Back to skill

Security audit

Daily News Brief

Security checks for vulnerabilities and agentic risk

Overview

The skill’s news collection purpose is coherent, but its installer adds durable scheduled execution and optional privileged service setup with weak scoping and removal controls.

Install only after reviewing the scripts and dependency sources. Prefer host-managed scheduling or a clearly marked per-user cron entry, avoid the optional systemd/admin setup unless you need it, verify recipients before enabling external delivery, and treat generated briefs as untrusted scraped content until links and Markdown are sanitized.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
install.sh:64
Finding

Cross-Session Execution Through Scheduled Tasks and System Services

Content
View full analysis
> logs/cron.log 2>&1" # Add the job to the current user's crontab (crontab -l 2>/dev/null | grep -v "news-brief.js"; echo "$CRON_JOB") | crontab - ``` The installer also generates the following optional systemd service: ```ini [Service] Type=simple User=$USER WorkingDirectory=$(pwd) ExecStart=/usr/bin/node $(pwd)/news-brief.js --setup-cron Restart=on-failure RestartSec=10 [Install] WantedBy=multi-user.target ``` ### Technical Analysis The installer modifies the current user's crontab to execute the Skill every day. It can also generate a systemd unit that the documentation instructs the user to copy into `/etc/systemd/system`, enable, and start with elevated privileges. Daily scheduling is consistent with the declared news-brief functionality, and the installer asks for confirmation before configuring it. Nevertheless, these mechanisms survive the current Skill run and cause code and dependencies from the project directory to execute later without renewed approval. The systemd option is especially excessive because it creates boot-level persistence while internally starting another scheduler through `--setup-cron`. The crontab replacement logic removes every existing crontab line containing `news-brief.js`, rather than identifying only a uniquely marked job owned by this installation. It may consequently alter unrelated scheduled tasks. ### Attack Path 1. A user runs `install.sh`. 2. The user accepts the scheduling prompt. 3. The installer rewrites the user's crontab and adds a daily command that executes `news-brief.js`. 4. Alternatively, the user follows the provided privileged systemd comman ...[truncated 1008 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
news-brief.js:139
Finding

Untrusted News Content Is Inserted Into Markdown Without Escaping or Link Validation

Content
View full analysis
{ const title = $(elem).text().trim(); const href = $(elem).attr('href'); if (title && href && href.startsWith('http')) { if (title.length > 10 && !this.isAdvertisement(title)) { newsItems.push({ title, url: href, category, source: '新浪', timestamp: new Date().toISOString(), priority: this.calculatePriority(title, category) }); } } }); ``` The collected values are later emitted directly: ```javascript brief.sections.international.forEach((item, index) => { markdown += `${index + 1}. **${item.title}** [${item.source}](${item.url})\n`; }); ``` ### Technical Analysis Headline text and link destinations originate from remotely retrieved HTML. The code performs only basic length and advertising-keyword checks before storing these values. It does not escape Markdown control characters in titles and does not validate that absolute URLs remain on an approved news domain. A compromised or malicious source page can therefore provide a title containing Markdown syntax or an anchor targeting an unrelated domain. The generated brief will preserve that content in local archives, console output, and any future delivery integration. Depending on the renderer, crafted content could create misleading links, embedded images, tracking requests, or instruction-like text. The generic parser also constructs relative URLs using the first configured source for a category rather than the source currently being parsed. This can misattribute links and undermine origin validation. ### Attack Path 1. A configured news site, upstream advertisement, or compromised ...[truncated 984 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package-lock.json:27
Finding

Dependency Lockfile Retrieves Packages From a Third-Party Registry Mirror

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (62)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SETUP-GUIDE.md (reported line 111)May include surrounding context.

schtasks /run /tn DailyNewsBrief

删除任务

schtasks /delete /tn DailyNewsBrief /f

text

## 📈 扩展功能

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This mismatch includes undeclared local file writes, external network fetching, and possible outbound publication channels. When a skill's declared purpose omits those capabilities, users and enforcement layers may not apply appropriate scrutiny, increasing risk of silent data storage, content exfiltration, or unreviewed external communications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

This mismatch includes undeclared local file writes, external network fetching, and possible outbound publication channels. When a skill's declared purpose omits those capabilities, users and enforcement layers may not apply appropriate scrutiny, increasing risk of silent data storage, content exfiltration, or unreviewed external communications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch includes undeclared local file writes, external network fetching, and possible outbound publication channels. When a skill's declared purpose omits those capabilities, users and enforcement layers may not apply appropriate scrutiny, increasing risk of silent data storage, content exfiltration, or unreviewed external communications.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile pins axios 1.13.6, and the provided advisories include SSRF/proxy bypass and prototype-pollution-related MITM/credential theft issues. In a news aggregation skill that fetches remote content, an HTTP client vulnerability is directly relevant because attacker-controlled URLs, redirects, or proxy handling can influence outbound requests and expose internal services or credentials.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==5.0.4 — 5 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-45149 (brace-expansion: Large numeric range defeats documented `max` DoS protection) +2 more

