Back to skill

Security audit

懒人系统

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed productivity check-in skill that uses scheduled reminders and memory for habit tracking, with some manageable risk from broad trigger phrases.

Install only if you want a recurring daily habit reminder and persistent progress tracking in Hermes memory. Consider using the more specific trigger "lazy system" or "懒人系统" and review or remove the cron job and memory entry if you later stop using it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "check in" is very broad and appears in ordinary conversation, which can cause accidental invocation of the skill when a user is not intending to activate it. Because this skill initiates memory-backed behavior tracking and scheduled check-ins, unintended activation can lead to unexpected persistence, nuisance automation, and collection of personal progress data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sets up scheduled proactive daily messages and stores user progress in memory, but the description does not prominently warn users about these behaviors at the point of installation/use. This undermines informed consent and can surprise users with ongoing monitoring-like interactions and retained behavioral data they did not realize would be stored.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrase "check in" is generic everyday language and can easily activate this skill in unrelated conversations, causing unintended invocation. In a skill that stores progress in memory and is designed for recurring behavioral check-ins, accidental activation can lead to confusing state changes, privacy issues, or unwanted automation flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger "打卡" is extremely common in Chinese and is used across many contexts, not just this skill. That makes accidental routing likely, especially because this skill performs memory-based check-in behavior and could respond when the user meant a different app, workflow, or casual statement.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
91% confidence
Finding

The short trigger "打卡" is overly broad and may match many unrelated user inputs. Although this appears in metadata rather than executable code, trigger collisions can still cause unintended skill activation and inappropriate access to the skill's memory-driven workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This trigger is informal and could overlap with many general productivity or assistant requests rather than uniquely identifying this skill. The file does not narrow activation context enough to distinguish this phrase from ordinary user speech.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.