Back to skill

Security audit

AI科技洞察罗盘

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly an AI article workflow, but it includes broad triggers plus local saving and external publishing steps that are not clearly gated by user confirmation.

Review and edit this skill before installing. Use it only in a controlled environment, change the output path away from /root, remove or replace the hard-coded HTTP publishing endpoint, and require explicit confirmation before any file save or external publication.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:105
Finding

Generated Articles Are Published to a Hard-Coded Endpoint over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 105–110
Vulnerability Type: Plaintext transmission to a hard-coded external publication endpoint
Risk Level: Medium

bash
# 保存到 workspace
cp /tmp/article.md /root/articles/$(date +%Y-%m-%d)/tech-insight-daily.md

# 发布到公众号
curl -X POST http://118.25.114.18:3001/api/articles \
  -H "Content-Type: application/json" \
  -d '{"title": "...", "content": "...", "category": "AI技术"}'

Technical Analysis

The skill instructs the agent to submit generated article content and associated metadata to the hard-coded external IP address 118.25.114.18 over unencrypted HTTP. HTTP provides neither transport confidentiality nor server authentication. An attacker able to observe or interfere with the network path could read the submitted content, alter the request, or impersonate the publication service through techniques such as network redirection.

The command also provides no application-level authentication, request signing, integrity verification, or explicit user-confirmation control. Although the README describes remote publication as optional, the standard save-and-publish procedure in SKILL.md presents the request directly. The hard-coded raw IP further prevents normal domain-based ownership validation and makes safe environment-specific configuration difficult.

This finding is limited to exposure and manipulation of the publication request. The reviewed files do not establish that the endpoint returns executable content or that the skill executes a remote payload.

Attack Path

  1. A user invokes the skill to collect sources and generate an article.
  2. The workflow creates /tmp/article.md and copies it into /root/articles.
  3. The agent follows the documented publication procedure and sends the article title, content, and category to http://118.25.114.18:3001/api/articles.
  4. An attacker positioned on the network path intercepts or redirects the plaintext HTTP connection.
  5. The ...[truncated 880 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the plaintext URL with a verified HTTPS endpoint using a valid certificate and mandatory certificate validation.
  2. Use a trusted domain rather than a raw IP address, and document how operators can verify ownership of the publication service.
  3. Move the endpoint into environment-specific trusted configuration instead of hard-coding it in skill instructions.
  4. Require authentication, such as a narrowly scoped API token obtained from a secret manager. Do not embed credentials in the skill package or command history.
  5. Add request-integrity controls, such as authenticated API requests or signed payloads, where supported by the service.
  6. Make remote publication explicitly opt-in. Before transmission, show the destination and the categories of data being sent and require user confirmation.
  7. Default to local-only article storage when remote publication has not been expressly requested.
  8. Avoid predictable shared temporary paths where practical. Create temporary files with restrictive permissions and unique names, then delete them securely after use.
  9. Add failure handling so TLS, authentication, or destination-verification errors stop publication rather than falling back to an insecure connection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes optional POST requests to external publishing services and Feishu document creation, but does not warn that generated content may be transmitted to third-party APIs. This creates data exfiltration and privacy risk, especially if generated articles contain proprietary prompts, internal analysis, or other sensitive material.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases in the front matter are broad enough to match ordinary requests about AI news, tech insights, or writing tasks, which can cause the skill to activate unexpectedly. Because this skill performs downstream file writes and publishing actions, over-broad invocation increases the chance of unintended execution and content publication without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill includes writing article content to the local filesystem and publishing it to an external service, but it does not prominently warn the user about these side effects or require explicit consent. This creates a real risk of unintended data persistence, disclosure, or unauthorized publication when the skill is triggered by a broad request.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The skill contains a concrete external transmission step that POSTs generated article content to a hardcoded remote HTTP endpoint. This is dangerous because it can exfiltrate potentially sensitive or proprietary generated content, uses insecure plaintext HTTP rather than HTTPS, and may publish content to an unintended or untrusted service.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

cp /tmp/article.md /root/articles/$(date +%Y-%m-%d)/tech-insight-daily.md

发布到公众号

curl -X POST http://118.25.114.18:3001/api/articles
-H "Content-Type: application/json"
-d '{"title": "...", "content": "...", "category": "AI技术"}'

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage examples include generic prompts like 'AI日报' and '写一篇技术深度文章', which are common user requests and may inadvertently route benign writing tasks into a workflow that searches, writes files, and publishes externally. In context, the ambiguity is more dangerous because the skill is not read-only; it can create persistent artifacts and trigger network publication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list is broad and generic enough to match many ordinary technology-related requests, which can cause the workflow to activate outside the user's intended scope. In this skill, unintended activation is more concerning because the workflow performs multi-step external data collection and writes output to local storage, increasing the chance of unnecessary autonomous actions and content generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs the skill to write generated content to a fixed filesystem path under /root without any mention of obtaining explicit user consent or allowing the destination to be configured. This can lead to unexpected local side effects, overwriting files, permission issues, or storing sensitive/generated content in a privileged location.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The display name and description are presented only in Chinese, with no indication that the skill supports user language choice or that it is intentionally limited to a Chinese-language audience. Under the policy, language constraints should be opt-in or clearly justified when locale-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.