Back to skill

Security audit

Todowrite

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed task-management workflow that can update TODO/checklist state and create GitHub issues only when explicitly directed.

Install this if you want the agent to manage TODOs aggressively across TaskList, local checklist files, and GitHub Issues. Be aware it may activate on general checklist/task language and can rename, complete, or delete TaskList entries as part of synchronization; ask for confirmation before broad moves or deferrals if precision matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description contains a large number of broad natural-language trigger phrases such as 'TODO management', 'checklist', 'task ID', and 'completion report' that could match ordinary user conversation and cause the skill to activate unexpectedly. Overbroad activation increases the chance that this skill hijacks unrelated requests, alters workflow behavior, or routes task data into files/issues without the user intentionally invoking this capability.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes very broad terms such as "move", "transfer", and "defer", and pairs them with mandatory destructive actions like marking tasks as `deleted`. In a natural-language agent workflow, these keywords can appear in many benign contexts, causing the skill to misclassify user intent and perform unintended state changes or deletions across task/checklist media.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.