Back to skill

Security audit

todo.txt skill

Security checks for vulnerabilities and agentic risk

Overview

This todo-list skill is coherent, but it can automatically install software from the internet with elevated privileges if todo.sh is missing.

Review before installing. The task-management behavior is understandable, but do not let an agent run the installer automatically. Install todo.sh yourself from a trusted, pinned source, avoid sudo-based source installs where possible, and confirm edit, delete, archive, and force-flag operations before allowing the skill to change your task files.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install_todo_cli.sh:25
Finding

Unpinned Remote Source Is Built and Installed with Elevated Privileges

Content
View full analysis

Vulnerability Details

File Location: scripts/install_todo_cli.sh:25-26
Additional Location: SKILL.md:26-29
Vulnerability Type: Mutable remote payload retrieval followed by privileged installation
Risk Level: High

Complete Code Snippet:

bash
git clone --depth 1 https://github.com/todotxt/todo.txt-cli.git "$tmp_dir/todo.txt-cli"
(cd "$tmp_dir/todo.txt-cli" && make && sudo make install)

The equivalent manual fallback in SKILL.md is:

shell
git clone https://github.com/todotxt/todo.txt-cli.git
cd todo.txt-cli
make
sudo make install
cp -n /usr/local/etc/todo/config ~/.todo/config

Technical Analysis

The Linux installation process clones the mutable default branch of an external Git repository without pinning a reviewed release tag or immutable commit. It performs no checksum or signature verification before invoking the remotely supplied build system.

Running make executes instructions controlled by the downloaded repository. The subsequent sudo make install executes the upstream installation target with root privileges. As a result, the effective code executed by the Skill can change after the Skill itself has been reviewed.

Retrieving the official todo.txt repository is relevant to the declared functionality, but compiling mutable remote content and granting its installation process root access exceed the minimum privileges needed to manage a user-owned todo.txt file. The installer could instead install a verified version into a user-owned directory.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or the mutable default branch.
  2. The attacker modifies the build or installation instructions to execute malicious commands.
  3. A user invokes the Skill on a Linux system where todo.sh is unavailable.
  4. Following SKILL.md, the Agent automatically runs scripts/install_todo_cli.sh.
  5. The insta ...[truncated 972 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed release and immutable commit rather than cloning the default branch.
  2. Download a fixed release artifact and verify its cryptographic checksum or maintainer signature before executing any build step.
  3. Avoid sudo make install. Install the CLI into a user-owned location such as ~/.local/bin and its configuration into a user-owned directory.
  4. If privileged installation is unavoidable, inspect and constrain the exact files being installed rather than executing an upstream Make target as root.
  5. Require explicit informed user confirmation before network retrieval, compilation, or privilege elevation.
  6. Display the exact pinned version, source URL, expected integrity value, and intended installation paths.
  7. Keep the bundled installer and the manual instructions in SKILL.md synchronized so the fallback does not reintroduce the unsafe path.

T08 · Insecure Dependencies

Warning
Location
README.md:30
Finding

Unversioned npx Installation Executes an Unpinned Package Toolchain

Content
View full analysis

Vulnerability Details

File Location: README.md:30-34
Vulnerability Type: Unpinned package execution during Skill installation
Risk Level: Medium

Complete Code Snippet:

text
## Installation

Paste the one-liner for your platform:

npx skills add aguilera-ee/todo.txt-skill

text

Technical Analysis

The documented installation command invokes npx without pinning the skills package to a specific version or integrity value. If the package is not already available locally, npx may retrieve and execute the package selected by the current registry resolution.

This creates a dependency supply-chain boundary outside the reviewed repository. The command does not establish that the package selected in the future is the same package or version that was considered when these instructions were authored.

Attack Path

  1. An attacker compromises the registry package, its maintainer account, or a future release selected by the unversioned package name.
  2. The attacker publishes package code containing a malicious install or runtime payload.
  3. A user follows the README and runs the documented npx command.
  4. npx resolves and downloads the current package version.
  5. The downloaded package executes with the privileges of the user running the command.
  6. The package can access or modify resources available to that user.

Impact Assessment

A compromised package could execute arbitrary code with the installing user's privileges. This may expose user-owned files, Agent configuration, environment variables, or credentials available to the process and may modify files writable by the user.

The audited repository does not itself contain such a payload, and the exact behavior of the external skills package was not part of the supplied artifact. The risk arises from documenting execution of a mutable, unpinned dependency.

