Back to skill

Security audit

墨记 (moji-daily)

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local daily task tracker that can create recurring reminders and update local Markdown task files, with no evidence of hidden or unrelated behavior.

Install this only if you want daily scheduled task prompts and local Markdown task history. Review the cron JSON, Feishu channel, schedule, and tasks directory before enabling it, and avoid putting secrets or highly sensitive details in task notes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The example chat triggers are broad natural-language phrases that can easily overlap with ordinary conversation, causing unintended activation and unauthorized task modifications. In a chat-driven automation skill that writes local files, ambiguous triggers increase the risk of accidental state changes without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises automatic writing and updating of local task files but does not warn users that conversational input may directly modify persistent local data. Without explicit notice and confirmation, users may unknowingly trigger file writes, overwrites, or rollovers, creating integrity and privacy risks for local notes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.