Back to skill

Security audit

ai-topic-scout-feishu

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Feishu workflow for collecting public YouTube/X content, analyzing it, and storing results, with disclosed integration risks but no evidence of deception or harmful behavior.

Before installing, use a dedicated environment, avoid sudo where possible, pin or review yt-dlp versions, and review the Feishu OAuth permissions. Treat configured channel names, usernames, fetched posts, generated analysis, and Feishu records as data that may pass through YouTube, Nitter mirrors, the configured LLM provider, web search, and Feishu. Enable cron only after confirming the target table and data sources are correct.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:11
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

系统工具 (可选)

macOS: brew install curl jq

Linux: sudo apt install curl jq

text

### 2. 配置数据源

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README says the system will use AI to analyze scraped YouTube and Twitter content, but it does not clearly warn users that third-party platform content may be transmitted to an external LLM service. This creates a real transparency and data-handling risk because users may unknowingly send content, metadata, or derived records to an external processor with different retention, logging, or compliance characteristics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description does not clearly disclose that fetched YouTube/Twitter content and derived analysis may be sent to third-party services, including LLM APIs and possibly public scraping endpoints like nitter.net. This creates privacy, compliance, and data-governance risk because users may not realize external services will receive collected content and metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description does not clearly disclose that fetched YouTube/Twitter content and derived analysis may be sent to third-party services, including LLM APIs and possibly public scraping endpoints like nitter.net. This creates privacy, compliance, and data-governance risk because users may not realize external services will receive collected content and metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases are short and broad, such as '抓取选题' and '分析选题', without requiring confirmation, namespace prefixes, or explicit target scope. This increases the chance of accidental activation in normal conversation, which could cause unintended scraping, analysis runs, and writes to Feishu tables.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill declares a generic exec dependency to run tools like yt-dlp, which introduces command-execution capability beyond narrowly scoped Feishu/topic-analysis operations. If user-controlled source values or future prompt flows are passed into shell commands without strict allowlisting, this can enable arbitrary command execution, SSRF, local file access, or abuse of the agent runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest uses a Chinese-only description and Chinese trigger phrases, with no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking or China-specific environment. This creates a natural-language policy concern because the skill appears to require a specific language/locale by default.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest declares a generic exec capability even though the skill’s stated purpose is topic discovery, web search, and Feishu Bitable updates. Generic command execution greatly expands the attack surface because any prompt-influenced workflow or downstream instruction could invoke arbitrary local commands, enabling data exfiltration, filesystem access, or execution of untrusted binaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script silently contacts third-party Nitter instances and sends the requested username and client metadata without any user-facing disclosure or consent step. In an agent skill context, undisclosed network egress can leak user interests or targets of investigation to external services, which is a real privacy and trust issue even if it is not a code-execution bug.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script launches an external subprocess to perform the fetch, but the runtime path provides no warning, prompt, or explanatory output that a shell utility will be invoked. For safety auditing, subprocess execution should be disclosed unless it is clearly surfaced to the user through logs, prompts, or surrounding documentation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_twitter.py (reported line 41)May include surrounding context.

python
url = f"https://{instance}/{username}"
            
            # 使用 curl 抓取 HTML
            result = subprocess.run(
                ["curl", "-sL", "-A", "Mozilla/5.0", url],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_youtube.py (reported line 39)May include surrounding context.

python
]
    
    try:
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README describes automatic creation of Feishu tables and automatic writing of scraped/analyzed data, but it does not provide a prominent warning about the scope of writes, persistence of collected content, or the possibility of overwriting/replicating data into a shared workspace. In an automation skill that stores external content, lack of clear disclosure can lead to unintended data exposure or governance issues, especially in team-owned Feishu environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This YAML file’s human-readable instructions, section headers, and inline comments are presented entirely in Chinese, which imposes a specific language choice on users. Under the policy, language constraints should either offer a user choice or be clearly documented as region-specific and justified; neither is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file-level description and function docstrings are written in Chinese, which imposes a specific language for user-facing instructions and developer guidance. The file does not offer an opt-in language choice or explain that the tool is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.