Back to skill

Security audit

RSS摘要工具免费版

Security checks across malware telemetry and agentic risk

Overview

This is a coherent RSS digest skill that uses a local feed CLI and expected network fetching, with some documentation rough edges users should notice.

Before installing, verify the external `feed` CLI source, expect the tool to contact RSS feeds and article sites when fetching content, and only let it mark entries as read when you explicitly ask for that action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill states that the AI should not automatically mark items as read, yet it also advertises and documents a bulk mark-as-read command as part of normal usage. This inconsistency can cause an agent to perform state-changing actions on a user's RSS database without clear confirmation, leading to data loss in the form of skipped unread content and reduced auditability of what was actually reviewed.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger condition says the skill should be used for SEO optimization, keyword analysis, ranking improvement, and search traffic optimization, which does not match the RSS digest functionality described elsewhere. Overbroad or mismatched triggers can cause an agent to invoke the skill in unrelated contexts, increasing the chance of inappropriate tool use, confusing outputs, or unintended command execution under false assumptions.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill encourages direct URL fetching and feed-content retrieval but does not clearly warn users that using the skill may initiate network access to third-party sites and expose requested URLs, feed metadata, or access patterns. In agent environments, this can create privacy and security risks, especially if feeds or fetched URLs are sensitive, internal, or user-identifying.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.