Back to skill

Security audit

Long Task Handler

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent long-task runner, but it can expose raw task logs and command details through chat notifications and plaintext local state without clear consent or redaction.

Review before installing. Use this only in workspaces where sending task status to chat is acceptable, avoid running commands that print secrets, tokens, database records, or private paths, and prefer a version that redacts logs, sends only summaries by default, routes notifications to the originating conversation, and stores minimal task state with restricted permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:107
Finding

Unredacted task output may be forwarded to a hard-coded external channel

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:107-116, SKILL.md:149-164, and SKILL.md:295-305
Vulnerability Type: Unredacted disclosure of command output
Risk Level: Medium

The skill specification forwards portions of process output and error logs directly through the messaging tool. Progress and completion notifications explicitly select the feishu channel instead of deriving the destination from the authenticated originating conversation.

Relevant progress-reporting code:

javascript
if (result.output && result.output !== lastOutput) {
  const newLines = result.output.slice(lastOutput.length);
  if (newLines.trim()) {
    await message({
      channel: 'feishu',
      message: `📊 任务进展:\n\`\`\`\n${newLines.slice(-500)}\n\`\`\``
    });
    lastOutput = result.output;
    silentSince = Date.now();
  }
}

Relevant completion-notification code:

javascript
const status = result.exitCode === 0 ? '✅' : '❌';
const duration = formatDuration(result.durationMs);

await message({
  channel: 'feishu',
  message: `${status} **任务完成!**
  
耗时:${duration}
退出码:${result.exitCode}

${result.exitCode === 0 ? '🎉 一切顺利!' : '⚠️ 任务失败,请检查日志'}

${fullLog.output ? '最近输出:\n```\n' + fullLog.output.slice(-1000) + '\n```' : ''}`
});

Relevant error-reporting code:

javascript
if (result.exitCode !== 0) {
  const errorLog = await process({
    action: 'log',
    sessionId,
    offset: -50,
    limit: 50
  });
  
  await message({
    message: `❌ **任务失败!**
  
退出码:${result.exitCode}
错误摘要:\n\`\`\`\n${errorLog.output.slice(-500)}\n\`\`\`

需要我帮你分析问题原因吗?`
  });
}

Technical Analysis

Build, deployment, migration, and model-training commands commonly print environment variables, authenticated URLs, access tokens, private filesystem paths, database records, or infrastructure identifiers. Limiting the output to the final 500 or 1,000 char ...[truncated 1782 chars]

Remediation
View remediation

Remediation Suggestions

  1. Route notifications only to the authenticated conversation and channel that originated the task. Do not hard-code feishu.
  2. Require explicit user approval before sending task output to a different channel, conversation, or recipient.
  3. Apply secret redaction before transmission. Detect common token formats, authorization headers, private keys, credential-bearing URLs, passwords, and configured secret values.
  4. Prefer structured status summaries over raw logs. Raw log delivery should be opt-in and restricted to authorized recipients.
  5. Normalize and sanitize output before embedding it in Markdown to prevent formatting or mention injection.
  6. Add configurable output limits and a policy that completely suppresses output for tasks classified as sensitive.
  7. Add tests verifying that secrets are removed and that notification destinations cannot differ from the originating context without authorization.

T09 · Insecure Skill Coding Practices

Warning
Location
task-manager.js:32
Finding

Task commands and caller-supplied options are persisted in plaintext

Content
View full analysis

Vulnerability Details

File Location: task-manager.js:32-39 and task-manager.js:47-63
Vulnerability Type: Plaintext storage and overbroad persistence of sensitive task metadata
Risk Level: Medium

The task manager serializes its complete task map and queue into task-state.json without redaction, field allowlisting, encryption, or an explicit restrictive file mode.

