Back to skill

Security audit

Cn Pomodoro Timer

Security checks for vulnerabilities and agentic risk

Overview

This is a small local Chinese pomodoro timer that stores only timer records locally and shows no evidence of exfiltration, privilege escalation, or hidden execution.

Before installing, expect a Chinese-language timer that may write focus-session records to ~/.qclaw/data/pomodoro.json. The included documentation and secondary script have some quality mismatches, and the promotional footer is unrelated, but the inspected behavior is local and low impact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims support for pause, resume, status, daily statistics, and local persistence, but the provided skill content does not define implementation details or constraints for those behaviors. This mismatch can mislead users and reviewers, causing over-trust in functionality and storage handling that may not actually exist or may be implemented elsewhere without scrutiny.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Broad trigger phrases like '开始专注' and '开始番茄钟' lack clear activation boundaries, increasing the chance the skill will activate during ordinary conversation rather than an intentional tool invocation. Unintended activation could cause unexpected local file writes or state changes, especially in an agent environment where users may use similar phrases casually.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Triggers for status, pause, continue, and statistics are highly generic and overlap with common conversational requests. In an agent setting, this ambiguity raises the risk of accidental execution, unintended timer manipulation, and unintended reads/writes of local state without the user's explicit intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file-level description states the tool is a Chinese pomodoro timer, and the user-facing commands and outputs throughout the script are Chinese-only. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

技能描述强调“开始25分钟专注时段,统计今日完成数量”,这通常意味着完成计数应基于计时结束。代码却暴露了“finish/完成”命令,可在任意时刻将当前计时写入历史并记为 completed=True,从而把未满25分钟的会话计入完成数量。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's user-facing natural-language strings and docstrings are entirely in Chinese, including the skill name and all runtime prompts, with no indication that the user can choose another language. The policy requires flagging language or locale constraints when they force a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

清单描述该技能支持暂停、继续、查看状态、统计以及本地存储,但代码仅提供一个同步运行的终端番茄钟循环,除了打印倒计时外没有任何状态查询、暂停/继续控制、完成数统计或持久化逻辑。实际行为明显少于并不同于清单承诺的能力。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

函数文档字符串明确写明“每4轮后长休息15-30分钟”,但后续实现中每一轮结束后都只执行相同的 break_minutes 短休息,没有任何第4轮后的长休息分支。这属于文档对行为的主动性描述与实际代码相矛盾。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest and documentation describe a narrowly scoped local focus-timer tool with local storage and no account requirement. The inclusion of branding and links to an external marketing site introduces behavior/intent outside that stated scope, even though this file does not itself execute network access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.