Back to skill

Security audit

news-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese daily-news helper that calls a disclosed public news API and does not show hidden persistence, credential use, local data access, or destructive behavior.

Install this only if you are comfortable with a Chinese-language news skill contacting api.cjiot.cc when you ask for news. Be aware that broad trigger wording may activate it on general news mentions, and treat fetched article content as third-party, untrusted text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

代码的核心行为与“每日新闻获取/按日期查询”基本一致:它接收可选日期参数,请求远程 API,获取每日新闻摘要列表并展示。但声明中还包括“新闻详情阅读”和“热点新闻排行”两项能力,而当前提供的代码并未实现新闻详情读取,也未实现独立或更广义的热点新闻排行功能,只是对当天文章做本地热度排序输出。因此,代码行为只部分覆盖了声明能力,存在描述与实际实现不完全一致的情况。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L003 使用“每日新闻获取技能”中文描述本身没有问题,但整份技能文档仅以中文定义交互示例、回复模板和触发方式,隐含该技能仅按中文进行交互,未说明是否支持其他语言或允许用户选择输出语言。按照语言/区域策略,若限定语言应有明确 opt-in、选择机制或合理的地区性说明。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions include broad keywords such as '新闻', '日报', and '头条', which can cause the skill to activate during ordinary conversation that merely mentions news. That can lead to unintended outbound requests to the third-party API and unnecessary context exposure, even if the transmitted data is limited.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

This flow retrieves article content from a third-party service and explicitly instructs the agent to display HTML-derived fields after transformation. If sanitization is incomplete or inconsistent, untrusted remote content could propagate into downstream renderers or prompt context, creating content-injection or unsafe rendering risk beyond a simple network call.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
**处理步骤:**
1. 从上下文获取当前新闻列表
2. 提取用户指定的文章 ID
3. 调用 API:`curl -s "https://api.cjiot.cc/api/v1/articles/{article_id}"`
4. 解析并展示新闻详情(标题、分类、热度、正文)

**回复模板:**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language strings exclusively in Chinese in the header comments and error/usage output. Under the policy rule for language/locale, forcing a specific language without user opt-in or a documented region-specific justification is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s docstring and all CLI output are written exclusively in Chinese, which imposes a specific language on users without any opt-in or configuration. Under the policy rules, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-article.js (reported line 32)May include surrounding context.

js
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-daily.js (reported line 25)May include surrounding context.

js
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

Static analysis

No suspicious patterns detected.