State-writing code:

javascript
saveState() {
  try {
    const data = {
      tasks: Object.fromEntries(this.tasks),
      queue: this.queue
    };
    fs.writeFileSync(STATE_FILE, JSON.stringify(data, null, 2));
  } catch (e) {
    console.error('Failed to save task state:', e);
  }
}

Task-registration code:

javascript
register(sessionId, options) {
  const task = {
    sessionId,
    status: 'running',
    createdAt: Date.now(),
    updatedAt: Date.now(),
    command: options.command,
    estimatedDuration: options.estimatedDuration,
    pollInterval: options.pollInterval || 30000,
    lastOutput: '',
    exitCode: null,
    timedOut: false,
    ...options
  };

  this.tasks.set(sessionId, task);
  this.saveState();
  return task;
}

Technical Analysis

The raw command is stored in the task object, and the trailing ...options spread copies every caller-supplied property into persistent state. Commands may contain inline API keys, passwords, credential-bearing connection strings, authenticated URLs, private filenames, or confidential arguments. Arbitrary option fields may contain equally sensitive information.

fs.writeFileSync is called without an explicit mode, so access restrictions depend on the process environment, parent-directory permissions, existing file permissions, and the operating-system umask. The state is also placed inside the skill directory rather than a dedicated protected runtime-state directory.

Cleanup only removes completed task records older th ...[truncated 1294 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace ...options with an explicit allowlist containing only fields required for task recovery and display.
  2. Avoid storing raw command strings. Persist a sanitized task label or redact credentials before serialization.
  3. Store runtime state in a dedicated operating-system-protected application data directory rather than the package directory.
  4. Create and maintain the state file with owner-only permissions, such as mode 0600, and validate permissions when loading an existing file.
  5. Use atomic writes through a securely created temporary file followed by a rename to prevent partially written state and unsafe permission inheritance.
  6. Encrypt sensitive state using a key managed outside the state file when sensitive persistence is unavoidable.
  7. Apply automatic retention and deletion during startup and task completion, including queued and failed tasks.
  8. Add tests confirming that passwords, tokens, connection strings, and unknown option properties never appear in persisted state.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill sends progress updates and completion notifications to external channels such as Feishu, including snippets of task output, but does not clearly warn the user beforehand. This creates a real confidentiality risk because command output and logs often contain secrets, file paths, internal hostnames, tokens, or user data that would be exfiltrated to third-party messaging systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

Nearly all user-facing instructions, examples, confirmations, and notifications are written only in Chinese, and the document does not state that language is configurable or limited to a region-specific context. This can constitute a locale policy issue when a skill effectively forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is designed to handle deployments, migrations, and task termination, all of which can modify systems or affect user data, yet it does not clearly warn users about these consequences at activation time. That increases the chance of users invoking impactful operations without understanding that the agent may perform destructive or irreversible actions in the background.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match ordinary requests such as '慢慢跑' or '别等我', which can cause the skill to activate unexpectedly and shift tasks into background execution without clear user intent. In this skill, unintended activation is more dangerous because activation can lead to execution, notifications, and state-changing operations like deployment or migration.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The progress monitor relays raw new task output to an external chat channel, which is a direct data exposure path. In long-running tasks like builds, deployments, migrations, and model training, stdout/stderr commonly contains credentials, dataset samples, stack traces, config values, and internal infrastructure details, making this especially risky.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The completion notification includes recent raw logs by default, which can expose sensitive execution details after the task finishes. This is particularly dangerous because end-of-task logs often contain final artifact paths, deployment endpoints, error traces, migration details, or secrets echoed during execution.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The /task <id> log behavior is described as returning raw execution logs on request, creating an easy path to disclose sensitive contents conversationally. Because logs often contain stack traces, environment details, and user or system data, exposing them without access checks or redaction is a meaningful confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description is presented only in Chinese ("长任务处理技能 - 后台执行、进度反馈、不阻塞队列") with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy expectations when a skill implicitly enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language description and inline documentation are predominantly in Chinese, which can indicate a language-specific constraint for users or maintainers. There is no accompanying statement that the skill supports multiple languages or that Chinese is required for a justified region-specific purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The task manager persists full task objects, including command strings and metadata, to a local JSON file without any notice, minimization, or protection. In an agent context, commands may contain secrets, file paths, tokens, or sensitive operational details, so silent persistence increases the risk of unintended disclosure to other local users, tools, or future runs.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Displaying full command names and session identifiers can leak operational details such as repository names, server targets, file paths, or internal workflow structure. The impact is lower than raw log leakage, but it still increases information exposure and can aid follow-on abuse or social engineering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest uses Chinese-only natural-language strings for the description, author-facing labels, config descriptions, and changelog entries. For a general-purpose skill manifest, that imposes a language choice without any stated opt-in or documented region-specific justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.