Back to skill

Security audit

techflow-news

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple TechFlow news summarizer that fetches one disclosed public website and formats same-day articles, with no hidden execution, persistence, or credential access found.

Install this if you want an agent to fetch and summarize today’s public TechFlow Chinese news. Be aware that generic Chinese requests about today’s news may invoke it, and the agent will read external webpage content from the disclosed TechFlow URL.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 8)May include surrounding context.

md
---
AIGC:
    ContentProducer: Minimax Agent AI
    ContentPropagator: Minimax Agent AI
    Label: AIGC
    ProduceID: 01f20fdb168c2f299d6c44ef27d2969b
    PropagateID: 01f20fdb168c2f299d6c44ef27d2969b
    ReservedCode1: 3046022100a6700b1c3fcbfe4f3555ae2aafbd8c751395a26c81f6d02d4dac07ff016baee8022100bbf1d29e3a658d5b7ddd8fe51ac54b5db1dcb1a60dfd82ea255c4c2da7aaa845
    ReservedCode2: 304502210093f376bdedbde740d6be80833d5db833d3e559ba8855e1e025cc6070bff1f6e6022069119f3176070fa31dd2591d3ab34830bc6291a1b69efeeb71ebfe66e59e62b7
description: 深潮TechFlow新闻聚合爬取。爬取https://www.techflowpost.com/?lang=zh-CN当天的文章,形成表格(日期、文章、主要内容、网址),并给出一段简短总结。用于用户询问"今天有什么新闻"、"汇总今天的文章"等场景。
license: MI

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description explicitly targets broad, everyday requests like '今天有什么新闻' and '汇总今天的文章', which can cause over-broad auto-invocation outside narrowly intended contexts. This increases the chance the agent fetches external content unexpectedly, expanding the attack surface for prompt injection or unintended browsing when a user asks generic news-related questions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language description hardcodes crawling https://www.techflowpost.com/?lang=zh-CN, which imposes a specific language/locale. The file does not state that this is optional, user-selected, or required for a documented region-specific purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.