T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:57- Finding
Unpinned Remote Project Retrieval and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent, but its setup instructions ask users to run an unpinned external project with Docker and npm, which needs careful review before installation.
Install only in an isolated development environment after reviewing the upstream repository, Docker Compose file, npm scripts, dependency lockfiles, and container images. Pin a reviewed commit or release before running it, avoid putting administrator passwords on the command line, and do not add real API keys or account-connected publishing credentials until you understand what data the app stores and sends to model providers or other services.
SKILL.md:57Unpinned Remote Project Retrieval and Execution
SKILL.md:71Administrator Password Exposed Through Command-Line Arguments
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd ai-content
# 2. 配置环境变量
cp backend/.env.example backend/.env
cp frontend/.env.example frontend/.env.local
# 3. 启动数据库与 Redis
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# 2. 配置环境变量
cp backend/.env.example backend/.env
cp frontend/.env.example frontend/.env.local
# 3. 启动数据库与 Redis
docker compose up -d
The skill promotes automated collection, AI processing, and multi-platform content workflows but does not warn users that scraped data, prompts, or account-related content may be transmitted to third-party model providers or external services. In this context, the missing disclosure increases the risk of privacy leakage, compliance issues, and unintended account-impacting actions if users supply sensitive materials or configure publishing-related integrations.
The trigger list is excessively broad and includes generic phrases such as content collection, material management, topic mining, and article templates, which can cause accidental activation in unrelated conversations. In an agent environment, overbroad matching can route benign user requests into a workflow that performs scraping, data processing, or other higher-risk actions without clear user intent.
The capability boundary states '直接发布到小红书(需手动复制发布)' and '微信公众号直连发布' are not supported, framing the skill as content creation and planning only. However, the rest of the file describes a full application stack with backend services, database initialization, admin bootstrap, and '发布管理'/'定时发布' workflow, which suggests operational publishing-management functionality beyond simple prompt/content assistance.
No suspicious patterns detected.