Back to skill

Security audit

新闻订阅

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly describes RSS news fetching, but it requests and advertises command execution and arbitrary feed access without enough scoping or safeguards.

Review before installing. This skill should only be used in an agent environment that does not grant unrestricted shell execution, validates custom RSS URLs, blocks internal/private network destinations, prefers HTTPS-only feeds, and treats fetched feed/article content as untrusted data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:24
Finding

Unnecessary General Command-Execution Permission

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-26
Additional References: SKILL.md:242, SKILL.md:335-337
Vulnerability Type: Excessive tool privileges
Risk Level: High

Evidence

yaml
tools:
- read
- exec

Technical Analysis

The Skill declares unrestricted exec capability even though its stated purpose is to retrieve and process public RSS feeds. RSS retrieval requires a constrained network-fetching interface, not general shell execution.

No executable implementation, command allowlist, argument validation mechanism, or enforceable sandbox policy is included in the project. The document also advertises generic file processing and system-command execution. These permissions exceed the minimum privileges required for the declared news-feed functionality.

Because the package consists only of instructions, exploitation depends on the hosting Agent granting and interpreting these capabilities. If exec is granted, untrusted user input, RSS content, or article content could influence the Agent into executing commands unrelated to news retrieval.

Attack Path

  1. An attacker provides a malicious custom feed or causes hostile text to appear in a retrieved feed.
  2. The Agent loads the feed content into its context.
  3. The hostile content instructs or persuades the Agent to invoke the Skill's declared exec capability.
  4. Without an enforceable command allowlist, the Agent runs an unintended system command.
  5. The command may read local files, alter accessible data, initiate network connections, or execute other programs within the Agent process's permission boundary.

Impact Assessment

Successful exploitation could provide command execution with the operating-system privileges of the hosting Agent. The accessible scope may include local files, environment variables, network resources, and writable directories available to that process.

There is no evidence that this ...[truncated 178 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tools.
  2. Replace shell-based retrieval with a dedicated HTTP client that exposes only GET requests.
  3. Restrict network access to approved RSS hosts when custom feeds are not required.
  4. If export is necessary, permit writes only to an explicitly selected output directory using a constrained file API.
  5. If command execution is genuinely required, document the exact commands and enforce a fixed executable allowlist with structured arguments.
  6. Never concatenate URLs, keywords, filenames, feed content, or other untrusted values into shell command strings.
  7. Run the Skill with a dedicated low-privilege account, a read-only filesystem where possible, and restricted outbound networking.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:188
Finding

Arbitrary Custom RSS URLs Can Enable Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:188-195
Additional References: SKILL.md:256, SKILL.md:262
Vulnerability Type: Unvalidated outbound network destination
Risk Level: High

Evidence

json
{
  "custom_source": {
    "name": "TechCrunch",
    "url": "https://techcrunch.com/feed/",
    "language": "en",
    "category": "technology"
  }
}

The instructions permit custom and mirror RSS URLs and separately recommend retrieving article URLs using general web-fetching tools or curl.

Technical Analysis

The Skill does not define validation rules for user-controlled URLs. In particular, it provides no:

  • Allowed-scheme policy
  • Host or domain allowlist
  • Private, loopback, link-local, multicast, or reserved address blocking
  • DNS rebinding protection
  • Redirect validation
  • Port restrictions
  • Response size or timeout limits
  • Content-type enforcement

As a result, an Agent implementing these instructions may treat an arbitrary URL as an RSS source. An attacker could direct requests toward localhost services, private network hosts, or cloud metadata endpoints. Redirects or DNS rebinding could bypass validation that only checks the original hostname.

Recommending curl increases the exposure when combined with the unnecessary exec permission, especially if the URL is interpolated into a shell command.

Attack Path

  1. An attacker supplies a custom RSS URL controlled by the attacker or referencing a private address.
  2. The Agent accepts the URL without validating its resolved destination.
  3. The Agent requests the URL directly or follows an attacker-controlled redirect.
  4. The request reaches a localhost service, internal network endpoint, or cloud instance metadata service.
  5. The response is parsed as feed or article content and returned to the Agent context.
  6. Internal information may then be disclosed through the Skill's output.

