Back to skill

Security audit

Smart Todo - AI智能代办管理

Security checks for vulnerabilities and agentic risk

Overview

This todo skill is useful in purpose, but it can persist workspace and conversation context even after a user declines saving a todo.

Review this skill carefully before installing. It writes local todo files and may save conversation excerpts, workspace file names, environment paths, and WorkBuddy memory-derived references in plaintext. The main issue is that its instructions say to keep context even when the user declines creating a todo; install only if you are comfortable editing or constraining that behavior first.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:49
Finding

Context and Agent Memory Are Captured and Retained After User Consent Is Denied

Content
View full analysis
List[str]: """检查 memory 目录中的记录""" memory_files = [] memory_dir = self.workspace_root / '.workbuddy' / 'memory' if not memory_dir.exists(): return memory_files # 读取最近的 memory 文件 try: md_files = sorted( memory_dir.glob('*.md'), key=lambda x: x.stat().st_mtime, reverse=True ) if md_files: # 读取最近的一个文件,提取提及的文件路径 with open(md_files[0], 'r', encoding='utf-8') as f: content = f.read() import re path_pattern = r'[\w\-./\\]+\.(?:py|js|ts|jsx|tsx|html|css|jav ...[truncated 3032 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:20
Finding

Installation Instructions Use a Mutable and Unpinned Personal Repository

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README advertises automatic capture of work files and conversation history but does not present any user-facing privacy warning, consent model, scope limitation, or retention policy. In a productivity skill, this is dangerous because normal use may silently collect sensitive filenames, document contents, or private conversation context and store them on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises automatic capture of work files, conversation history, and task state, but does not present this as sensitive data collection requiring clear user awareness and consent. Because the captured material may include proprietary filenames, code context, and private dialogue, persistence materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow states that even if the user refuses todo creation, the system will still silently save context for later reference. Retaining data after an explicit refusal defeats user intent and creates an unauthorized persistence channel for potentially sensitive conversation and workspace information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The title, instructions, and all example trigger phrases are presented exclusively in Chinese, implying a fixed language/locale for interaction. The file does not state that the skill is region-specific or offer users an alternative language or explicit opt-in to the locale constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Add-todo triggers like '记一下' are ambiguous and may be used in casual conversation without intending to create a persistent task. Because this skill is designed for natural-language auto-invocation, ambiguous triggers can create unintended records, pollute task storage, and potentially persist sensitive user statements that were not meant to be saved as todos.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The work-interruption triggers include common conversational phrases such as '等一下' and '换个事', which can easily appear in ordinary dialogue unrelated to todo management. In a skill that auto-saves progress and captures context, overly broad triggers can cause unintended activation, resulting in accidental state changes and unnecessary collection of user context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill performs file read/write operations against a persistent todo store but does not declare any explicit tool scope or permissions boundary. That mismatch weakens least-privilege controls and makes it harder for the host to constrain what filesystem access the skill actually needs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

整个技能名称、描述、触发语和示例均默认固定为中文表达,未说明是否支持其他语言,也未给用户提供语言或 locale 选择。按规则,未获用户选择即强制特定语言/区域设置属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The interruption triggers are broad everyday phrases like '等一下' and '先做别的', which can be matched in normal conversation without clear intent to invoke the skill. In this skill, false triggering is more dangerous because invocation can lead to context capture and persistence of conversation/workspace data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

This line explicitly instructs silent retention of user conversation/workspace context even when the user rejects creating a todo. That is a direct privacy and consent violation, and in a productivity skill it is especially risky because captured context may include sensitive project details, filenames, and work-in-progress notes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs broad collection of opened files, recent file modifications, recent conversation history, and current task goals into persistent todo records. This exceeds what is necessary for basic task tracking and can unintentionally store sensitive operational, source-code, or personal information.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example todo format includes detailed dialogue excerpts, specific source file paths, recent files, and interruption reasons, demonstrating persistent storage of sensitive workspace context in plaintext markdown. If the todo files are accessed by other tools, users, or backups, this can leak confidential project and behavioral information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This manifest file contains natural-language values exclusively in Chinese for user-visible task statuses and priorities. Because the file provides no opt-in, fallback, or documented region-specific justification, it appears to force a specific language/locale, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file's user-visible docstrings, labels, defaults, and output formatting are written in Chinese throughout, which effectively fixes the skill's language/locale for users. There is no indication of user opt-in, language selection, or a documented region-specific justification, so this is a language policy concern under the stated rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module captures conversation history, workspace paths, current directory, and environment details without any visible consent, notice, or minimization. In a todo-management skill, this is more dangerous because the expected scope is task tracking, not broad context harvesting, so users may unknowingly disclose sensitive project and conversational data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code broadens a todo skill into filesystem inspection by walking the workspace and parsing .workbuddy/memory files to infer 'open files'. That can expose unrelated project files and memory artifacts that may contain sensitive paths or content, exceeding what users would reasonably expect from simple todo management.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The formatter replays recent conversation content in plain text, including up to the last five messages and partial message bodies. This can surface secrets, credentials, personal data, or internal business information in todo notes or interruption summaries where they may be stored longer or shown in broader contexts.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The interruption capture stores task context plus prior conversation history and creates a resume point by quoting previous text. This increases the chance that sensitive user or assistant content is copied into persistent task state or displayed later outside the original conversational context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module title, docstrings, status values, generated file content, and console output are all written in Chinese, which imposes a specific language/locale on users. There is no indication that the skill offers language selection or that the Chinese-only behavior is intentionally limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code creates the storage directory and later writes or overwrites active.md and archive.md as part of normal operation. Although some methods have internal docstrings and one error print, there is no user-facing disclosure at the points where user data is persisted or modified, so the skill performs safety-relevant file writes without clear warning.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire template, including headings and field labels, is written in Chinese and provides no indication that other languages are supported or that the user can choose the output language. Under the policy for natural-language issues, forcing a specific language without user opt-in is a reportable locale/language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The comments describe obtaining the list of currently open files, implying IDE-backed awareness of active editor state. In practice, the code approximates this by checking recently modified files and parsing a memory markdown file, which is not the same behavior and can produce materially different results from what the documentation suggests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.