Back to skill

Security audit

新闻聚合引擎

Security checks for vulnerabilities and agentic risk

Overview

This news aggregation skill is not clearly malicious, but it asks for broad file, command, API, and callback capabilities that are not well scoped for a news summary tool.

Review this skill before installing. It may be acceptable only in a sandboxed agent where you can approve each command, file access, API call, and callback destination. Avoid giving it broad filesystem access, secrets, or API keys unless you have verified why they are needed for your specific news task.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:10
Finding

Excessive File-Access and Command-Execution Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-12
Vulnerability Type: Excessive Agent tool privileges
Risk Level: Medium

The skill declares general-purpose local file-reading and command-execution capabilities:

yaml
tools:
  - read
  - exec

Related instructions reinforce the intended availability of these capabilities at SKILL.md:290-292:

markdown
- **File processing**: Supports reading, parsing, and writing multiple file formats
- **API integration**: Calls external services through standardized interfaces and processes responses
- **Command execution**: Executes system commands in a secure sandbox and collects results

Technical Analysis

The stated purpose of this skill is to search, filter, deduplicate, and summarize news. That workflow does not inherently require unrestricted access to local files or a general command-execution interface. Declaring read and exec therefore violates the principle of least privilege.

The document does not define:

  • An allowlist of permitted commands or executables
  • Validation or escaping rules for command arguments
  • Restrictions on accessible file paths
  • A restricted working directory
  • Controls preventing access to environment variables or credentials
  • Enforced sandbox boundaries
  • A requirement for user confirmation before sensitive operations

Although the document states that commands execute in a sandbox, it provides no enforceable sandbox configuration. It also inconsistently describes the skill as MD+EXEC at line 62 and as a pure Markdown skill at line 332. No malicious command or direct exploitation implementation was found, but the excessive permissions create an exploitable capability boundary if attacker-controlled instructions reach the Agent.

Attack Path

A plausible exploitation sequence is:

  1. A user supplies malicious input, a custom news-source URL, or content containing adversarial ins ...[truncated 1543 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove read and exec from the declared tools because they are not required for news aggregation.
  2. Replace them with narrowly scoped web-search and HTTP-fetch capabilities restricted to approved protocols and domains.
  3. If local reading is genuinely required, limit access to a dedicated working directory and reject absolute paths, traversal sequences, symbolic-link escapes, and sensitive system locations.
  4. If command execution is unavoidable:
    • Use a fixed executable and subcommand allowlist.
    • Pass validated arguments without invoking a shell.
    • Reject shell metacharacters and user-controlled command fragments.
    • Run commands in an isolated container with a read-only filesystem, no host mounts, no secrets, minimal environment variables, restricted networking, and an unprivileged account.
    • Require explicit user confirmation for every command.
  5. Treat article text, search results, custom source URLs, and callback-related values as untrusted data rather than Agent instructions.
  6. Document and enforce output controls that prevent local file contents or credentials from being included in news summaries.
  7. Correct the contradictory MD+EXEC and pure-Markdown classifications so the declared capability model accurately reflects the implementation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The top-level description is broad and vague, describing general efficiency improvement and aggregation behavior without precise activation boundaries. Broad descriptions make prompt routing and tool use less predictable, increasing the risk that unrelated or attacker-crafted instructions are treated as in-scope for a privileged skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Accepting generic 'input data or instructions' gives the skill effectively open-ended trigger scope. In an agent setting, that ambiguity can let hostile prompt content smuggle unrelated operational instructions into a skill that also advertises powerful capabilities, including exec and callback handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented callback_url enables transmission of results to an arbitrary external endpoint without any warning, validation, or trust boundary guidance. That creates a straightforward exfiltration path for retrieved content, internal summaries, or even accidentally included sensitive data if an attacker supplies a malicious callback destination.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The FAQ states that for international news the skill will translate titles and key points into Chinese. This imposes a specific language behavior without offering the user a choice or documenting opt-in, which is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

For a news aggregation skill, documenting generic file handling, API integration, and especially command execution is overbroad and not tied to a narrowly defined workflow. Excess capabilities increase the chance that an agent will perform unnecessary local actions or run arbitrary commands in response to ambiguous prompts, expanding the attack surface beyond simple retrieval and summarization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Advertising file write, API integration, and command execution without user-facing warnings normalizes high-risk actions in a skill whose primary function is content aggregation. Users and orchestrators may not realize the skill can modify local state or initiate privileged operations, which raises the likelihood of unsafe invocation and abuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and body are internally inconsistent: it advertises exec in frontmatter and elsewhere describes API, file, and command execution, but later classifies itself as pure Markdown. That mismatch can mislead users and agents about the actual privilege level, causing execution-capable behavior to be invoked under a lower-trust assumption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.