Back to skill

Security audit

WeekendWiz

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent weekend scheduling skill, with expected local file updates, screenshots, and disclosed reminder setup, though users should notice its auto-cleanup and QQ bot reminder behavior.

Before installing, confirm you are comfortable with the skill maintaining schedule files under memory/, cleaning up expired events, loading a Google-hosted font in rendered HTML, and sending reminder text through qqbot when reminders are configured. Avoid putting sensitive locations or notes into reminders unless you trust the delivery channel and recipient.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: weekend-wiz
description: Weekend schedule management assistant with magical organization powers. Create, update, and visualize weekend schedules with HTML rendering and automated reminders. Use when users need to manage their weekend calendar, add schedules, set reminders, or generate visual schedule screenshots. Supports markdown schedule files, beautiful HTML visualization, cron reminders, and automatic cleanup of expired events. Named after the wizard-like ability to magically organize your weekends.
---

# WeekendWiz 🧙‍♂️

Your magical weekend schedule assistant that helps you organize your f

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs the agent to read and write local files such as memory/schedule.md and memory/schedule.html, but it does not declare any tool scope or permissions boundary. This creates ambiguity about what filesystem access is expected and can lead to overbroad file operations if the runtime grants more access than the skill truly needs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic cleanup that removes expired events, but it does not warn users that data will be deleted or archived without an explicit confirmation step. This is dangerous because calendar history may be valuable, and silent cleanup can cause unintended data loss or make recovery difficult.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The reminder workflow sends reminder content to an external qqbot channel/user, but the skill does not warn that schedule details, locations, and notes may leave the local environment. Because calendar entries often contain sensitive personal information, users may unknowingly exfiltrate private data to a third-party messaging channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring and implementation hard-code Chinese labels such as "今天/明天/本周/未来" and use Chinese month formatting like "年/月". This is a natural-language locale constraint with no user opt-in or documented justification, which fits the policy violation category for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The schedule format, labels, reminder examples, and user requests are written in Chinese, which implies a fixed language/locale experience. The file does not state that the skill is intentionally region-specific or offer users a language choice, creating a potential language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML template hard-codes a Chinese locale via lang="zh-CN" and uses Chinese-only visible text such as the title and month display. This is a natural-language policy concern because it imposes a specific language/locale without any visible opt-in or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.