Back to skill

Security audit

Omni News

Security checks for vulnerabilities and agentic risk

Overview

This news skill mostly aggregates public feeds, but it should be reviewed because it mixes removed monitoring and push features with active-looking persistence, cron, and optional long-running service instructions.

Install only if you are comfortable with broad public-source fetching and local news archives. Do not enable push channels, cron schedules, X/Twitter cookies, Playwright deep fetching, or Docker self-hosting unless you explicitly want those behaviors and can review the configuration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 978)May include surrounding context.

4B: HTML(邮件/分享场景)

html
<!-- Omni News HTML邮件模板,参考自cclank开源项目 -->
<div style="max-width:600px;margin:0 auto;font-family:-apple-system,sans-serif">
  <h1 style="color:#1a1a1a;border-bottom:3px solid #0066cc;padding-bottom:10px">
    📰 Omni News 日报

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 978)May include surrounding context.

4B: HTML(邮件/分享场景)

html
<!-- Omni News HTML邮件模板,参考自cclank开源项目 -->
<div style="max-width:600px;margin:0 auto;font-family:-apple-system,sans-serif">
  <h1 style="color:#1a1a1a;border-bottom:3px solid #0066cc;padding-bottom:10px">
    📰 Omni News 日报

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The architecture section explicitly states the sentiment layer is '中文情感分析', and elsewhere the skill consistently specifies Chinese-only sentiment tooling and Chinese-oriented output without offering a language choice. This creates a natural-language locale policy issue because users seeking multilingual or English news handling are not given an opt-in or alternative.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims push/monitoring behavior was removed, but later sections still describe push rules, personalized tracking, and monitoring as active capabilities. This kind of contradictory documentation is dangerous because operators or downstream agents may enable data collection, retention, or outbound notifications that users were told were disabled, creating privacy and scope-creep risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Although the file says TrendRadar was removed, substantial later content still presents TrendRadar-derived tracking, report generation, monitoring, and smart push features as integrated behavior. In a skill document, this discrepancy can mislead an agent into performing persistent surveillance-style actions or retaining topic profiles beyond the user's expectation, which increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.