Back to skill

Security audit

news-daily-report

Security checks for vulnerabilities and agentic risk

Overview

This daily news skill mostly matches its stated purpose, but it requires using profile or memory data for personalization, stores inferred traits in a local file, and generates HTML from untrusted news data without escaping.

Review this skill before installing. Use it only if you are comfortable with Chinese-language news output, a fixed external news API, local report files, and memory-based personalization. Avoid letting it use long-term memory or profile data unless the user explicitly consents, and treat generated HTML as untrusted unless the news fields are escaped and URLs are validated.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_h5_report.py:90
Finding

Stored HTML Injection Through Untrusted News Data

Content
View full analysis
' + news['title'] + '\n' if news.get('picture'): html_content += ' News image\n' html_content += '
' + news['abstract'] + '
\n' html_content += '
\n' html_content += ' ' + news['source'] + '\n' html_content += ' Read more →\n' html_content += '
\n' ``` The displayed English text in this excerpt is a translation of the corresponding user-interface literals; the vulnerable concatenation operations are unchanged. ### Technical Analysis The generator directly concatenates the externally supplied `title`, `picture`, `abstract`, `source`, and `url` fields into HTML. It does not apply context-sensitive HTML escaping or validate URL schemes. The data originates from the remote news API and is persisted in `data/daily_report.json`. Consequently, the application crosses a trust boundary when it treats those fields as safe markup. Possible payload classes include: - A title or abstract containing an HTML element with an event handler. - A picture value containing a quotation mark that terminates the `src` attribute and injects another attribute. - A URL using a dangerous scheme such as `javascript:`. - Markup that creates deceptive forms, overlays, or redirects within the generated report. The report also lacks a restrictive Content Security Policy that could provide defense in depth. ### Attack Path 1. An attacker compromises, controls, or otherwise influences a response returned by the conf ...[truncated 1191 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:22
Finding

Unnecessary Agent-Memory Profiling and Persistent Storage of Inferred Interests

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

声明描述的是一个可获取个性化每日日报的能力,强调用户兴趣偏好、查询关键词排序,以及生成 H5 页面。但实际代码只包含一个简单的数据拉取脚本:请求固定接口、读取 JSON 响应并保存到本地文件。代码中没有任何用户输入处理、排序逻辑、个性化参数、身份信息传递或 H5 生成流程。虽然注释中提到了自动生成 H5 页面,但相关代码已被注释掉,不能算实际行为。因此,代码实际功能只是“抓取并保存新闻推荐数据”,与声明的完整能力存在明显不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes network access plus file read/write behavior but does not declare any explicit tool scope or permissions boundary. That increases the chance of overbroad execution in hosts that rely on metadata for least-privilege enforcement, especially because the workflow includes local file creation/deletion and outbound API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs use of user profile/memory together with API-driven personalization, but provides no user-facing notice or consent boundary for using personal context in content generation. This can cause users' inferred interests or remembered attributes to be processed and reflected in outputs without transparency.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly require reading conversation context and memory for personalization, yet the skill provides no warning, consent flow, or minimization rule. In a conversational system, that makes it easy to over-collect or overuse retained personal data beyond the user's immediate request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the model to use conversation context, user profile, and memory to drive ranking and generated content, which creates a natural-language data leakage path. Even if the external API call is fixed, the model may echo sensitive remembered attributes into reasoning, JSON fields, or the final report.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example output explicitly includes a 'sorting_reason' that summarizes the user's profile, encouraging the model to expose remembered personal traits in a generated artifact. This is especially risky because examples often get copied verbatim into implementations and user-facing outputs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Repeatedly mandating use of user profile and memory during ranking increases the likelihood that sensitive retained context will be propagated into outputs, logs, or generated files. Repetition in instructions also makes the privacy-invasive behavior central to the workflow rather than incidental.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The operational guide instructs the model to identify interests from memory/profile context as part of normal workflow, which operationalizes use of retained user data in generated artifacts. In this skill context, the generated H5 report and intermediate JSON files make such leakage more persistent and shareable than transient chat text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON payload uses a fixed Chinese success message ("操作成功"), indicating the skill or data output is locked to a specific language. The file provides no indication that users can opt into this locale or that the skill is region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for obtaining personalized daily news recommendations, sorting by user interests and keywords, and generating an H5 daily report. This file instead contains a large static corpus of mixed general-news and tabloid-style items, including celebrity relationship sightings, entertainment gossip, and sports snippets, which does not reflect clearly personalized or recommendation-focused daily reporting behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The JSON embeds a Chinese-only sorting rationale and audience/profile text without any indication of user locale detection or opt-in, which can force output or behavior in a language the user did not request. In a personalized news skill, this can degrade usability, mislead users about personalization choices, and create accessibility or compliance issues for users expecting another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly declares lang="zh-CN", and all visible content is presented only in Simplified Chinese. For a general daily report skill artifact, this is a natural-language locale restriction with no user opt-in or explanation that the output is intentionally region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes obtaining personalized daily reports based on user interest preferences and query-keyword sorting, and generating an H5 page. In this file, the code only performs a fixed GET request to a news recommendation endpoint, saves the raw response to JSON, and does not accept user preferences, query keywords, or generate an H5 page; the H5 generation code is commented out.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs writing a new JSON file and deleting an existing one without warning the operator or user about local state changes. While the described path is limited, undisclosed file modification behavior can still surprise users and create integrity or auditability issues in shared workspaces.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest says the skill obtains personalized daily reports using user interest preferences and query-keyword sorting, then generates an H5 page. This HTML shows a broad fixed list of news across many unrelated categories with no visible indication of filtering, ranking rationale, or personalization, so the produced artifact does not clearly match the claimed personalized behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The footer states '数据来源:本地新闻推荐 API', which implies the report's source is a local recommendation API. However, the document directly references numerous externally hosted images and article URLs from Sina, 163, and other sites throughout the page, so the documentation-style attribution is misleading about where the displayed content is actually sourced from.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The generated HTML and user-facing strings are fixed to Chinese, including lang="zh-CN", Chinese date formatting, and Chinese labels/text. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The inline comment says '发送 POST 请求' (send POST request), but the next line calls requests.get(). This is an active contradiction between documentation and behavior, not merely missing detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.