High
Category
Supply Chain
Confidence
83% confidence
Finding

brace-expansion 5.0.4 is flagged for denial-of-service issues involving pathological expansion patterns. In this package-lock it appears only as a development/transitive dependency, so the practical risk to the deployed skill is limited unless developer tooling or any runtime path processes attacker-controlled glob patterns.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
87% confidence
Finding

form-data 4.0.5 is flagged for CRLF injection via unescaped multipart field names and filenames. This skill is primarily a news collector, so multipart upload behavior may not be central, but if any fetched content or metadata is repackaged into multipart requests, attacker-controlled values could corrupt request boundaries or inject unintended headers/content.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==2.3.1 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
80% confidence
Finding

picomatch 2.3.1 is associated with ReDoS and incorrect glob matching issues, but here it is a transitive development dependency under file-watching tooling. That makes it a real vulnerable package with relatively low production exposure unless untrusted glob expressions are processed in development or CI environments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.22.0 — 16 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +13 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

undici 7.22.0 is flagged for multiple HTTP parsing and request-smuggling-style issues. In this skill, undici is pulled in by cheerio and is relevant because the application ingests remote web content; HTTP client desynchronization, CRLF injection, or response queue poisoning can have serious effects when talking to attacker-controlled or compromised news sources.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest permits axios versions affected by multiple known advisories, including SSRF-related and prototype-pollution/MITM-associated issues. This skill's purpose is to fetch external news content automatically, so a vulnerable HTTP client is especially risky because it processes untrusted remote endpoints on a schedule without user intervention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automatic publication to Feishu, WeChat bots, email, console, and historical archiving, but does not warn users that content, recipients, logs, or generated summaries may be sent to external services and stored persistently. In an automation skill, lack of disclosure increases the chance of unintended data sharing, accidental oversharing to configured recipients, and retention of potentially sensitive generated content or metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide explicitly tells users to run setup scripts and PowerShell as administrator to create a scheduled task, but it does not explain what privileged changes will be made or advise users to inspect the script first. In a skill package, this is risky because any hidden or later-modified script executed with elevation could alter system settings, persistence, or install additional components beyond the stated task setup.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation instructs use of shell commands and describes filesystem/network-capable behavior, but it does not declare any explicit tool scope such as allowed tools or permissions. This creates an authorization and transparency gap: a user or platform may treat the skill as low-risk documentation while it implicitly relies on command execution and external access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes multi-channel publishing, archival history, reading statistics, and feedback collection without a prominent user warning or consent model. In a news-aggregation context, automatic outbound posting and retention can expose user preferences, recipients, or collected content to third parties and create privacy/compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all user-facing content exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or alternative language option is provided. The file does not indicate that the skill is intentionally region-specific or limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all user-facing content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this locale. Under the language/locale policy criterion, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire brief is presented in Chinese, and the file contains no indication that the user can choose another language or that the locale restriction is intentional and justified. Under the policy, a skill that forces a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is natural-language content, so language-policy checks apply. The file forces a single language throughout the skill content and does not indicate user opt-in, multilingual support, or a documented region-specific justification for the Chinese-only presentation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 48)May include surrounding context.

sh
# 设置文件权限
echo "🔒 设置文件权限..."
chmod +x news-brief.js
chmod 644 config.json package.json

# 测试运行
echo "🧪 测试运行..."

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The script offers to add a cron entry that persistently runs news-brief.js every day, creating a persistence mechanism on the host. In context this appears to support the skill's advertised scheduling behavior, but persistent execution increases risk because any compromise of the script, dependencies, or working directory will be re-executed automatically.

Content

Scanner excerpt · install.sh (reported line 69)May include surrounding context.

sh
if [[ "$OSTYPE" == "linux-gnu"* ]] || [[ "$OSTYPE" == "darwin"* ]]; then
        CRON_JOB="0 8 * * * cd $(pwd) && node news-brief.js >> logs/cron.log 2>&1"
        
        # 添加到crontab
        (crontab -l 2>/dev/null | grep -v "news-brief.js"; echo "$CRON_JOB") | crontab -
        
        if [ $? -eq 0 ]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 116)May include surrounding context.

sh
echo "📄 服务文件已创建: daily-news-brief.service"
    echo "请手动复制到系统目录:"
    echo "sudo cp daily-news-brief.service $SERVICE_FILE"
    echo "sudo systemctl daemon-reload"
    echo "sudo systemctl enable daily-news-brief.service"
    echo "sudo systemctl start daily-news-brief.service"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 117)May include surrounding context.

sh
echo "📄 服务文件已创建: daily-news-brief.service"
    echo "请手动复制到系统目录:"
    echo "sudo cp daily-news-brief.service $SERVICE_FILE"
    echo "sudo systemctl daemon-reload"
    echo "sudo systemctl enable daily-news-brief.service"
    echo "sudo systemctl start daily-news-brief.service"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 118)May include surrounding context.

sh
echo "📄 服务文件已创建: daily-news-brief.service"
    echo "请手动复制到系统目录:"
    echo "sudo cp daily-news-brief.service $SERVICE_FILE"
    echo "sudo systemctl daemon-reload"
    echo "sudo systemctl enable daily-news-brief.service"
    echo "sudo systemctl start daily-news-brief.service"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 119)May include surrounding context.

sh
echo "📄 服务文件已创建: daily-news-brief.service"
    echo "请手动复制到系统目录:"
    echo "sudo cp daily-news-brief.service $SERVICE_FILE"
    echo "sudo systemctl daemon-reload"
    echo "sudo systemctl enable daily-news-brief.service"
    echo "sudo systemctl start daily-news-brief.service"

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The printed 'systemctl enable' step instructs the user to configure the skill as a persistent system service, which would cause it to survive reboots. Although this is optional and manual, persistence is security-relevant because a later-compromised script or dependency would gain recurring execution with the configured service context.

Content

Scanner excerpt · install.sh (reported line 118)May include surrounding context.

sh
echo "请手动复制到系统目录:"
    echo "sudo cp daily-news-brief.service $SERVICE_FILE"
    echo "sudo systemctl daemon-reload"
    echo "sudo systemctl enable daily-news-brief.service"
    echo "sudo systemctl start daily-news-brief.service"
fi

Static analysis

No suspicious patterns detected.