Back to skill

Security audit

news-hot-hub

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its news-aggregation purpose, but it needs review because it returns raw third-party article HTML to the agent and documentation asks users to expose a Zhihu browser session cookie for unsupported features.

Review before installing. Use it only in an environment where outbound requests to the named platforms are acceptable, treat returned article content as untrusted data, avoid following any instructions found inside fetched articles, and do not provide a personal Zhihu browser cookie unless the skill is updated with a reviewed authenticated feature and safer secret-handling guidance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/aibase.py:131
Finding

Untrusted remote article HTML is forwarded directly to the AI Agent

Content
View full analysis
str: try: resp = session.get(url, headers=HEADERS, timeout=15) resp.raise_for_status() soup = BeautifulSoup(resp.text, "html.parser") content_div = soup.find("div", class_="article-content") or soup.find("article") return content_div.decode_contents() if content_div else "" except Exception as e: print(f"Failed to retrieve article content from {url}: {e}", file=sys.stderr) return "" ``` The retrieved HTML is subsequently included in the generated result: ```python items = _extract_items(data, data_type)[:limit] results = [] for item in items: content = "" if with_content: article_url = f"https://news.aibase.cn/{data_type}/{item.get('oid', '')}" content = _fetch_article_content(session, article_url) results.append(_build_item(item, data_type, content if with_content else None)) return results ``` The content is added to the output object without sanitization: ```python if content is not None: result["content"] = content return result ``` ### Technical Analysis The Skill retrieves complete article content from a remote website and returns the HTML directly in JSON intended for consumption by an AI Agent. Although BeautifulSoup identifies an article container, `decode_contents()` preserves the remotely controlled markup and text inside that container. There is no trust-boundary annotation, instruction filtering, plain-text conversion, content-length restriction, or isolation between the remote article and the Agent's instruction context. An attacker who controls or compromises an AIBase article can place instruc ...[truncated 1620 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/platform-guide.md:170
Finding

Documentation requests exposure of an authenticated Zhihu session cookie for unavailable features

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Dependency installation is not reproducible or integrity-locked

Content
View full analysis
=2.28.0 beautifulsoup4>=4.12.0 lxml>=4.9.0 ``` The installation instruction executes ordinary dependency resolution: ```bash pip install -r ${SKILL_DIR}/requirements.txt ``` ### Technical Analysis All dependencies are identified by conventional package names and are retrieved through pip's configured package source. No suspicious package name, custom index, direct URL, or known malicious component was identified in the supplied files. However, the use of open-ended lower bounds allows future package releases to be selected automatically. No upper bounds, exact reviewed versions, lock file, or package hashes are supplied. Installation is therefore non-reproducible and does not verify that the downloaded artifacts match versions reviewed with the Skill. If an upstream account, package release, configured package index, or distribution artifact is compromised, a later installation could resolve to an affected release. Native or installation-time behavior from dependencies may execute with the privileges of the user performing the installation. ### Attack Path 1. A dependency publisher account, release pipeline, package index, or distribution artifact is compromised. 2. A new affected version satisfying the `>=` constraint becomes available. 3. A user runs the documented pip installation command. 4. pip resolves the unconstrained dependency to the affected version. 5. Malicious installation or runtime behavior executes with the installing user's privileges. This is a supply-chain hardening weakness; the audit did not establish that any currently named dependency is malicious. ### Impact Assessment If the supply chain is compromised, impact may include arbitrary code execution with the privileges of the environment running pip or the Skill, acces ...[truncated 298 chars]
Remediation
View remediation
beautifulsoup4== lxml== ``` 2. Generate and maintain a lock file that includes transitive dependencies. 3. Record cryptographic hashes and install with: ```bash pip install --require-hashes -r requirements.txt ``` 4. Perform dependency updates through a controlled review process with vulnerability and compatibility testing. 5. Use a trusted, explicitly configured package index and prevent fallback to unapproved indexes. 6. Install into an isolated virtual environment under a non-privileged account. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch similarly indicates the skill's trigger surface and promised platform coverage do not correspond to the actual implementation. In an agent ecosystem, overstated functionality can cause inappropriate routing of user requests and unnecessary execution of code with network access, even when the requested platform is not truly supported.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch similarly indicates the skill's trigger surface and promised platform coverage do not correspond to the actual implementation. In an agent ecosystem, overstated functionality can cause inappropriate routing of user requests and unnecessary execution of code with network access, even when the requested platform is not truly supported.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch similarly indicates the skill's trigger surface and promised platform coverage do not correspond to the actual implementation. In an agent ecosystem, overstated functionality can cause inappropriate routing of user requests and unnecessary execution of code with network access, even when the requested platform is not truly supported.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes Python scripts, performs web fetching, and references environment variables, yet the manifest does not declare any tool scope or permissions boundary. This creates an implicit trust gap: an agent may allow shell, network, or env access broader than users expect, increasing the chance of unauthorized outbound requests or environment exposure when the skill runs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad trigger phrases can cause the skill to activate on ordinary conversation about trends, news, or hot topics without clear user intent to run code. Because the skill has shell/network characteristics, accidental invocation increases the risk of unnecessary outbound requests and user surprise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Catch-all routing terms such as '全部', '所有', or '对比' without stronger boundaries make it easy for unrelated requests to be interpreted as permission to run multi-platform fetching. In context, this expands the execution surface and may trigger multiple network calls when the user did not explicitly ask for tool use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill aggregates only 知乎、今日头条、AIBase and can fetch those individually or all together. This document instead states the skill integrates six platforms including 微博、V2EX、36氪, which materially expands the advertised behavior and user-facing scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phrase "是一个中文热点数据聚合技能" describes the skill as explicitly Chinese-language oriented. Under the policy rule, forcing a specific language or locale without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified as region-specific; this line does not provide that justification or user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes data aggregation and per-platform/all-platform hot-list retrieval, but does not mention comparative analysis or keyword frequency analysis. The architecture introduces a separate compare capability with cross-platform词频分析, which is a meaningfully broader behavior than simple hot-search aggregation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

