Back to skill

Security audit

hotnews

Security checks for vulnerabilities and agentic risk

Overview

The skill’s news-fetching purpose is clear, but it authorizes an unpinned external npm CLI through npx, so the reviewed artifact does not fully define the code users may run.

Review this skill before installing in an environment with sensitive files or credentials. Prefer a pinned and verified hotnews package version, a lockfile or bundled reviewed implementation, and a restricted runtime for npm/npx execution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11–14
Vulnerability Type: Unpinned and unverifiable third-party dependency execution
Risk Level: Medium

yaml
Requires npm install.
allowed-tools:
  - Bash(hotnews *)
  - Bash(npx hotnews *)

Technical Analysis

The skill permits npx hotnews * execution but does not pin the hotnews package to an audited version or provide a lockfile, integrity hash, canonical registry location, or verified publisher identity.

When the package is unavailable locally, npx can retrieve it from the configured npm registry and execute its code. The effective implementation may therefore change after this skill has been reviewed. Package lifecycle hooks and the CLI entry point can run code with the privileges of the user operating the agent.

This creates a software supply-chain risk. A compromised publisher account, malicious package release, dependency confusion condition, registry compromise, or package ownership transfer could cause future skill invocations to execute attacker-controlled code. The repository contains only SKILL.md, so the behavior of the external package could not be verified within the audited artifact.

Attack Path

  1. An attacker compromises the hotnews package, one of its transitive dependencies, or the package publisher account.
  2. The attacker publishes a malicious package version to the registry resolved by npm.
  3. The agent loads this skill and invokes an allowed command such as npx hotnews baidu.
  4. Because no exact version or integrity value is specified, npx resolves and downloads the malicious release.
  5. Package installation hooks or the CLI entry point execute attacker-controlled code locally.
  6. The payload operates with the agent process's user privileges and can access resources available in that execution environment.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running th ...[truncated 774 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the package to an exact, reviewed version rather than resolving the latest release, for example by using an explicitly verified version such as hotnews@X.Y.Z.
  2. Document and verify the canonical package name, registry URL, publisher, and source repository to reduce typosquatting and dependency-confusion risks.
  3. Add a lockfile containing package integrity metadata and enforce deterministic installation with npm ci.
  4. Verify the package tarball and dependency integrity before execution. Consider signature or provenance verification where supported.
  5. Disable npm lifecycle scripts with --ignore-scripts where the package can operate without them.
  6. Prefer bundling reviewed source code in the skill package so the executed implementation is included in the audit scope.
  7. Run the tool in a restricted environment with minimal filesystem access, no unnecessary credentials, limited outbound networking, and no elevated privileges.
  8. Periodically re-audit the pinned package and its transitive dependencies before upgrading them.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The manifest allows Bash(npx hotnews *) without a pinned version, which means the agent may execute an unpinned package directly from the registry. In an agent/tooling context this is especially risky because it turns a documentation-level issue into an executable supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx hotnews without pinning an exact package version allows whatever version is current at execution time to be fetched and run. That creates a supply-chain risk: a malicious update, dependency compromise, or typosquat could result in arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes fetching trending news from Chinese platforms and GitHub, which necessarily involves outbound network access, but it does not explicitly warn users about that behavior. Under the markdown-specific warning criterion, behaviors affecting privacy or system/network activity should be disclosed when describing the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description emphasizes Chinese platforms and trending sources but does not provide any opt-in language or locale choice. Because locale-related constraints should be explicitly justified or user-selectable, this can be interpreted as a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation states under 'Recommended Sources' that toutiao is a valid source, but the manifest and source list only declare 8 endpoints and do not include toutiao. This is an active documentation-to-capability contradiction rather than a mere omission, because it instructs users to use a source the skill does not claim to support.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.