Back to skill

Security audit

SHrimp Tasks

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed task manager, but paired mode gives agents broad access to prompt/provider settings and private app data without enough documented limits or safeguards.

Install only if you are comfortable running the pinned external npm MCP package. Local mode is lower risk because tasks stay on the machine, but before pairing with the iOS app you should confirm what prompt sections, provider settings, inbox items, and activity logs the agent can access or change. Require explicit approval for permanent delete, batch operations, prompt changes, and provider-setting changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill advertises a permanent deletion capability for tasks but provides no warning, confirmation, or safety guidance around irreversible actions. In an agent-operated task manager, this increases the risk of accidental or misinterpreted destructive actions causing data loss, especially when tools may be invoked autonomously or in batches.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.