Back to skill

Security audit

URL Summarizer

Security checks for vulnerabilities and agentic risk

Overview

This URL summarizer is low-risk but appears incomplete: it claims to summarize pages while its script only returns an empty summary template.

Install only if you are comfortable with a placeholder-style skill that may rely on the agent's own web tools to do the real summarization. Do not provide private, internal, or sensitive URLs unless you intend the agent to retrieve and process them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says the skill summarizes any web page by URL and can be used for batch summarization and comparison. However, the supplied code does not implement those behaviors. It only echoes the provided URL in a fixed JSON template with empty fields. Although the docstring mentions extraction and an agent web_fetch capability, the actual code chunk itself performs no network access, no extraction, and no summarization. This is a material mismatch in primary purpose and implemented capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is broad enough to trigger on generic summarization requests, which can cause the agent to invoke a URL-fetching skill outside its intended scope. That increases the chance of unexpected external network access, user confusion, and use on inputs that were not clearly meant to be treated as URLs or remote content sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill documentation does not warn that it fetches content from external URLs, so users may not realize that providing a link causes outbound requests and third-party content retrieval. This reduces informed consent and can create privacy, security, or policy issues if sensitive/internal URLs are supplied or if network access is unexpected in the current environment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function documentation says it will "Fetch and extract key content from a URL" and describes an extraction skeleton, implying some real content-processing behavior. In practice, the function simply echoes the input URL into a fixed dictionary with empty fields and performs no fetch or extraction at all, which is an active contradiction between intent documentation and implementation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.