news-summary

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is vulnerable to command injection in multiple locations. In lib/generator.js, the openInBrowser function uses exec to run a PowerShell command where the path includes the topicName (derived directly from the user's query). A malicious query containing shell metacharacters could execute arbitrary commands. Similarly, SKILL.md instructs the agent to execute browser-opening commands using the <topic> string, which is also user-controlled.
  • [DYNAMIC_EXECUTION]: The server.js file uses child_process.spawn with shell: true to execute the claude CLI tool. While the primary arguments are static, the content piped to the process's standard input includes unsanitized data from external news sources and user-provided 'custom prompts'. This presents a high risk of execution flow manipulation if the CLI tool or the shell environment handles specific escape sequences improperly.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a significant indirect prompt injection surface. It fetches news from the web and pipes the titles, summaries, and URLs into a prompt for the claude CLI. A malicious news article could contain instructions designed to hijack the agent's behavior during the 'AI Interpretation' phase. Although the prompt includes instructions to 'only output HTML', LLMs remain susceptible to adversarial content within processed data.
  • Ingestion points: Data enters via the WebSearch or Brave Search tools (referenced in SKILL.md and README.md).
  • Boundary markers: The server.js prompt uses '重要:你的输出必须是纯HTML代码' (Important: Your output must be pure HTML code) to attempt to constrain the output, but lacks robust structural delimiters for untrusted content.
  • Capability inventory: The skill can write files (fs.writeFile), delete files (fs.unlink), and execute CLI commands (spawn('claude', ...)).
  • Sanitization: No evidence of sanitization or escaping for the news content was found before it is interpolated into the AI prompt.
  • [PRIVILEGE_ESCALATION]: The instructions in SKILL.md for restarting the server require the agent to execute taskkill (Windows) or kill -9 (Linux/macOS) on processes identified by port number. While intended for local development, providing the agent with instructions to terminate arbitrary processes based on dynamic input is a dangerous capability.
  • [PATH_TRAVERSAL]: In server.js, the endpoints /check-analysis, /delete-analysis, and /view-analysis use timestamp and newsId parameters from the URL query to construct file paths using path.join. Because these parameters are not validated or sanitized, an attacker could use .. sequences to read or delete arbitrary files on the local file system relative to the server's working directory.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 02:32 AM
Security Audit — agent-trust-hub — news-summary