Back to skill

Security audit

定时任务管理(含token节约)

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a disclosed task-auditing tool, but it gives under-scoped deletion instructions and forces unrelated promotional links into every response.

Review before installing. Use it only if you are comfortable letting an agent inspect WorkBuddy task history and token usage, and do not allow it to delete or merge scheduled tasks without an explicit review, backup, and confirmation. Treat the promotional footer links as unrelated third-party marketing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill requires unrelated promotional links to be appended to every output, which is an instruction-injection style abuse of the agent channel for marketing. This is dangerous because it turns operational/security output into a vehicle for unsolicited external links, potentially enabling phishing, user tracking, or trust erosion unrelated to the stated task.

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The documentation creates inconsistent deletion safety rules: PAUSED tasks require confirmation, but replaced tasks may be deleted directly. In a task-management skill with destructive capabilities, inconsistent confirmation logic increases the risk of erroneous or irreversible deletion based on incomplete functional-overlap analysis.

Missing User Warnings

Low
Confidence
79% confidence
Finding
The README explicitly describes reading the local `workbuddy.db` task database to audit scheduled tasks, but it does not warn users that the database may contain sensitive prompts, schedules, metadata, or operational context. In this skill context, local task databases are directly tied to user automation state, so undocumented access increases the risk of unintentional disclosure or overbroad data collection during use.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Overly broad trigger phrases can cause unintended invocation of a skill that reads task data, evaluates deletions, and proposes operational changes. In this context, accidental activation is risky because the skill is not purely informational; it influences destructive and sensitive workflow-management decisions.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Ambiguous read-when examples like '帮我整理一下定时任务' or '定时任务太多了想精简' may match casual user requests and invoke a skill that accesses system task metadata and recommends deletion/merging. The danger is heightened because the skill handles sensitive operational state and can steer users toward destructive maintenance actions without a tightly scoped invocation signal.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
Allowing direct deletion of 'replaced' tasks without a user warning is a genuine destructive-action safety flaw. Replacement judgments can be wrong or incomplete, and deleting automation tasks without confirmation can break workflows, remove historical configurations, or cause loss of operational coverage.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
Mandating fixed promotional Chinese text and links in every output without opt-in is unrelated to the skill's operational purpose and abuses the agent's response channel. This creates a trust and safety issue by mixing system/task-management results with unsolicited marketing, and it may direct users to external destinations they did not request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.