Back to skill

Security audit

新闻订阅

Security checks across malware telemetry and agentic risk

Overview

This news RSS skill mostly describes ordinary headline fetching, but it also requests and advertises broad command execution and file-writing behavior that is not clearly scoped to that purpose.

Review this skill carefully before installing. It may be useful for RSS news aggregation, but grant exec authority only if you are comfortable with the agent running local commands for this workflow, and use explicit output paths for exports to avoid accidental overwrites. Do not provide sensitive API keys unless you understand why they are needed, because public RSS fetching should usually not require one.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill is presented as a news RSS fetcher, but later advertises file handling and system command execution as core features. This capability mismatch is dangerous because it expands the operational scope beyond what a user would reasonably expect, increasing the chance that an agent grants or uses powerful `exec` behavior under a benign-looking skill label.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The skill uses broad activation language around generic content creation and marketing tasks instead of narrowly scoping itself to RSS news retrieval. Overbroad prompting increases the likelihood that an agent invokes this skill in unrelated contexts where its network and execution capabilities are unnecessary, expanding attack surface and enabling capability misuse.

Missing User Warnings

Low
Confidence
72% confidence
Finding
The markdown describes exporting results to local files without a clear warning that the skill may create or overwrite files. In an agent environment, undisclosed file-modification behavior can surprise users and lead to accidental data loss or unauthorized writes when combined with automated execution flows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.