Remediation
View remediation

Remediation Suggestions

  1. Pin the skills package to a reviewed, explicit version in the documented command.
  2. Prefer a package-manager workflow that uses a lockfile and verifies registry integrity metadata.
  3. Document the expected publisher and package source so users can validate what will be executed.
  4. Consider providing a non-executing download or repository-clone method followed by local inspection.
  5. Avoid recommending elevated privileges for this installation command.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to manage todo.txt tasks, but it also instructs the agent to install software, clone code from the network, build from source, and make system-wide changes. This expands the trust boundary far beyond task management and can lead to unauthorized package installation, execution of unreviewed code, and persistent modification of the host system when a simple task command fails.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill authorizes package installation, repository cloning, compilation, and privileged installation without those actions being necessary for normal todo management. This creates a path for an agent to perform high-risk system modification, including running sudo make install, which could execute arbitrary install hooks or replace system files.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
(This script lives in the same directory as this `SKILL.md` file. It detects your OS, installs `todo.sh` — via Homebrew on macOS, from source on Linux — sets up

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/install_todo_cli.sh (reported line 25)May include surrounding context.

sh
tmp_dir="$(mktemp -d)"
    trap 'rm -rf "$tmp_dir"' EXIT
    git clone --depth 1 https://github.com/todotxt/todo.txt-cli.git "$tmp_dir/todo.txt-cli"
    (cd "$tmp_dir/todo.txt-cli" && make && sudo make install)
    mkdir -p ~/.todo
    cp -n /usr/local/etc/todo/config ~/.todo/config
    ;;

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The feature list advertises add, edit, complete, archive, and delete capabilities but does not explicitly warn that these actions modify the local todo.txt data. In an agentic context, users may treat the skill as informational and not realize natural-language requests can cause persistent file changes or deletions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states the skill is self-installing and may run a bundled installation script on macOS or Linux, but it does not clearly warn users that system-level shell commands may be executed. Because installation scripts can modify the environment, fetch dependencies, and potentially require elevated privileges, unclear disclosure materially increases execution and supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The installation command uses npx skills add aguilera-ee/todo.txt-skill without pinning a specific version, so users may fetch whatever package version is current at execution time. That creates a supply-chain risk window where a compromised upstream package, account takeover, or unexpected breaking update could cause unreviewed code to run on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly says users can 'just describe what you need and let your agent pick the skill,' which encourages broad automatic activation from ordinary language. In a skill that can modify task files and run commands, ambiguous triggering increases the chance of unintended execution and state-changing actions without the user deliberately invoking this skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation embeds network-enabled installation and setup procedures inside an operational skill, causing the agent to cross from task handling into environment provisioning. Even if intended as convenience, this can cause execution of external commands and file changes unrelated to the user's immediate todo request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill includes package installation, source builds, and filesystem/configuration changes without prominently warning that these modify the system and may require elevated privileges. Lack of warning increases the chance that an agent or user will trigger risky commands without understanding the consequences.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
98% confidence
Finding

The Linux fallback path includes sudo make install, which requests elevated privileges to install software built from cloned source. In an agent-executed context, this is especially dangerous because it can grant root-level execution to unreviewed code and permanently modify the host system.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

git clone https://github.com/todotxt/todo.txt-cli.git cd todo.txt-cli make sudo make install cp -n /usr/local/etc/todo/config ~/.todo/config

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The skill explicitly documents a flag for skipping confirmation prompts, which is risky in an autonomous agent context where the agent may act on ambiguous input. Removing confirmation gates makes accidental completion, deletion, or reprioritization more likely and reduces the user's opportunity to catch mistakes before data is changed.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
## Key options (flags before the action)
| Flag | Meaning |
|------|---------|
| `-f` | Force — skip confirmation prompts |
| `-p` | Plain mode — no colors |
| `-c` | Color mode |
| `-t` | Auto-prepend today's date when adding tasks |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The example normalizes use of the -f flag to bypass confirmation prompts, and the surrounding guidance says to use it for automation. In an agent setting, suppressing confirmations increases the risk of unintended state changes to the user's task data, especially if the agent misidentifies the target task number.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

Example with flag:

shell
todo.sh -f do 3       # delete task 3 without confirmation
todo.sh -t add "Buy milk +groceries"   # add with today's date

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Linux branch clones a remote repository, builds it, runs sudo make install, and copies configuration files into the user's home directory. While the file header says it installs todo.sh, it does not specifically disclose the privileged system-wide install, remote code retrieval/build, or home-directory writes at the point of execution beyond generic success/error messages.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/install_todo_cli.sh (reported line 25)May include surrounding context.

sh
tmp_dir="$(mktemp -d)"
    trap 'rm -rf "$tmp_dir"' EXIT
    git clone --depth 1 https://github.com/todotxt/todo.txt-cli.git "$tmp_dir/todo.txt-cli"
    (cd "$tmp_dir/todo.txt-cli" && make && sudo make install)
    mkdir -p ~/.todo
    cp -n /usr/local/etc/todo/config ~/.todo/config
    ;;

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/install_todo_cli.sh (reported line 26)May include surrounding context.

sh
trap 'rm -rf "$tmp_dir"' EXIT
    git clone --depth 1 https://github.com/todotxt/todo.txt-cli.git "$tmp_dir/todo.txt-cli"
    (cd "$tmp_dir/todo.txt-cli" && make && sudo make install)
    mkdir -p ~/.todo
    cp -n /usr/local/etc/todo/config ~/.todo/config
    ;;
  *)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill description includes delete, archive, move, and deduplicate operations that alter or remove task data, but it does not warn users about the potential impact on their todo files. For markdown files, omission of warnings about behavior affecting user data is in scope for this rule.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
99% confidence
Finding

The example command todo.sh -f do 3 uses the do action, which marks task 3 as done, but the comment says it will delete task 3 without confirmation. This is an active contradiction between documentation and actual command behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.