Back to skill

Security audit

每日简报生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates Chinese daily news briefings from public sources, with disclosed network fetching and local Markdown output, but users should treat fetched news text as untrusted.

Install only if you want a Chinese daily briefing tool that fetches public web content. Review generated briefings as untrusted news data, verify important stories at the source, and be cautious opening or clicking links because remote article fields are not escaped or URL-validated.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/fetch_news.py:263
Finding

Untrusted News Content Can Cause Indirect Prompt Injection

Content
View full analysis
{}".format(summary)) ``` ### Technical Analysis Article titles and summaries originate from external websites, RSS publishers, and story submitters. Removing HTML tags does not neutralize natural-language instructions. The retrieved content is copied into terminal output and the generated Markdown briefing without explicit trust-boundary markers or an instruction requiring the consuming agent to treat it only as untrusted data. If the generated report is subsequently interpreted by an AI agent, an attacker-controlled title or summary could contain instructions such as requests to ignore the briefing task, disclose contextual information, or invoke available tools. This is an indirect prompt-injection condition: the mal ...[truncated 1543 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_news.py:263
Finding

Unsanitized Remote Fields Permit Markdown Content Injection

Content
View full analysis
{}".format(summary)) ``` ### Technical Analysis The report generator interpolates externally supplied titles, URLs, and summaries directly into Markdown. It does not escape Markdown control characters and does not validate the URL scheme. Truncating a string does not make it safe. An attacker can use characters such as brackets, parentheses, newlines, and image syntax to escape the intended link or blockquote structure. Depending on the Markdown renderer, a crafted value could inject additional links, images, headings, or deceptive formatting. A renderer that automatically loads remote images could also expose the viewer's IP address and request metadata to an attacker-controlled server. The URL is accepted from remote API or RSS data without restricting it to expected `https` or `http` schemes. Whether non-HTTP schemes become actionable depends on the Markdown viewer and its security controls. ### Attack Path 1. An attacker controls or influences an article title, link, or RSS summary returned by a configured source. 2. The attacker embeds Markdown delimiters, a deceptive destination, an image reference, or an unexpected URL scheme in the field. 3. The script retrieves the field and passes it to `generate_report`. 4. The field is inserted directly into the Markdown link or blockquote. 5. A user opens the generated file in a Markdown renderer. 6. The renderer displays attacker-controlled formatting or links and may load remote resources if such loading is enabled. ### Impact Assessment This issue affects the integrit ...[truncated 541 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to perform network access via curl/fetch and explicitly references running a local script, but it does not declare any corresponding tool scope or permissions. This creates a permission-transparency gap: the agent may fetch external content or write files through undeclared capabilities, increasing the chance of unintended data access, unexpected side effects, or bypass of operator expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description explicitly states that it generates structured Chinese briefings, and later instructions prefer Chinese sources and show only Chinese output. There is no opt-in, fallback, or explanation that this is a region-specific skill, which makes it a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases like '给我今天的简报' and similar natural requests are broad enough to overlap with ordinary conversation, making accidental or silent invocation more likely. In this skill's context, accidental activation can lead to unsolicited network requests and external content retrieval, which is more sensitive than a purely local formatting skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language documentation stating the skill is a Chinese daily briefing generator, and the CLI description and runtime messages are also exclusively in Chinese. Under the policy rule, forcing a specific language without offering a user language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generated report title, section labels, footer, argparse description, and status messages are all hardcoded in Chinese, with no indication that users can choose another language. Because this is a general news-fetching utility rather than a clearly justified region-specific compliance tool, the file presents a language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.