` options explicitly so the date cannot be ambiguously interpreted as a positional parameter. 3. Resolve the intended root and candidate directory to canonical paths, then verify that the candidate remains beneath the root. 4. Reject values containing path separators, `.` components, or `..` components. 5. Reject output directories that are symbolic links, or open files using safe descriptor-based operations that do not follow symlinks. 6. Use restrictive directory permissions such as `umask 077` where reports may contain non-public information. 7. Apply the same centralized validation function to every script accepting a date or output-directory argument. 8. Run scheduled jobs with a dedicated, least-privileged account. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/collect-twitter.sh:18
Finding

Predictable Shared Temporary Files Permit Symlink-Based File Overwrite

Content
View full analysis
/dev/null; then if grep -q "timeline-item" \ "/tmp/twitter-${instance}.html" 2>/dev/null; then TWITTER_CONTENT=$(grep -oP \ '(?<=class="tweet-content"[^>]*>).*?(?=)' \ "/tmp/twitter-${instance}.html" | head -10) if [[ -n "$TWITTER_CONTENT" ]]; then break fi fi fi done ``` ### Technical Analysis The script writes downloaded data to deterministic filenames in the shared `/tmp` directory. It does not use `mktemp`, does not create a private temporary directory, does not check whether the destination already exists, and does not prevent symbolic-link traversal. On systems where multiple users share `/tmp`, another local user can create one of the expected paths as a symbolic link before the collector runs. `curl -o` follows the pathname and can truncate or overwrite the link target using the victim process's permissions. The files are also not removed after use, leaving remotely supplied HTML in predictable locations. ### Attack Path 1. The attacker has local access to the same host but does not need access to the victim account. 2. Before the victim starts the collector, the attacker creates a symbolic link: ```bash ln -s /home/victim/path/to/writable-file /tmp/twitter-nitter.net.html ``` 3. The victim runs `scripts/collect-twitter.sh`. 4. The first ...[truncated 826 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description presents a broader end-to-end skill for collecting and ranking daily AI content across creator workflows, including KOL tracking and automated briefing pushes. The supplied code chunk is much narrower: it validates existence of a local raw-content.json file, extracts fields with jq, writes an analysis instruction document in Chinese for evaluating WeChat-worthy topics, and emits a placeholder markdown output plus guidance to run a separate OpenClaw AI session manually. This is a materially different primary behavior because the script is a preparation step for downstream analysis, not the described collection/ranking/publishing automation system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broader creator-focused AI scouting system with Twitter/KOL tracking, configurable briefing workflows, and Feishu/Obsidian pushes. The supplied code chunk is narrower: it is a cron-invoked daily shell script that collects HN and TechCrunch via another script, creates directories, checks for a report, generates a placeholder markdown report if needed, and prepares a Feishu send step mostly through logging. The code even states 'Twitter: 需手动/browser收集' and does not include Obsidian output. While daily content collection and Feishu-oriented reporting are directionally aligned, several headline capabilities in the description are absent or contradicted in this code chunk, so this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk's primary purpose is housekeeping: computing a cutoff date and recursively removing old dated folders under local collected and filtered directories. That is materially different from the declared skill purpose of gathering, ranking, and publishing AI content updates. Cleanup could be a supporting maintenance script for a larger pipeline, but the supplied chunk itself does not implement the described user-facing capabilities and instead exercises an undeclared destructive filesystem capability (rm -rf on old directories). Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises a broader creator publishing workflow tool with ranking, KOL tracking especially on X/Twitter, tutorial/industry scouting, and automated pushes to Feishu/Obsidian using configurable templates and time windows. The provided code only fetches posts from two public sources (Hacker News and Reddit), parses them, and saves them locally as JSON/Markdown with logging. While this partially aligns with generic AI content collection and industry update gathering, it does not implement several prominent declared functions, and its actual scope is materially narrower than described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broader creator-oriented AI content scouting and publishing workflow, including ranking, multiple content categories, configurable windows/templates, and automated Feishu/Obsidian delivery. The supplied code chunk only implements a narrow Twitter/X collection step: it scrapes Nitter search results for AI-related tweets, fetches RSS feeds for three hardcoded accounts, and saves the results as a local markdown file. While KOL tracking on X/Twitter is partially aligned with the description, the primary behavior is substantially narrower than the declared end-to-end workflow, and several prominent declared capabilities are absent. Therefore this is a meaningful description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code partially matches the general idea of collecting daily AI content and producing a briefing-like output, but it does not implement several prominent declared capabilities. The description highlights creator publishing workflows, KOL tracking on X/Twitter, practical tutorial picks, industry updates, and automated pushes to Feishu/Obsidian with configurable templates and time windows. In contrast, the script only gathers posts/articles from three sources, applies simple thresholds, and saves results locally as JSON/Markdown. There is no social-KOL tracking, no Twitter/X access, no outbound integrations, and no configurable briefing system. Because these missing capabilities are central to the declared purpose rather than incidental, this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code partially matches the broad idea of AI content collection, but materially falls short of the declared description. It does collect daily AI-related content from Hacker News, TechCrunch, and Reddit and saves briefing-style outputs. However, the declared purpose emphasizes ranking, Twitter/X KOL tracking, and automated publishing pushes to Feishu/Obsidian with configurable templates and time windows. None of those core capabilities are actually implemented. Twitter support is especially overstated: the script explicitly says Twitter requires manual use of another browser tool and only generates instructions for how a human/operator might fetch content later. Because several headline capabilities in the description are absent from the code, this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The code partially matches the declared description because it does collect daily AI-related content and includes an optional Twitter-oriented workflow. However, the declared purpose suggests a more complete creator publishing pipeline with ranking, KOL tracking on X/Twitter, practical tutorial selection, and automated Feishu/Obsidian briefing pushes using configurable templates and time windows. The actual script is much narrower: it aggregates from Hacker News, TechCrunch, and Reddit, writes local JSON/Markdown files, and only generates a manual task guide for Twitter collection rather than performing automated tracking. There is no code for Feishu/Obsidian delivery, configurable templates, or meaningful ranking/briefing automation. Therefore the description