Back to skill

Security audit

Learning Checkin

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local learning tracker, but an undocumented cron helper can create scheduled jobs that automatically record check-ins, so it needs review before installation.

Review before installing. If used, do not run or adopt the setup-cron output as written; configure reminders to call reminder/message flows only, and require explicit learning-checkin wording or confirmation before recording a check-in. Expect local habit data files to be created in the skill folder, and note that the current init path appears to reference an undefined get_welcome_message helper.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill's stated purpose understates its actual behavior: it stores multiple categories of local state, inspects environment/language information, and references reminder/cron management beyond the simple check-in description. A description-behavior mismatch is dangerous because users and orchestrators may grant trust based on incomplete disclosures, and the noted possibility of generated cron commands performing automatic check-ins conflicts with the claimed reminder-only workflow and can falsify user activity records.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill's own reminder documentation says the agent should check whether the user already checked in before sending reminders, but the generated cron examples invoke the checkin action directly. In this context, a scheduled job would silently create check-ins without user action, falsifying habit data and defeating the integrity of the feature.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The setup-cron behavior constructs scheduled commands that run 'python ... learning_checkin.py checkin' at reminder times. That means the system will automatically record learning completion on behalf of the user, corrupting streak tracking and allowing unattended or misleading progress records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented trigger phrases are short, generic natural-language expressions such as "I'm done" and "check-in complete" that can easily appear in unrelated conversations. In an agent environment, this can cause accidental invocation of the skill, unintended state changes, or logging of check-ins when the user did not mean to interact with this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Progress-check examples like "What's my streak?" and "How am I doing?" are ambiguous and overlap with ordinary assistant queries unrelated to this skill. This increases the chance the skill will intercept general conversation and expose or act on skill-specific data unexpectedly.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly describes local reads and writes to a data directory, but it declares no tool scope or permissions. That creates a trust and containment problem: an agent may execute file-capable behavior without any explicit contract to the user or platform about what filesystem access is needed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Trigger phrases like "I'm done" and "check-in complete" are broad enough to appear in normal conversation unrelated to this skill. In an agent environment, that can cause unintended state changes, creating false records, streak manipulation, or surprise automation when the user did not intend to interact with the skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code comments and docstrings state that only language information is collected, but init_skill also returns the absolute data_dir and skill_path in its output. This creates a privacy/transparency mismatch that can expose local filesystem layout to the caller, which may aid reconnaissance even if the data is not highly sensitive by itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file declares messages as 'English-only' and relies on an external agent to translate them, while the code separately detects the user's locale. This creates a language-policy issue because users are not offered an explicit language choice or opt-in; the skill effectively forces English as its native output behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases "I finished my learning" and especially "check-in done" are broad natural-language utterances that can easily appear in ordinary conversation without a clearly scoped activation boundary. This can cause unintended state changes such as false daily check-ins, streak inflation, or suppression of reminders when the user did not intend to interact with the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.