Back to skill

Security audit

新闻聚合工具免费版

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only news aggregation skill with some sloppy and inconsistent wording, but no artifact-backed hidden execution, persistence, credential use, or destructive behavior.

Install only if you are comfortable with the agent making live web requests to news/search sources for your prompts. Do not provide a callback URL unless you specifically want results sent there and trust that destination. Treat the SEO and generic export/create language as documentation defects, not core capability instructions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The skill is presented as a narrowly scoped news aggregation tool, but the documented 'create/query/export' operations materially broaden its implied behavior. Scope ambiguity is dangerous because it can cause the agent or user to authorize actions beyond passive summarization, including file creation or data export workflows that were not clearly disclosed or constrained.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documentation says the free version does not support exporting news, yet later text states that execution supports export operations. Contradictory capability claims create a safety and trust problem: an agent may attempt data export despite user expectations, potentially writing files or transmitting aggregated content in ways the user did not intend.

Vague Triggers

Medium
Confidence
77% confidence
Finding
Ambiguous trigger conditions and broad activation language increase the chance that the skill runs in contexts the user did not specifically intend. In a tool with network retrieval behavior, unclear activation boundaries can lead to unnecessary external requests, overcollection of content, or invocation during unrelated conversations.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill performs live retrieval from external news sources and accepts a user-supplied callback URL, but it does not clearly warn users that using the skill may contact third-party services. This omission is dangerous because it can expose user queries, metadata, or result payloads to external domains, and callback behavior can be abused for unexpected outbound requests or data exfiltration.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.