技能清单说明该技能用于聚合知乎、今日头条、AIBase三大平台热搜数据,但该文档将微博、V2EX、36氪也纳入平台接入与状态管理范围,并说明可继续扩展新平台。这表明代码/设计文档的实际作用域大于清单宣称的三平台聚合能力,存在描述与实现范围不一致。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

manifest 将技能定位为“热搜/热榜/热点聚合”,并仅描述单个平台热榜或全平台热点获取;但文档明确写明知乎支持 hot-question、hot-video、topic、all 等额外能力,其中 topic 是关键词搜索而非热榜聚合。该能力集合超出清单对技能用途的自然语言承诺。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs operators to obtain and inject authenticated Zhihu cookies for commands unrelated to the skill's stated public hot-topic aggregation purpose. This increases the skill's privilege boundary and introduces handling of reusable session credentials, which could enable unauthorized account-backed scraping or credential leakage through logs, environment inspection, or downstream tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation tells users to copy browser request cookies and export them as an environment variable without any warning that these are sensitive authentication credentials. That practice can lead to accidental exposure via shell history, process listings, CI logs, screenshots, or reuse of personal session cookies in an automation context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/hub.py (reported line 105)May include surrounding context.

python
cmd.extend(["--limit", str(limit)])

    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, timeout=30)

        if result.returncode != 0:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and CLI help text present the skill interface in Chinese only, which can force a specific language on users without opt-in. The policy explicitly flags language or locale constraints unless the skill offers a choice or clearly justifies the restriction as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is described as a "中文热点数据聚合器" and focuses on Chinese platforms, but the natural-language instructions do not indicate whether output language is optional or user-selectable. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest's 'all platforms' concept refers to the three named sources only, while this architecture says the all flow starts 6 platform scripts in parallel. That creates a mismatch in what users should expect when requesting full-network hot topics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all headings and usage/documentation content in Chinese only, which can constitute a language/locale policy issue when no user opt-in or alternative language option is provided. The file does not state that the skill is region-specific or that Chinese is required for a justified compliance reason.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能清单说明该技能用于聚合知乎、今日头条、AIBase三大平台热搜数据,但本数据格式文档目录和后续章节还定义了微博、V2EX、36氪等额外平台以及 compare 分析输出。这表明该技能的文档化行为范围已超出其对外声明的三平台聚合目的,属于描述与实际文档范围不一致。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

manifest 仅声明获取单个平台热榜或一次性获取所有平台数据并汇总输出,而此处文档定义了 hub.py compare 的跨平台热点词频分析结果结构,包括关键词统计、平台覆盖数和逐平台标题分析。这不是单纯的数据抓取/汇总,而是额外的分析能力,超出了已声明的技能用途。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency specification for requests is unpinned, allowing future installs to resolve to different versions over time. This creates a supply-chain and reproducibility risk because a vulnerable or incompatible release could be installed without review, especially for a network-facing data aggregation skill that relies on HTTP requests.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28.0
beautifulsoup4>=4.12.0
lxml>=4.9.0

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
87% confidence
Finding

Requests has multiple known advisories, and because the manifest does not pin a version, there is no way to verify whether deployments will use a patched release. In a skill that fetches external content, an affected requests version could expose credentials or mishandle transport security depending on how the library is used elsewhere in the codebase.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The beautifulsoup4 dependency is specified with a lower bound only, so installations are not reproducible and may silently pull in newer releases. While not directly exploitable by itself, this weakens dependency integrity and can introduce unreviewed code changes into the scraping/parsing pipeline.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests>=2.28.0
beautifulsoup4>=4.12.0
lxml>=4.9.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The lxml package is also unpinned, which is more concerning in a parser used on externally sourced content from news and hot-topic platforms. Because parsing libraries often receive security fixes for malformed input handling, leaving the version open-ended increases the chance of deploying an affected or untested release.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests>=2.28.0
beautifulsoup4>=4.12.0
lxml>=4.9.0

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Lxml has a history of security advisories, and without an exact version pin the deployment may resolve to a vulnerable release. This is especially relevant for a skill aggregating and parsing third-party web content, where malformed or hostile HTML/XML input is plausible and parser flaws may become reachable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.