materially overstates the implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description overstates the skill’s functionality. The code does perform AI content collection and produces a briefing-style Markdown/JSON output, which partially aligns with 'daily AI content' collection. However, it does not implement several central declared behaviors: ranking, KOL tracking, X/Twitter support, Feishu/Obsidian delivery, configurable templates, or broad configurable time windows. Its actual scope is much narrower: local collection from Hacker News and Reddit only, with simple formatting and logging. Because these missing capabilities are core to the declared purpose rather than minor implementation details, this is a material mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code is broadly related to daily AI content collection and creator publishing workflows, especially HN/TechCrunch collection and X/Twitter tracking, so the description is directionally aligned. However, several important declared capabilities are not actually implemented in this chunk. The script mainly orchestrates preparation steps: collection kickoff, generation of a Twitter collection guide, creation of an analysis prompt/task, and report/template scaffolding. It does not execute the core ranking itself, does not send Feishu messages despite claiming automated pushes, and shows no Obsidian support. Because these are user-visible primary capabilities in the declared description rather than minor implementation details, this is a meaningful description-behavior mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill directs use of bundled shell scripts and operational automation, but it does not declare any tool scope or allowed-tools boundary. That omission weakens least-privilege controls and can cause the agent to invoke shell capabilities more broadly than users or the platform expect, increasing the risk of unintended filesystem or process actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation description is broad enough to trigger on common content-scouting requests, potentially causing the agent to read local config, access external sources, and write reports when the user did not intend this particular workflow. In this skill, the risk is heightened because activation can cascade into browser use, shell-script fallback, group-channel posting, and local file writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs pushing results to a group channel and writing a full report to Obsidian without requiring an explicit warning or confirmation about disclosure and persistence. In a creator workflow, collected content, account monitoring results, and user prompts may contain sensitive operational data, and automatic posting/storage can expose it to unintended recipients or leave durable local copies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template instructs automatic writes to local Obsidian/workspace paths and a push to a Feishu chat ID, but it provides no explicit consent, disclosure, or confirmation step before externalizing collected content. In an agent skill, this creates a real data-handling risk because sourced content, operational metadata, and possibly sensitive notes or configuration-derived paths may be persisted or sent to a group chat without the user's awareness at run time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file hard-codes a Chinese-only push format for group delivery without indicating any user preference check, locale negotiation, or opt-in. This can override the user’s requested language or audience needs, causing misleading or unusable output in multilingual contexts and reducing user control over generated communications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script hard-codes analysis instructions that require Chinese-language evaluation and explicitly optimize for WeChat/public-account suitability and Chinese audience relevance, without any user opt-in or configuration. This can silently bias downstream AI outputs, override user intent, and cause inappropriate content targeting or language selection in workflows where the user expected neutral or differently localized analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language content is written entirely in Chinese, including the title, operational comments, and user-facing log/output strings. There is no indication that the skill is region-specific or that users can opt into another language, which conflicts with the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Lines in this section announce '步骤3: 发送飞书消息' and '消息已准备发送', but there is no sending action beyond loading the report into a variable. The comments say an OpenClaw agent would handle sending, so the section's documented behavior overstates what the code itself does.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code only reads the report and prints status messages in the Feishu step; there is no command invoking a Feishu API, messaging tool, or agent action to perform the send. This directly contradicts the final summary line claiming "飞书: 已推送" (Feishu: pushed), creating an intent-code divergence in the script's own operational messaging.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script performs recursive deletion of dated directories under the pipeline's collected and filtered data stores using rm -rf. While this appears intended as routine retention management rather than malicious behavior, it is still a destructive capability that is not reflected in the skill description, so users or orchestrators may invoke the skill without realizing it can permanently delete local data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language messages, usage text, logs, and output are all presented in Chinese, with no option to select another language and no justification that the skill is intended only for a Chinese-speaking environment. This can violate language/locale policy when users are not given an explicit opt-in or documented constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-facing comments, status messages, and generated markdown content are all in Chinese, with no indication that the skill is region-specific or that other languages are supported. This can violate language/locale policy when users are not given an opt-in choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The script sends a request to a third-party conversion service, api.rss2json.com, to obtain TechCrunch feed data instead of fetching the RSS feed directly. In a content-collection skill, this introduces an unnecessary external dependency that can observe request metadata, influence returned content, or fail unpredictably, which is more concerning because the skill is intended for automated publishing workflows where poisoned or incorrect content may propagate downstream.

Content

Scanner excerpt · scripts/collect-v2.sh (reported line 187)May include surrounding context.

sh
# 使用rss2json服务获取TechCrunch AI内容
TECHCRUNCH_FILE=$(mktemp)
if curl -s --max-time 30 \
    "https://api.rss2json.com/v1/api.json?rss_url=https://techcrunch.com/category/artificial-intelligence/feed/" \
    -o "$TECHCRUNCH_FILE" 2>/dev/null; then
    
    if jq -e '.items' "$TECHCRUNCH_FILE" > /dev/null 2>&1; then

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-visible strings throughout the script, including the header, logs, generated markdown report, and Twitter guide, are all written in Chinese. This imposes a specific language on users without opt-in or a documented justification for the locale constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This shell script issues HTTP requests to Hacker News, TechCrunch, and Reddit and stores the results in files under the output directory. While the operations are part of content collection, there is no explicit user-facing warning near the start of the script that it will contact third-party services and persist retrieved data locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.