TaskTime CLI

Security checks across malware telemetry and agentic risk

Overview

TaskTime is a disclosed task-timer skill that installs a CLI and saves task logs locally and to ClawVault as part of its stated purpose.

Install only if you are comfortable with a global npm CLI and with completed task names, notes, timing metadata, and reports being saved persistently and potentially synced to ClawVault. Avoid putting secrets, customer data, or confidential project details in task descriptions or notes, and use `--no-vault` for work that should stay out of remote memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises that completed tasks are automatically saved to ClawVault, but the description does not provide a prominent privacy warning about what task descriptions and notes may be transmitted or persisted externally. In an agent context, task titles and notes can contain sensitive data such as internal project names, credentials-in-context, customer details, or research notes, so implicit auto-sync increases the risk of unintended data exfiltration.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal