Back to skill

Security audit

每日毛选语录硬核推送

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it handles messaging credentials and unattended pushes with enough under-disclosed and weakly scoped behavior that users should review it carefully before installing.

Install only if you are comfortable with a Chinese-language daily automation that writes Markdown files locally and may send generated content to Telegram on a schedule. Use --no-send or --dry-run first, set a dedicated Telegram bot/chat, restrict the output directory, avoid running install.sh with elevated privileges, and rotate the bot token if logs may already contain failed Telegram request details.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_daily.py:47
Finding

Telegram Bot Token May Be Disclosed Through Persistent Exception Logs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/install.sh:17
Finding

Mutable Dependency Range Is Installed Globally Without Integrity Verification

Content
View full analysis
/dev/null; then echo "Installing requests..." pip3 install "requests>=2.31.0,<3" fi echo "Dependency check completed" ``` ### Technical Analysis The installation script resolves `requests` from the active pip package index using a mutable version range. It does not use: - An exact dependency version - Package hashes - A lock file - An isolated virtual environment - An explicitly trusted package index Consequently, two installations performed at different times can resolve different package artifacts. A compromised package-index account, malicious mirror, poisoned pip configuration, or future compromised release within the accepted range could introduce unreviewed code. The command also invokes `pip3` against the active Python environment. Depending on how the installer is run, this can modify a shared user or system Python installation and affect unrelated applications. No malicious dependency name or current dependency compromise was identified. The issue is the unsafe and non-reproducible installation mechanism. ### Attack Path 1. An attacker compromises an accepted package source, configured mirror, package publisher account, or a future release satisfying `requests>=2.31.0,<3`. 2. The target runs `scripts/install.sh` in an environment where `requests` is not already importable. 3. `pip3` resolves and downloads the attacker-controlled or compromised artifact. 4. Installation-time package behavior executes with the privileges of the user running the installer. 5. The malicious dependency can modify files, access that user's data and credentials, or persist through the Python environment. 6. If the script is run with ...[truncated 620 chars]
Remediation
View remediation
" .venv/bin/python -m pip install \ --require-hashes \ --index-url https://pypi.org/simple \ -r requirements.lock ``` 5. Generate `requirements.lock` from a reviewed environment and include hashes for every downloadable artifact. 6. Document that the installer should not be run with unnecessary elevated privileges. 7. Review and lock all runtime dependencies, including `httpx`, which is imported by `scripts/deep_gen.py` but is not installed by the current installer. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Tainted flow: 'DEEPSEEK_API_KEY' from os.environ.get (line 24, credential/environment) → httpx.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/deep_gen.py (reported line 96)May include surrounding context.

python
try:
        logger.info("调用 DeepSeek API 生成硬核深度解读(v5.0 协议)...")
        resp = httpx.post(
            f"{DEEPSEEK_BASE_URL}/chat/completions",
            headers={
                "Authorization": f"Bearer {DEEPSEEK_API_KEY}",

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/generate_daily.py (reported line 40)May include surrounding context.

python
e,
        save_files,
        setup_logging
    )
    from deep_gen import (
        generate_deep_analysis,
        create_deep_document,
        format_deep_telegram_message
    )
except ImportError as e:
    logging.error(f"导入模块失败: {e}")
    sys.exit(1)


def send_telegram(message: str) -> bool:
    """发送 Telegram 消息"""
    try:
        import requests

        bot_token = os.environ.get('TELEGRAM_BOT_TOKEN')
        chat_id = os.environ.get('TELEGRAM_CHAT_ID')

        if not bot_token or not chat_id:
            logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False

        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,
            'parse_mode': 'HTML',
            'disable_web_page_preview': True
        }

        response = requests.post(url, data=data, timeout=30)
        result = response.json()

        if result.get('ok'):

Tainted flow: 'url' from os.environ.get (line 47, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/generate_daily.py (reported line 55)May include surrounding context.

python
'disable_web_page_preview': True
        }

        response = requests.post(url, data=data, timeout=30)
        result = response.json()

        if result.get('ok'):

Tainted flow: 'req' from os.environ.get (line 183, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push_daily.py (reported line 184)May include surrounding context.

python
}).encode()
        
        req = urllib.request.Request(url, data=data, method="POST")
        with urllib.request.urlopen(req, timeout=30) as response:
            result = json.loads(response.read().decode())
            if result.get("ok"):
                logger.info("Telegram推送成功")

Tainted flow: 'token_req' from os.environ.get (line 223, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push_daily.py (reported line 224)May include surrounding context.

python
}).encode()
        
        token_req = urllib.request.Request(token_url, data=token_data, method="POST")
        with urllib.request.urlopen(token_req, timeout=30) as token_response:
            token_result = json.loads(token_response.read().decode())
            if not token_result.get("code") == 0:
                logger.error(f"飞书认证失败: {token_result.get('msg')}")

Tainted flow: 'msg_req' from os.environ.get (line 239, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/push_daily.py (reported line 249)May include surrounding context.

python
}
        )
        
        with urllib.request.urlopen(msg_req, timeout=30) as msg_response:
            msg_result = json.loads(msg_response.read().decode())
            if msg_result.get("code") == 0:
                logger.info("飞书推送成功")

