Security audit
TickTick
Security checks for vulnerabilities and agentic risk
Overview
This TickTick skill is a straightforward CLI integration that uses a full-access TickTick token but clearly scopes and safeguards task changes.
Install only if you are comfortable giving the TickTick CLI full access to your TickTick tasks and habits. Keep the API token private, and review delete or bulk-change confirmations carefully.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
