Back to skill

Security audit

每日要闻

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese daily-news skill that fetches news from a disclosed third-party API, with ordinary privacy and content-trust cautions but no evidence of hidden, destructive, persistent, or credential-seeking behavior.

Install this only if you are comfortable with news queries being sent to api.cjiot.cc. Use it for explicit news requests, and treat fetched article bodies as untrusted third-party content rather than instructions for the agent to follow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个较完整的新闻技能,包含每日摘要、详情阅读、按日期查询和热点排行。当前提供的代码片段确实实现了“按日期获取每日新闻摘要列表”这一部分,也会按 heat 字段排序展示,因此与新闻获取主题基本一致。但它没有实际实现“新闻详情阅读”,只是打印提示让用户调用另一个脚本;也没有看到独立的热点新闻排行能力,只有对返回列表进行本地排序。因此,代码行为只覆盖了声明中的部分功能,声明范围明显大于该代码片段实际实现的能力,存在描述与行为不完全一致的情况。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill is designed to send user-derived parameters such as dates and article IDs to an external domain, which is an actual external data transmission path. Although the transmitted data appears low sensitivity in this context, any third-party network call introduces privacy, dependency, and supply-chain risk, especially if invocation can happen automatically.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

接口地址:

text
https://api.cjiot.cc/api/v1/daily?date={YYYY-MM-DD}

参数说明:

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

Fetching article details from a third-party endpoint is a real outbound network action and exposes the agent to untrusted remote content. The returned content includes HTML fields, so even though the markdown says tags should be removed, remote content must be treated as untrusted to avoid unsafe rendering or downstream prompt/content injection.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

接口地址:

text
https://api.cjiot.cc/api/v1/articles/{article_id}

参数说明:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger rules are broad enough to invoke the skill for generic mentions such as '新闻' or '头条', which can cause unintended network requests to a third-party API and unexpected context switching. In an agent environment, over-broad activation increases the chance of data being sent externally when the user did not explicitly request this skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This step operationalizes the external request with curl, confirming that the skill performs outbound network access to a third-party service. While normal for a news skill, the danger comes from automatic invocation and reliance on untrusted remote responses, not from the news use case itself.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
**处理步骤:**
1. 获取当前日期(格式:YYYY-MM-DD)
2. 调用 API:`curl -s "https://api.cjiot.cc/api/v1/daily?date={当前日期}"`
3. 解析返回的新闻列表
4. 按热度排序展示前 10 条新闻摘要

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill sends a user-supplied date to an external API, which is a legitimate but real external transmission. In this context the parameter is low sensitivity, so the main risk is privacy leakage of user intent/history and dependence on a third-party service, rather than direct compromise.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
**处理步骤:**
1. 解析用户输入的日期
2. 调用 API:`curl -s "https://api.cjiot.cc/api/v1/daily?date={日期}"`
3. 解析并展示新闻列表

**回复模板:**

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This external request fetches detailed article content, including HTML-bearing fields, from a remote service based on context-selected article IDs. The skill context makes this somewhat more dangerous than a simple summary fetch because it processes richer untrusted content that could lead to unsafe rendering or content injection if not sanitized.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
**处理步骤:**
1. 从上下文获取当前新闻列表
2. 提取用户指定的文章 ID
3. 调用 API:`curl -s "https://api.cjiot.cc/api/v1/articles/{article_id}"`
4. 解析并展示新闻详情(标题、分类、热度、正文)

**回复模板:**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language documentation and console output in Chinese, including the usage instructions, error text, and result labels, with no indication that the user can choose another language. Under the language/locale policy rule, forcing a specific language without user opt-in is a reportable policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-article.js (reported line 32)May include surrounding context.

js
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-daily.js (reported line 25)May include surrounding context.

js
process.exit(1);
  }

  const url = `https://api.cjiot.cc/api/v1/daily?date=${date}`;

  https.get(url, (res) => {
    let data = '';

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language content throughout the file is exclusively in Chinese, including the description, trigger examples, and reply templates. The file does not state that the skill is region-specific or give users a choice of language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains natural-language strings entirely in Chinese, including the top-level usage documentation and runtime error/help output. That imposes a specific language on users without any opt-in or alternative, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.