Back to skill

Security audit

personalized-news-collector

Security checks for vulnerabilities and agentic risk

Overview

This news skill is not clearly malicious, but it should be reviewed because it can infer interests from chat history and fetch arbitrary web pages without clear consent or limits.

Install only if you are comfortable with the agent using prior conversation or memory to infer news interests and making outbound requests to news or other selected sites. A safer version should ask before using history, confirm inferred interests, prefer the reviewed source list, and restrict external fetching to trusted HTTPS news domains with redirect and size limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Warning
Location
SKILL.md:13
Finding

Unconsented Profiling of User Interests from Conversation History

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–14
Vulnerability Type: other: Sensitive Conversation-History Profiling
Risk Level: Medium

Vulnerable Code Snippet:

markdown
### 1. Analyze Interests
All the news conllected news should match user's interests. User's interests can be summarized from recent memory and conversation history. At least **three** main interests should be offered.

Technical Analysis

The skill directs the agent to infer a user's interests from recent memory and conversation history. This processing is not limited to information supplied in the current request, and the instructions neither require consent nor establish boundaries concerning which historical data may be inspected.

Requiring at least three inferred interests may encourage the agent to derive additional categories even when the current interaction provides insufficient context. Historical conversations can contain private, sensitive, or context-specific information that the user did not intend to reuse for news personalization.

The skill does not explicitly require transmitting conversation history to external news sources. The primary risk is unauthorized contextual profiling and disclosure of inferred interests in the generated response.

Attack Path

  1. A user invokes the personalized news skill without explicitly specifying topics.
  2. The skill instructs the agent to inspect recent memory and conversation history.
  3. The agent extracts or infers at least three interests, potentially including sensitive subjects from unrelated prior conversations.
  4. The agent uses those inferred interests to select news and includes the interest categories in its output.
  5. Anyone able to view the response may learn private interests or prior conversational themes that the user did not intend to disclose.

Impact Assessment

The issue does not grant operating-system privileges, execute code, or directly expose credentials. Its scope is ...[truncated 357 chars]

Remediation
View remediation

Remediation Suggestions

  • Use interests explicitly supplied in the current request by default.
  • Obtain affirmative user consent before accessing conversation history or persistent memory.
  • Present inferred interests to the user for confirmation before retrieving news.
  • Inspect only the minimum relevant context and avoid deriving sensitive categories such as health, religion, politics, finances, or sexuality unless explicitly requested.
  • Do not include inferred personal attributes in output unless necessary and approved by the user.
  • Define clear retention, disclosure, and context-isolation rules for information derived from conversation history.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:19
Finding

Unrestricted External URL Retrieval with Redirect Following

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–24
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code Snippet:

markdown
### 2. Collect News

Get news concerning user's interests. You should collect as much as Information from different sources. You can use the command like:
 
``curl -sL `the url of informtion source` ``

You can use the URLs offered at  `sources.md` as your news sources, but some of them may not be available and they should not be your only choices. You are supported to collect Information from more sources, especially when user's interests are not included in `sources.md`.

Technical Analysis

The skill authorizes the agent to retrieve arbitrary information-source URLs through curl -sL. The -L option follows redirects, while the instructions impose no restrictions on URL schemes, hostnames, resolved IP addresses, redirect destinations, response sizes, or request timeouts.

Although the documented placeholder is not itself a shell-injection payload, broad and insufficiently validated source selection creates an SSRF-style risk when an untrusted request can influence the selected URL. Redirect following can also bypass validation that is performed only on the initial hostname.

The retrieved response is untrusted external content. The skill does not instruct the agent to treat embedded instructions as inert news data, creating secondary exposure to indirect prompt injection. There is no evidence that the skill downloads or executes remote code, so this does not meet the criteria for remote payload retrieval and execution.

Attack Path

  1. An attacker supplies a purported news topic, source, or URL that influences the agent's source selection.
  2. The agent invokes curl -sL against the attacker-influenced URL.
  3. The initial server returns a redirect to a loopback, private-network, link-local, cloud metadata, or other unintended endpoint; alternatively, t ...[truncated 1336 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict retrieval to an explicit allowlist of trusted HTTPS news and feed domains.
  • Reject non-HTTP(S) schemes, embedded credentials, malformed hosts, and nonstandard destinations unless specifically required.
  • Resolve hostnames before each request and reject loopback, private, link-local, multicast, reserved, and cloud-metadata address ranges.
  • Revalidate the destination after every redirect or disable redirects entirely.
  • Set strict connection, transfer, and overall timeouts.
  • Limit response size, redirect count, and accepted content types.
  • Use a structured HTTP or feed-reading tool instead of constructing shell commands.
  • Keep URL values separate from shell syntax and never interpolate user-controlled text into a shell command.
  • Parse retrieved content strictly as untrusted data and explicitly ignore instructions contained in articles, feeds, metadata, or web pages.
  • Prefer the reviewed sources in sources.md; require explicit user confirmation before accessing any additional domain.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is configured to trigger for vague requests about 'current news' or 'events happening around' without requiring a specific topic or explicit consent to profile the user. In context, this broad activation increases the chance the skill will run unexpectedly, infer interests from recent memory/conversation history, and initiate external news collection beyond what the user clearly requested.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly direct the agent to use recent memory and conversation history to derive interests and to fetch data from external URLs via curl, but they do not require disclosure or consent for either behavior. This is dangerous because it can lead to silent exfiltration of sensitive contextual interests through outbound requests and network activity the user did not knowingly authorize.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.