A var ...[truncated 638 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an allowlist of known RSS providers.
  2. If custom sources are required, permit only https URLs.
  3. Reject embedded credentials, nonstandard ports, malformed hosts, and unsupported URL schemes.
  4. Resolve the hostname before connecting and reject loopback, private, link-local, multicast, unspecified, and reserved address ranges for both IPv4 and IPv6.
  5. Repeat destination validation after every DNS resolution and redirect.
  6. Limit redirect count and reject cross-scheme redirects.
  7. Apply connection, read, and total-operation timeouts.
  8. Limit response size and require an expected RSS or Atom content type.
  9. Disable access to cloud metadata endpoints at both the application and network layers.
  10. Do not use shell commands or curl through exec; use a structured HTTP client that does not invoke a shell.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:180
Finding

Preconfigured RSS Feed Uses Unencrypted HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:180
Vulnerability Type: Plaintext network communication
Risk Level: Medium

Evidence

text
http://feeds.bbci.co.uk/news/rss.xml

Technical Analysis

One preconfigured feed uses plaintext HTTP rather than HTTPS. HTTP provides neither transport confidentiality nor server authentication and does not protect response integrity.

A network-positioned attacker can modify the feed response before it reaches the Agent. Because retrieved news content is subsequently summarized or processed as Agent input, tampered content could produce false reports or introduce adversarial instructions into the Agent context.

The plaintext endpoint also contradicts the Skill's own guidance requiring HTTPS and certificate validation.

Attack Path

  1. The Agent requests the preconfigured feed over HTTP.
  2. An attacker controlling or observing the network path intercepts the request.
  3. The attacker replaces or modifies the RSS response.
  4. The Agent parses the altered titles, summaries, links, or embedded text.
  5. The malicious content influences generated output or attempts to trigger other granted tools, including the declared command-execution capability.

Impact Assessment

An attacker may manipulate news content, links, and instructions consumed by the Agent. This can compromise output integrity and may facilitate follow-on attacks when the Agent automatically follows links or treats feed content as trusted instructions.

This issue does not itself disclose local secrets, but it removes transport integrity and creates an injection point into the Agent's processing context.

Remediation
View remediation

Remediation Suggestions

  1. Replace the HTTP feed URL with the provider's verified HTTPS endpoint.
  2. Enforce HTTPS for every predefined and custom source.
  3. Enable normal TLS certificate and hostname verification without insecure overrides.
  4. Reject redirects that downgrade from HTTPS to HTTP.
  5. Treat all retrieved feed content as untrusted data rather than executable instructions.
  6. Sanitize feed markup and prevent retrieved content from authorizing tool calls or changing Agent behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as a simple RSS headline fetcher, yet later advertises file handling and system command execution as core features. That capability expansion creates a material mismatch between user expectations and actual authority, increasing the chance the agent invokes powerful operations under an innocuous news-related pretext.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill uses broad activation language around common writing and marketing tasks, which can cause over-invocation outside a narrowly defined news-fetching workflow. In an agent setting, ambiguous triggers are dangerous because they increase the odds that a networked, higher-privilege skill is selected in contexts where it is unnecessary, exposing user prompts and enabling unintended side effects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Declaring exec for a skill whose stated purpose is fetching RSS feeds violates least privilege. Even if no explicit exploit string is shown in this file, unnecessary execution capability materially increases the attack surface because future prompts, examples, or implementation details may route user input into shell commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill supports outbound requests to external RSS feeds and even custom RSS URLs without clearly warning users that their queries, topics, or configured sources may be transmitted to third parties. In this context, the danger is elevated because custom URLs can direct the agent to untrusted endpoints, creating privacy, tracking, and potentially SSRF-like exposure depending on the runtime.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is presented as an AI skill driven through parameters in conversation, yet the '数据导出' section shows direct CLI command usage (news-feed --export ...), implying a standalone executable workflow not otherwise described. This creates intent/documentation divergence about how the skill actually operates and whether it includes command execution behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.