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

描述强调的是一个完整的“每日毛选语录硬核推送”能力集合,包括 AI 深度解读、配图、语音,以及通过 Obsidian 和 Telegram 进行多渠道推送。而代码片段的实际职责更窄:它是一个“深度解读生成模块”,负责向 DeepSeek API 发送提示词、获取生成内容、按六章结构解析,并格式化为文档字符串和 Telegram 消息字符串。代码并没有展示图片生成、语音合成、文件写入 Obsidian 仓库、或向 Telegram API 发送消息等关键行为。另一个明显差异是,代码确实具备外部网络调用能力(访问 DeepSeek API),但声明权限为空。虽然部分描述内容(硬核解读、六章结构、拒绝鸡汤、直击本质)与代码高度一致,但整体技能描述覆盖了更多未在此代码中实现的核心功能,因此应判定为描述与代码行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

该代码块与“每日毛选语录 + AI 深度解读 + Telegram 推送”的核心用途基本一致:会获取当日语录、调用 AI 生成深度内容、生成文档并通过 Telegram 发送消息。但描述中强调的若干能力在此代码中没有体现,尤其是“配图”“语音”以及“Obsidian+Telegram 多渠道推送”。当前代码只实现了文本内容生成、本地文件保存和 Telegram 文本消息发送。从审计标准看,这属于描述包含了该代码块未展示的重要能力,因此应判定为存在描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该描述与此代码片段存在明显不一致。代码的核心功能是“读取已生成文档并推送消息”,而不是生成“AI深度解读”内容本身。它只从 Markdown 中抽取若干段落,并截断分析内容后发送。与此同时,代码具备实际的外部网络通信能力:调用 Telegram Bot API 和飞书开放平台发送消息,但声明的 permissions 为空,且描述只明确提到 Telegram/Obsidian,没有清楚声明飞书渠道。描述中强调的六章结构、2000+字硬核解读、阶级分析等内容在此代码里没有实现,因此若将整个技能描述套到这段代码上,会夸大/偏移其主要行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

从该代码块看,实际功能是基础工具支持,而不是描述中的完整技能能力。它会读取本地 JSON 配置与语录数据,选取一条语录,生成一个明确标注为“AI生成失败时的回退方案/简单模式”的文档和 Telegram 消息模板,并把 Markdown 保存到本地目录。虽然配置中出现 voice_enabled、channels、template_file,且输出目录指向 Obsidian 路径,也有 Telegram 消息格式化函数,但这些都只是占位或辅助,当前代码并未执行语音生成、图片生成、消息发送或 AI 深度解读。故描述明显高于代码实际行为,属于描述与实现不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README presents the skill entirely in Chinese and describes fixed Chinese-language content generation and delivery, but does not indicate that language is configurable or optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises automatic generation and delivery of content to local storage and Telegram, but it does not clearly warn that the skill will write files and transmit generated content to external services once configured. In an agent/automation context, missing disclosure can cause users to enable unattended behavior without realizing the privacy and integrity implications of outbound messaging and filesystem writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cron example documents fully unattended daily execution and push behavior, but there is no explicit caution that the task will run automatically every day and continue sending/writing content until disabled. In practice, this can lead to persistent unwanted transmissions, spam to Telegram chats, and silent accumulation of files in user-managed directories.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares required binaries and environment variables but does not define an explicit permission/tool scope despite clearly describing capabilities that involve file writes, network access, environment secret use, shell/cron automation, and local path access. This is dangerous because users and orchestration systems cannot accurately constrain what the skill may do, increasing the chance of unintended secret access, network exfiltration, or filesystem modification beyond user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description explicitly frames the skill as performing a 'forced cognitive reboot' and later requires a specific ideological analysis method as the default output style. This imposes a particular worldview/tone on generated content without describing user choice or opt-in, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill text does not prominently warn users that it writes to a fixed local path and may automatically push content to Telegram on a schedule. This is dangerous because silent local writes and unattended outbound messaging can surprise users, expose sensitive workspace structure, overwrite expected locations, or cause unintended automated publication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON configuration hard-codes Chinese-language paths and content/style values such as "每日语录" and "写实摄影风格,高清,有深度", indicating the skill is configured for a specific language/locale. Under the policy, locale-specific behavior should offer user choice or include a clear justification; neither is present in this file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest positions the skill as delivering '每日毛选语录' with Mao-selected quotations, but this data file contains '不管黑猫白猫,能抓老鼠的就是好猫。' attributed to 邓小平 rather than 毛泽东. If used by the skill, the actual delivered content would not consistently match the declared Mao-quote purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template presents all user-facing headings and prompts exclusively in Chinese, such as the title and section labels. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and prompt schema are written to generate output specifically in Chinese, and the skill does not present any opt-in or configurable language selection. This is a natural-language locale constraint that may violate policy when imposed without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function sends quote text, source, and date to a third-party API without any consent gate, disclosure, or data classification check. In this skill, content may seem low sensitivity, but the implementation is generic and could forward unpublished, private, or regulated material to an external processor, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring, function descriptions, log messages, and CLI description are all written in Chinese, which establishes a fixed language experience for users. The file does not indicate that Chinese is optional or that the skill is intentionally region- or locale-specific, so this appears to violate the language/locale choice policy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/generate_daily.py (reported line 47)May include surrounding context.

python
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False

        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/push_daily.py (reported line 175)May include surrounding context.

python
logging.warning("未配置 Telegram BOT_TOKEN 或 CHAT_ID")
            return False

        url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
        data = {
            'chat_id': chat_id,
            'text': message,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script presents all user-facing output in Chinese and instructs users to create a cron task with a Chinese task string, without offering any language or locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.