Back to skill

Security audit

Last 30 Days—CN版

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent China social-media research purpose, but it gives the agent broad automatic behavior and opens generated HTML reports that are built unsafely from untrusted data.

Review before installing. Use it only for intentional China social-media research, avoid sensitive internal names or confidential topics unless you are comfortable sending them to redfox.hk, and do not let it automatically open generated HTML reports until the HTML escaping and link validation issues are fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
references/output-rules.md:3
Finding

Mandatory promotional instructions hijack the agent's final response

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cn_last30days.py:614
Finding

Generated HTML permits active-content injection through unescaped keywords and URL attributes

Content
View full analysis
str: """行内 Markdown 转换:粗体、链接""" import re text = text.replace("&", "&").replace("<", "<").replace(">", ">") # [text](url) text = re.sub(r'\[([^\]]+)\]\(([^)]+)\)', r'\1', text) # **bold** text = re.sub(r'\*\*(.+?)\*\*', r'\1', text) return text ``` The user-controlled keyword is copied without HTML encoding: ```python def format_as_html(data: dict, max_items: int = 50, report_html: str = "") -> str: """生成网站风格 HTML 报告""" keyword = data["keyword"] total = data["total_items"] date_range = data["date_range"] ``` Remote API or local JSON URL values are inserted directly into `href` attributes: ```python for idx, item in enumerate(items): title_escaped = item["title"].replace("&", "&").replace("<", "<").replace(">", ">").replace('"', """) desc_escaped = item["desc"][:200].replace("&", "&").replace("<", "<").replace(">", ">") if item.get("desc") else "" author_escaped = item["author"].replace("&", "&").replace("<", "<").replace(">", ">") item_url = item.get("url", "") url_attr = 'href="' + item_url + '"' if item_url else 'href="#"' author_link = item.get("author_link", "") author_html = ('' + author_escaped + '') if author_link else ('' + author_escaped + '') ``` The unsafe attributes are then embedded in ...[truncated 5148 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Enabling implicit invocation without tight trigger constraints makes the skill available for automatic selection even when user intent is ambiguous. Because this skill is designed to analyze social-media discussions across multiple Chinese platforms, accidental invocation can lead to overbroad data gathering, incorrect assumptions about locale/platform relevance, and misrouting of user requests.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/cn_last30days.py (reported line 755)May include surrounding context.

python
</div>'
            )

        xhs_notice = (
            '<div style="background:#fff3cd;border:1px solid #ffc107;border-radius:8px;padding:10px 14px;margin-bottom:14px;color:#664d03;font-size:13px;line-height:1.6">'
            '⚠️ 受小红书风控规则限制,部分作品链接可能无法正常跳转,您可复制对应作品标题前往小红书搜索查看,感谢理解🙇‍♀️🙇‍♀️'
            '</div>'
        ) if pkey == "xhs" else ""
        no_data_html = "<div class='no-data-hint'><p>未查询到相关内容,建议更换关键词重试。</p></div>" if not items else ""
        panels_html += (
            '\n        <div class="tab-panel" id="panel-' + pkey + '" style="display: ' + display + '">\n'
            '            ' + error_html + '\n'
            '            ' + xhs_notice + '\n'
            '            <div class="card-list">\n'
            '                ' + cards + '\n'
            '            </div>\n'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The README says the skill automatically runs WebSearch before calling the engine and automatically merges and interprets results. Autonomous external actions increase the chance of unreviewed query expansion, unintended data sharing, and opaque decision-making that users may not realize is happening before information is sent out.

Content

Scanner excerpt · README.en.md (reported line 36)May include surrounding context.

md
### Highlights

- **Pre-research mechanism**: Automatically runs WebSearch to extract trending terms before calling the engine, optimizing query strategy.
- **Smart merging**: Automatically merges related keywords into a single call to reduce API invocations.
- **Signal interpretation**: Automatic interpretation of key metrics like Xiaohongshu save/like ratio, Douyin share count, and WeChat read count.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly states the skill ships with a built-in free public API key while also warning not to hard-code or expose keys. A bundled shared credential creates clear risk of secret exposure, abuse by third parties, quota exhaustion, and use of a common identity across users, which can also enable traffic attribution or service disruption.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation guidance is extremely broad, telling users they can simply describe topics in natural language with no fixed commands. In an agent environment, loose trigger boundaries can cause over-invocation, unintended external searches, and accidental transmission of sensitive or irrelevant user content to third-party services.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says users can 'directly use natural language' without fixed commands and provides example phrases like '帮我研究一下…' and '对比一下…', which overlap with common everyday requests. It does not define clear activation boundaries, exclusions, or negative examples, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to automatically open a generated HTML file after analysis, which is not necessary to fulfill the tool's research purpose. Auto-opening local HTML can trigger browser execution of embedded active content or unexpected external requests, and it removes user control over a side effect that goes beyond generating a report.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs automatic HTML generation and opening without warning or confirmation, creating an unnecessary action chain after the main task completes. In an agent context, removing confirmation for browser-launching behavior increases the risk of surprising file execution, privacy leaks through external resource loading, and reduced operator oversight.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, description, and default prompt are entirely in Chinese and direct analysis of Chinese social media content, but the manifest does not offer a language or locale opt-in choice. This can violate language/locale policy when a skill implicitly assumes a specific language without explicit user selection or documented regional justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt is broad enough that the skill could be selected for generic research or trend-analysis requests without a clear user request for this specific China social-media workflow. In combination with implicit invocation, this increases the chance of unintended routing, causing the agent to apply platform-specific assumptions or collect/analyze content the user did not explicitly ask for.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template mandates a Chinese-language badge and, throughout the document, requires output in Chinese formatting and headings. This is a natural-language policy concern because it enforces a specific language/locale rather than offering a user-selectable option or documenting a justified regional-only scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a social-media topic research tool for searching and comparing discussion trends across platforms. While network access is expected, automatically reading secrets from process environment variables and ~/.qoder/apis/redfox.json goes beyond the user-facing research purpose and introduces credential-access behavior not disclosed in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends user-supplied keywords and source metadata to a third-party service without any user-facing privacy notice or consent mechanism. If users input sensitive business topics, incident terms, client names, or internal project identifiers, those terms are disclosed externally and may be logged by the remote provider.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest emphasizes searching recent discussions and cross-platform analysis, but the implementation persistently writes output files under ~/Downloads/CnLast30Days unless configured otherwise. Local file creation is not merely incidental logging here; it is a default side effect that materially expands behavior beyond the described search/analysis function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The file brands the skill as 'China Social Media Topic Research' and immediately frames outputs around Chinese platforms and a China-focused research context. While the domain is region-specific, the README does not explicitly state that this locale specialization is intentional or that users are opting into a China-only analysis scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames the skill as an on-demand social media research and cross-platform analysis tool. L94 adds a persistent 'subscribe once and receive automatic updates' capability, which implies scheduled monitoring or push delivery beyond the described research use case and is not otherwise declared in the manifest context provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

All user-facing instructions and examples are in Chinese, and the document does not state that Chinese is optional or required for a justified region-specific reason. This can constitute a language/locale policy issue because it effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documentation minimizes side effects by saying the JSON-to-HTML step does not write Markdown, while the command still writes an HTML artifact to disk and then opens it. This is a real transparency and safety issue because it can mislead the operator about filesystem changes and downstream execution in a browser.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The output document is hardcoded with lang="zh-CN", and the tool's strings are entirely fixed to Chinese. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.