Back to skill

Security audit

yoooclaw-personal-daily

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese news-daily skill that reads configured topics and uses search or fixed RSS feeds, with network-fetch hardening worth considering but no hidden destructive behavior found.

Install this only if you want a Chinese-language daily news workflow and are comfortable with your configured interest topics being used in search/RSS requests. In sensitive network environments, run it with egress controls that block private, loopback, link-local, and metadata-service addresses because the RSS helper does not enforce those checks itself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_rss.py:126
Finding

Server-Side Request Forgery Through Unvalidated RSS Destinations and Redirects

Content
View full analysis

Vulnerability Details

File Location: scripts/fetch_rss.py:126-150
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Medium

Vulnerable Code

python
def fetch(url, limit):
    parsed_url = urllib.parse.urlparse(url)
    if parsed_url.scheme not in {"http", "https"}:
        raise ValueError("only HTTP(S) feed URLs are allowed")
    request = urllib.request.Request(
        url,
        headers={
            "User-Agent": "YoooClaw-RSS/1.0 (+https://clawhub.ai/)",
            "Accept": "application/rss+xml, application/atom+xml, text/xml, application/xml",
        },
    )
    with urllib.request.urlopen(request, timeout=15) as response:
        final_url = response.geturl()
        content = response.read(MAX_RESPONSE_BYTES + 1)
    if len(content) > MAX_RESPONSE_BYTES:
        raise ValueError("feed response exceeds 5 MiB")
    root = ET.fromstring(content)
    if local_name(root.tag) == "feed":
        feed_title, items = parse_atom(root, final_url, limit)
    else:
        feed_title, items = parse_rss(root, final_url, limit)
    return {
        "ok": True,
        "feed_title": feed_title,
        "url": final_url,

Technical Analysis

The URL validation only permits http and https schemes. It does not reject loopback, private, link-local, reserved, unspecified, multicast, or cloud metadata addresses.

Furthermore, urllib.request.urlopen() follows HTTP redirects automatically. The resulting final_url is retrieved but is not subjected to any destination validation. Therefore, an initially trusted public RSS endpoint can redirect the request to a network location that should not be reachable through the Skill.

The documented workflow limits normal execution to 17 fixed public feeds, which reduces direct attacker control over the initial URL. However, it does not mitigate a compromised or misconfigured feed, an unsafe redirect, or applicable DNS manipulation. The client can retrieve up to 5 MiB from t ...[truncated 1586 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for configured feeds

    • Reject plain HTTP initial URLs.
    • Reject redirects that downgrade from HTTPS to HTTP.
  2. Enforce an exact destination allowlist

    • Maintain an explicit list of approved RSS hostnames.
    • Validate both the initial URL and every redirect target against that list.
    • Compare canonicalized hostnames rather than using suffix or substring matching.
  3. Validate resolved IP addresses

    • Resolve the destination before connecting.
    • Reject loopback, private, link-local, multicast, reserved, unspecified, and documentation-only address ranges for both IPv4 and IPv6.
    • Validate every address returned by DNS resolution.
  4. Control redirects

    • Disable automatic redirects and process them explicitly, or install a redirect handler that validates every Location target.
    • Set a small maximum redirect count.
    • Revalidate the final URL and its resolved address before accepting the response.
  5. Mitigate DNS rebinding

    • Ensure the address validated is the address used for the connection.
    • Revalidate destination addresses after redirects.
    • Prefer network-layer egress controls that deny access to internal and link-local ranges.
  6. Apply defense in depth

    • Run the RSS process with restricted network egress.
    • Preserve the existing timeout and response-size limits.
    • Log rejected destinations without exposing credentials or sensitive response content.
    • Add tests covering redirects to 127.0.0.1, ::1, RFC 1918 networks, link-local ranges, and common cloud metadata addresses.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个完整的新闻日报技能,核心在于:基于用户主题主动搜集新闻、在不同宿主中选择搜索工具、必要时回退 RSS,并最终生成日报内容。实际代码只是底层的 RSS/Atom 获取与解析组件,功能范围明显更窄,且缺少声明中最关键的行为:主题驱动的新闻发现、工具选择/回退编排、日报文本生成、趋势分析与来源汇总。虽然声明中提到回退内置 RSS,而该脚本可作为 RSS 获取的支持实现,但单独看此代码块,其主要目的并不等同于所声明的完整技能,因此构成描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill clearly instructs the agent to perform network-backed news acquisition and tool selection, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization-boundary problem: a host may expose broader network/tool access than intended, and reviewers cannot verify least-privilege constraints from the manifest alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file instructs the skill to always construct both Chinese and English queries for every search group. This imposes a fixed language behavior without offering user opt-in or explaining a justified region-specific requirement, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains all user-facing operational instructions in Chinese and does not indicate that language selection is optional or configurable. That can violate a language/locale policy when a skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s title and all output template text are in Chinese, and the instructions require producing the report in that language. This is a natural-language locale constraint that applies to all uses of the template, with no user opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file instructs that the final reply must include specific Chinese phrasing such as “RSS 来源:国内 … 海外 … 总计 …”, which imposes a fixed language on user-facing output. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document is entirely scoped to domestic Chinese RSS sources and uses Chinese-language content labels without indicating any user choice or opt-in for language/locale. Under the policy, forcing a specific language or locale without offering choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code emits the Chinese string "(无标题)" as a fallback title, which imposes a specific language in user-facing output. The file does not offer a locale choice or document a justified region-specific constraint, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The RSS parsing path also uses the Chinese fallback string "(无标题)" for missing titles. Because this user-visible output is forced regardless of user preference, it violates the language/locale policy criteria for all file types.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.