Back to skill

Security audit

military-news-collector

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese-language military news aggregation skill that searches public news sources and does not request local, persistent, credential, or code-execution access.

Install this only if you want Chinese-language military news roundups. Expect the agent to perform multiple public web searches and fetch news pages; no local data or credentials are requested by the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger description is broad enough to activate on general questions about current events or geopolitics, not just narrowly scoped military-news requests. That can cause the skill to overtake user intent, perform unnecessary browsing, and surface sensitive conflict-related content when the user did not clearly ask for this specialized workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates Chinese output regardless of the user's language preference, which can override user intent and reduce transparency or usability for non-Chinese-speaking users. While this is not a code-execution or data-exfiltration issue, it is still a behavioral safety problem because it forces an output mode the user may not understand.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely written in Chinese and presents the resource list and search guidance only in that language. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.