Back to skill

Security audit

Toggl CLI – Time tracking for you and your agent

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its Toggl purpose, but its install path asks users to run unpinned third-party code and link it globally, so it needs review before use.

Install only if you trust the referenced toggl-cli repository, preferably after pinning and reviewing a specific commit. Keep TOGGL_API_TOKEN out of broad shell environments during install/build, revoke it if exposed, and verify resource IDs carefully before using delete commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Execution of Unpinned Third-Party Repository Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 7–11
Vulnerability Type: Unpinned and unverified third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
git clone https://github.com/FroeMic/toggl-cli
cd toggl-cli
npm install
npm run build
npm link

Technical Analysis

The installation instructions clone the current state of a third-party Git repository without pinning a reviewed commit or immutable release. They then execute npm installation and build operations against that mutable source.

npm install may execute package lifecycle scripts from the cloned repository or its transitive dependencies. npm run build explicitly executes repository-controlled code. Finally, npm link exposes the resulting executable globally within the user's npm environment. Consequently, the code executed during installation can differ from the code originally reviewed with this Skill.

This constitutes a supply-chain risk rather than evidence that the current upstream repository is malicious. The vulnerability arises because the instructions provide no version pinning, integrity verification, dependency provenance validation, or isolation boundary before executing externally controlled code.

Attack Path

  1. An attacker compromises the referenced GitHub account, repository, release process, or a transitive npm dependency.
  2. The attacker adds malicious lifecycle, build, or runtime code.
  3. A user follows the Skill's instructions and clones the mutable default branch.
  4. npm install or npm run build executes the attacker-controlled code with the user's local privileges.
  5. The malicious code reads accessible files or environment variables, potentially including TOGGL_API_TOKEN.
  6. npm link makes the attacker-controlled toggl executable available globally, allowing subsequent legitimate-looking invocations to continue running the modified implementation.

Impa

...[truncated 908 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the repository to a reviewed, immutable commit hash rather than cloning and executing the mutable default branch.
  • Prefer a signed and versioned release from a trusted distribution channel.
  • Publish and verify cryptographic checksums or signatures for the reviewed source and release artifacts.
  • Commit and review the dependency lockfile, then use npm ci instead of npm install to enforce exact dependency versions.
  • Audit package lifecycle scripts and consider initially installing with --ignore-scripts, enabling only explicitly reviewed scripts when required.
  • Run installation and builds in an isolated, minimally privileged environment without unrelated credentials in its environment.
  • Avoid npm link where possible. Install a pinned package version into a dedicated environment or invoke a verified local binary explicitly.
  • Restrict TOGGL_API_TOKEN exposure to processes that require it, rather than making it broadly available during installation or build operations.
  • Document a verification and update process so each new upstream revision is reviewed before users execute it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file lists delete operations such as toggl te delete <id> but provides no warning that the command removes user data. Under the markdown-file criteria, destructive behaviors that could affect user data should be disclosed to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation includes toggl proj delete <id> with no accompanying caution about destructive effects on project data. The markdown guidance should warn users when commands can modify or remove resources affecting workspace integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README lists toggl client delete <id> but does not warn users that this operation may permanently remove client records or associated organizational structure. This omits a user-facing warning for a data-affecting action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file documents toggl task delete <id> --project <project_id> without warning that it deletes task data. This is a user-data-affecting operation that should be disclosed in the skill description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documented toggl group delete <id> --organization <org_id> operation can affect organization structure or access grouping, but no caution is provided. The markdown should warn users about potentially disruptive administrative actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
## API Reference

- **Base URL:** `https://api.track.toggl.com/api/v9`
- **Auth:** HTTP Basic with API token as both username and password
- **Rate Limits:** 1 request/second (leaky bucket), 30-600 requests/hour (quota)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
## API Reference

- **Base URL:** `https://api.track.toggl.com/api/v9`
- **Auth:** HTTP Basic with API token as both username and password
- **Rate Limits:** 1 request/second (leaky bucket), 30-600 requests/hour (quota)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
## API Reference

- **Base URL:** `https://api.track.toggl.com/api/v9`
- **Auth:** HTTP Basic with API token as both username and password
- **Rate Limits:** 1 request/second (leaky bucket), 30-600 requests/hour (quota)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
## API Reference

- **Base URL:** `https://api.track.toggl.com/api/v9`
- **Auth:** HTTP Basic with API token as both username and password
- **Rate Limits:** 1 request/second (leaky bucket), 30-600 requests/hour (quota)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

md
## API Reference

- **Base URL:** `https://api.track.toggl.com/api/v9`
- **Auth:** HTTP Basic with API token as both username and password
- **Rate Limits:** 1 request/second (leaky bucket), 30-600 requests/hour (quota)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

Get current user:

bash
curl -u $TOGGL_API_TOKEN:api_token https://api.track.toggl.com/api/v9/me

List time entries:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The command toggl tag delete <id> deletes a resource, yet the markdown provides no caution about removing labels that may be used in workflows or reports. Markdown skill descriptions should disclose destructive behaviors that affect user data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.