Back to skill

Security audit

新闻

Security checks for vulnerabilities and agentic risk

Overview

This finance-news skill asks for command execution and broad file handling that are not clearly scoped to news search and summarization.

Review carefully before installing. Use it only in a sandboxed agent environment where command execution is disabled or tightly allowlisted, and do not grant broad filesystem access unless you have verified exactly what files it can read or write. There is no artifact-backed evidence of malware, persistence, or exfiltration, but the requested authority is broader than a finance-news summarizer needs.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:24
Finding

Excessive File-Read and Command-Execution Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-26
Vulnerability Type: Excessive privileges and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec

Technical Analysis

The skill declares both file-reading and system-command execution capabilities, although its documented purpose is to search for and summarize financial news. Unrestricted local file access and command execution are not inherently necessary for that task; a narrowly scoped network retrieval interface would ordinarily be sufficient.

This violates the principle of least privilege. The risk is increased by the generic instruction input documented at SKILL.md:68-72 and by the later assertion that the skill supports file processing and system-command execution at SKILL.md:205-210. The document recommends command allowlisting and sandboxing, but it does not define or enforce a command allowlist, permitted path boundaries, argument validation, or sandbox policy.

The package contains no executable implementation, so actual command execution, sandbox escape, or malicious intent cannot be confirmed from the audited artifact. The finding concerns the excessive authority requested by the skill definition and the absence of enforceable restrictions.

Attack Path

  1. An agent loads the skill and grants the declared read and exec tools.
  2. An attacker supplies crafted instruction text directly or through untrusted news content processed by the skill.
  3. The crafted content induces the agent to read a local file unrelated to financial-news processing or to invoke a system command.
  4. Because no enforceable command allowlist, path restriction, or argument-validation policy is defined, the invocation may operate outside the skill's legitimate scope.
  5. The resulting local data or command output may be exposed in the agent response or used to perform additional actions permitted by the execut ...[truncated 1016 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the exec capability because financial-news retrieval and summarization should not require arbitrary system-command execution.
  2. Replace unrestricted read access with a dedicated HTTPS or search tool limited to approved financial-news sources.
  3. If local file access is essential, restrict it to explicitly designated workspace paths and deny traversal, symbolic-link escapes, hidden credential files, and environment configuration files.
  4. If command execution cannot be removed, enforce a host-level allowlist of exact executables and fixed argument schemas. Do not construct shell commands from user instructions or retrieved content.
  5. Execute permitted operations in an isolated sandbox with a read-only filesystem, minimal operating-system identity, no inherited secrets, restricted network egress, resource limits, and no access to unrelated workspaces.
  6. Treat user instructions and retrieved news content strictly as untrusted data. Validate structured inputs and prevent retrieved text from altering tool-use policy.
  7. Document the exact tools, paths, hosts, HTTP methods, and operations required by the skill so that permissions can be reviewed and enforced.
  8. Add automated tests verifying that attempts to access unauthorized files, execute non-allowlisted commands, or contact unapproved hosts are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The invocation guidance is overly broad and encourages use for generic productivity, automation, batch processing, and workflow optimization rather than narrowly for market news. In combination with powerful tools like exec, this increases the chance the skill is selected for unrelated requests, allowing a seemingly benign news skill to gain access in contexts where its expanded capabilities are dangerous.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Additional broad 'Use when' language expands the skill's applicability to generic data analysis, reporting, and visualization tasks that are outside its named purpose. This kind of scope inflation is risky because it can cause an agent to invoke a capability-bearing skill in far more situations than users would reasonably expect, especially when the skill also advertises command execution and file operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

System command execution is not justified by the stated task of searching and summarizing financial news, so exposing exec materially increases the attack surface without a clear functional need. In an agent environment, this can enable prompt-driven command execution, environment inspection, local file access, or other host-side actions under the guise of a harmless news skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a market-news search and summarization tool, but the documentation broadens its behavior to include generic file handling, external API use, and system command execution. This capability expansion creates a misleading trust boundary: users may invoke a low-risk news skill while actually granting a much higher-risk action surface that could modify files or run commands unrelated to news retrieval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The display name, summary, and description are presented in Chinese, while no language-selection or opt-in behavior is described. This can violate a language/locale policy when a skill imposes a specific language without offering the user a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The paid-features table says multi-source aggregation, semantic search, and intelligent summarization are unavailable in the free version. Elsewhere, the manifest broadly describes the skill itself as automatically searching and summarizing latest financial news and market dynamics, creating a direct documentation-level contradiction about what the skill actually provides.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation mentions file handling, API integration, and command execution but does not provide a clear, prominent warning that these actions may affect local data or system state. This creates a consent and transparency problem: users may reasonably assume a news skill is low impact when it can actually perform side-effecting operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

General file write capability is broader than necessary for a news retrieval/summarization skill and can be abused to alter local data, drop artifacts, or overwrite user files. Even if intended for report export, describing broad file-processing behavior without scoping output locations or formats creates unnecessary risk in a context that users would expect to be mostly read-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.