Back to skill

Security audit

公众号爆款封面生成

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core purpose is coherent, but it requires direct use of unvalidated remote image URLs and creates HTML reports from user/API data without clear escaping or URL safety controls.

Review before installing. Use this only if you trust RedFox as the data/API provider, can revoke the REDFOX_API_KEY, and are comfortable with the agent fetching API-returned image URLs and writing a local HTML report. Prefer running it in a network-restricted environment and opening generated HTML cautiously until URL validation and HTML escaping are added.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:84
Finding

Unvalidated Remote Image URLs Enable Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/report_template.md:21
Finding

Unescaped User and API Data Can Be Injected into Generated HTML Reports

Content
View full analysis
爆款封面分析报告 - {关键词}主题 ``` ```html
关键词:{关键词} | 数据来源:公众号爆款雷达接口 | 分析数量:{分析数量}张封面
``` ```html 封面示例 ``` ```html 封面图
作者:{作者名}
``` ### Technical Analysis The mandatory report template inserts values from two untrusted sources directly into HTML: - User-controlled keywords - Remote API fields, including `coverUrl`, `oriUrl`, article titles, and author names The Skill does not require contextual HTML escaping or URL validation before these values are inserted. Text-node values can therefore inject markup, while attribute values containing quotation marks can terminate an existing attribute and introduce new attributes or elements. The `href` placeholders also accept arbitrary URL schemes ...[truncated 1878 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:53
Finding

Unpinned Requests Dependency Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tainted flow: 'headers' from os.getenv (line 45, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/fetch_explosive_covers.py (reported line 59)May include surrounding context.

python
print(f"URL: {url}", file=sys.stderr)
                print(f"参数: {params}", file=sys.stderr)

            response = requests.get(url, params=params, headers=headers, timeout=30)

            if debug:
                print(f"状态码: {response.status_code}", file=sys.stderr)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill advertises a narrowly scoped design-analysis function, but its instructions require external API usage, credential handling, direct URL fetching, and HTML file generation that are not transparently declared in its stated behavior. This mismatch can bypass user and platform expectations, making risky operations appear as benign design assistance and reducing informed consent around data access and file creation.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/report_template.md (reported line 27)May include surrounding context.

md
<body style="font-family:-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;line-height:1.6;color:#333;background:#f5f5f5;padding:20px">
    <div style="max-width:1200px;margin:0 auto;background:#fff;border-radius:12px;padding:30px;box-shadow:0 2px 12px rgba(0,0,0,0.08)">
        
        <!-- 报告标题 -->
        <h1 style="color:#1a1a1a;margin-bottom:30px;font-size:28px;border-bottom:3px solid #1890ff;padding-bottom:15px">📊 爆款封面分析报告</h1>
        
        <!-- 数据来源信息 -->

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README says users can 'Simply describe your niche, content topic, or cover needs in natural language — no commands to memorize,' which does not define clear activation boundaries or exclusions. This broad phrasing overlaps with ordinary design-related conversation and could cause unintended invocation because there are no negative examples or explicit trigger constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill invites activation via unconstrained natural-language requests such as '直接用自然语言说出你的赛道、内容主题或封面需求即可', which makes accidental or ambiguous invocation more likely. In an agent environment, broad triggers can cause the skill to run in contexts the user did not clearly intend, potentially sending user prompts or uploaded images to external services and consuming privileged resources like API-backed analysis/generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example phrases are generic everyday requests like '帮我设计美妆教程封面' and '参考这张图帮我设计封面', which overlap with normal conversation and can be matched too loosely by orchestrators. Because this skill can analyze user-provided content and generate outputs via an external API, overly generic triggers increase the risk of unintended invocation, data sharing, and unnecessary tool execution.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly instructs use of environment credentials, external API access, and file writes, but declares no tool scope or permissions boundaries. In an agent environment, this creates an authorization gap where the skill may gain or assume broader capabilities than users or platform policy expect, increasing the risk of unintended network access, secret use, and filesystem modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level trigger wording is broad enough that ordinary user requests about covers, images, or article analysis could activate the skill without clear user intent to use external data sources or generate files. Over-broad activation raises the chance of surprising tool use, unintended network requests, and accidental handling of user-provided content under a more privileged workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger rule table uses ambiguous conditions like users providing themes, copy, or images, which are common across many benign conversations and could route unrelated content into this skill. In context, that matters because the workflow then performs network-backed querying, image fetching, and file output, so ambiguous routing increases the blast radius of unintended execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template sets lang="zh-CN" and all visible interaction text is fixed in Chinese, which can force a specific language/locale experience. Under SQP-3, this is a natural-language policy concern unless the skill offers a language choice or clearly documents that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file mandates '统一使用"爆款封面",禁止使用' several alternate terms, imposing a fixed wording policy regardless of user preference or context. This is a natural-language policy concern because it forces terminology choice without offering the user any language or phrasing opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs the skill to generate and save an HTML report file in the current working directory. For markdown files, SQP-2 applies when the description omits warnings about behaviors that affect user data or the local system, and there is no disclosure here that a file will be created.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.