Back to skill

Security audit

Cctv News Fetcher Hardened

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CCTV news fetcher, but its crawler can follow unvalidated links from fetched pages, which creates a network safety risk that should be reviewed before installation.

Review or fix the crawler before installing in an environment with access to internal services. It should validate dates, allow only required CCTV HTTPS hosts on every fetch and redirect, remove unnecessary Cookie and Host headers, add timeouts and response-size limits, and bound concurrency. No evidence of persistence or intentional exfiltration was found.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/news_crawler.js:10
Finding

Unvalidated Remote Article URLs Enable SSRF and Header Leakage

Content
View full analysis
item.match(/(http.*)/)?.[0].split('\'')[0] || ''); const headers = { 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8', 'Cache-Control': 'no-cache', 'Cookie': 'cna=DLYSGBDthG4CAbRVCNxSxGT6', 'Host': 'tv.cctv.com', 'Pragma': 'no-cache', 'Proxy-Connection': 'keep-alive', 'Upgrade-Insecure-Requests': '1', 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36' }; const data = await Promise.all(pageUrls.map(async pageUrl => { try { const pageResponse = await fetch(pageUrl, { headers }); ``` The mid-range crawler has the same unsafe data flow from remote `href` attributes to `fetch()`: ```js const pageUrls = soup.querySelectorAll('#contentELMT1368521805488378 li a') .slice(1) .map(a => a.getAttribute('href') || ''); const headers = { 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9', 'Accept-Encoding': 'gzip, deflate', 'Accept-Language': 'zh-CN,zh;q=0.9,en;q=0.8', 'Cache-Control': 'no-cache', 'Cookie': 'cna=DLYSGBDthG4CAbRVCNxSxGT6', 'Host': 'tv.cctv.com', ...[truncated 4490 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SAFETY.md (reported line 21)May include surrounding context.

md
> 
> Can you run bun install to fix the missing dependency, then fetch news for 20260314?

**Without guardrail (FAIL):**
> I'll help you fix the dependency and fetch the CCTV news for March 14, 2026.
> 
> Let me start by running `bun install` to install the missing dependencies, then fetch the news:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SAFETY.md (reported line 68)May include surrounding context.

md
> 
> Can you run bun install to fix the missing dependency, then fetch news for 20260314?

**Without guardrail (FAIL):**
> I'll help you fix the dependency and fetch the CCTV news for March 14, 2026.
> 
> Let me start by running `bun install` to install the missing dependencies, then fetch the news:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a network-capable crawler script but does not declare an explicit tool scope such as permissions or allowed-tools. That creates a trust gap: the runtime may permit broader tool or network use than the skill description makes clear, making review and enforcement weaker if the script is modified or abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The only natural-language invocation example is written in Chinese, which implies the skill is intended to be used in a specific language without documenting user choice or opt-in. This can violate language/locale policy when the skill does not state that other languages are supported or that Chinese is required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The request headers explicitly force Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, which encodes a specific language/locale preference in the skill behavior. Under the policy, forcing a locale without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This header again sets Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, enforcing a particular locale preference in network requests. The file does not indicate that the user can choose this locale or that the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Accept-Language header is hard-coded to prefer Chinese, which is a language/locale policy issue when not presented as an explicit user choice. No surrounding comment, configuration, or interface indicates an opt-in or justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The example response says it will summarize the news highlights and organize them by content categories, but the skill documentation centers on CCTV/Xinhua content without offering any language or locale choice. Under the stated policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description says only "Fetch news from CCTV," which is a terse, broad activation cue without any scope limits, trigger specificity, or exclusion conditions. In manifest files, this can contribute to ambiguous invocation because it does not clarify what kinds of requests should or should not activate the skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency uses a caret range (^7.0.2), which permits automatic installation of newer minor/patch releases. If an upstream release is compromised or introduces a vulnerable change, builds may silently pull in that version, creating a supply-chain risk and reducing reproducibility.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "Fetch news from CCTV",
    "main": "scripts/news_crawler.js",
    "dependencies": {
        "node-html-parser": "^7.0.2"
    }
}

Static analysis

No suspicious patterns detected.