Back to skill

Security audit

Tech Morning Briefing

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed daily tech-news briefing workflow that searches public news, posts summaries to Feishu, and keeps bounded local state for deduplication and rotation.

Before installing, confirm you want a daily scheduled job that sends generated tech-news summaries to Feishu and appends them to a Feishu archive document. Use a Feishu app with only the permissions needed for chat push and document creation/append, protect the Tavily API key, and adjust the cron timezone or schedule if Asia/Shanghai is not appropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly describes automatic Feishu chat pushes and archival document writes, but it does not clearly warn users that collected content will be sent to a third-party service and stored persistently. This can lead to unintentional outbound sharing and retention of scraped or summarized content, which is a meaningful privacy and data-governance risk in an automated scheduled skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs persistent writes to local files and synchronization of generated content to a Feishu document, but it does not require any user-facing notice, consent, or retention disclosure. This creates a privacy and data-governance risk because searched content, generated summaries, history, and document identifiers may be retained or shared externally without the operator or end user understanding what is stored, for how long, or where it is sent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README presents the skill as '每日科技晨报' and the cron task string is fully specified in Chinese, indicating a fixed language expectation. Because no opt-in or language-selection mechanism is documented, this can be read as a locale/language policy issue under the rule for natural-language policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scheduled run example fixes execution to '30 7 * * *' in the 'Asia/Shanghai' timezone. Since the README does not frame this as a user-selectable default or a region-specific skill, it introduces a locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction requires the ending quote to be in English every day, which imposes a specific language choice on output despite the rest of the skill being Chinese. This is a natural-language locale policy concern because no user opt-in or configurable language preference is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.