Back to skill

Security audit

创作者AI日报(免费版)

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core purpose is understandable, but it should be reviewed because it can use a logged-in X feed and write local Obsidian files under broad activation wording.

Review this before installing if you do not want an agent browsing your logged-in X feed or creating files in your Obsidian vault. Use it only with an explicit collection request, confirm the target vault path first, and avoid broad SEO prompts that could activate it unintentionally.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger scope is overly broad and overlaps with common SEO-related requests, increasing the chance that the skill auto-activates in contexts where the user did not intend X scraping or local file modification. Because the skill has exec/read/write capabilities and is documented to collect account-specific X data and write into a local vault, ambiguous invocation meaningfully raises the risk of unauthorized actions.

Vague Triggers

Low
Confidence
76% confidence
Finding
The example trigger '采集今日 AI 内容日报' is underspecified and lacks consent checkpoints for browsing a logged-in X account or writing to local storage. In a tool-enabled agent environment, vague activation examples can cause the skill to run without clear user awareness of data access and side effects.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes writing reports into the user's Obsidian Vault but does not prominently warn that it will modify local files or require explicit confirmation of the destination path. In a tool-enabled agent, silent or poorly signposted local writes can lead to unintended file creation, overwrites, or writes into sensitive synced note repositories.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill collects the logged-in user's X home timeline, which is account-specific data that may reflect private interests, contacts, recommendations, and potentially sensitive browsing context. Without a clear privacy warning and explicit consent boundary, the skill could access and summarize personal feed data beyond what the user expected, making this especially risky in an agent with browser or exec capabilities.

Static analysis

No suspicious patterns detected.