Back to skill

Security audit

Jina Web Fetcher - 网页抓取

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Jina AI web-fetching helper; users should know that requested URLs and search terms go through a third-party service.

Install only if you are comfortable sending requested URLs, search terms, and retrieved public page content to Jina AI. Do not use it for private intranet links, authenticated pages, confidential documents, regulated data, or URLs containing secrets or sensitive query parameters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill routes arbitrary target URLs through the third-party service r.jina.ai but does not warn users that both the requested URL and the fetched content are disclosed to that external provider. This creates a real privacy and data-handling risk, especially if users pass internal links, sensitive query terms, or proprietary pages, because the skill explicitly encourages fetching arbitrary URLs and Google searches through a proxy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing descriptive content in the skill file is written in Chinese, but the file does not indicate that the skill is intended only for a Chinese-speaking audience or provide an opt-in language choice. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.