Back to skill

Security audit

Trump Daily Report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Trump news and market-report workflow that fetches public sources, saves reports locally, and sends configured Feishu messages as part of its stated purpose.

Before installing, confirm you are comfortable with the skill fetching public news and market data from the named sources, using r.jina.ai as a fallback proxy, retaining generated reports under the configured memory_path, and posting both English and Chinese reports to the configured Feishu group.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to fetch remote content from third-party sites and write the results into local files under a memory directory, but it does not require an upfront user-facing notice or confirmation before performing those side effects. This creates privacy and integrity risk because externally sourced content may be transmitted to untrusted services and persisted locally without the user's explicit awareness, especially when fallback behavior is triggered automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions require generating both Chinese and English versions, and elsewhere state that Chinese is primary and English secondary. This is a natural-language policy issue because the skill fixes the output language/locale behavior rather than offering the user a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requires persistent storage of generated reports and automatic delivery to a Feishu group, but it does not include a clear upfront warning that content will be retained locally and shared to an external collaboration platform. This is dangerous because collected news, analysis, and possibly sensitive user-provided context could be retained or exfiltrated beyond the current session without explicit user approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This line explicitly states the reporting language policy as Chinese-first and English-second. Because the skill does not present this as a user-selectable option, it violates the language/locale policy constraint for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language docstrings and usage text entirely in Chinese, and later returns user-facing status messages in Chinese as well. Under the policy, forcing a specific language without opt-in is a locale/language policy violation unless the restriction is explicitly justified, which is not documented here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all headings and usage guidance in Chinese only, with no indication that users may choose another language or that the language restriction is justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.