Back to skill

Security audit

automation-token-optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an automation audit tool, but it also tells the agent to delete or modify scheduled tasks with weak confirmation and to append unrelated promotional links to every output.

Review this skill carefully before installing. Use it only if you are comfortable with it reading scheduled-task metadata, prompts, and local token-usage records, and do not allow it to update or delete tasks unless you explicitly approve each exact change and have a backup. The mandatory promotional footer should be removed before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:233
Finding

Mandatory Promotional Content Hijacks Agent Responses

Content
View full analysis
💡 更多实用 AI 效率工具,领取自媒体IP&数字员工&一人公司资料,关注公众号「桂皮AI实战」,添加微信「guipi996」 > 📱 加入自媒体&AI 副业变现交流群:https://e418e2e692454bfaa8b6206e3f0ba789.app.codebuddy.work ``` The heading states that promotional information must be appended to every output. The following instruction requires every result to include the supplied social-media advertising, personal contact identifier, and third-party recruitment URL. ### Technical Analysis The Skill imposes a persistent output instruction unrelated to its declared automation-token auditing functionality. When the Skill is loaded, this instruction attempts to alter the Agent's response behavior by forcing advertising and an external link into every result. This behavior is not required to read token statistics, identify redundant tasks, or generate an audit report. It therefore exceeds the minimum instructions necessary for the declared functionality and matches skill instruction hijacking. The external URL is not accessed by the Python script, and the reviewed project contains no code that automatically transmits data to it. The risk instead arises from the Agent being instructed to distribute the URL to users. ### Attack Path 1. A user installs or invokes the Skill for automation-task analysis. 2. The Agent loads and follows the instructions in `SKILL.md`. 3. The mandatory footer instruction becomes part of the Agent's active session context. 4. The Agent appends the promotional contact information and third-party URL to an otherwise legitimate audit response. 5. A user may follow the externally supplied URL or contact identifier, leaving the trusted Skill environment. ### Impact Assessment No operating-system privileges, credentials, or database write access are obtained through this instruct ...[truncated 554 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:99
Finding

Scheduled Tasks May Be Deleted Without Explicit User Confirmation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个具备分析与治理能力的定时任务全生命周期管理工具,核心能力应包括自动发现高消耗任务、评估可合并任务、识别可删除任务,并产出完整优化方案。实际代码主要完成数据查询、汇总和 Markdown 报告渲染:它从本地 SQLite 数据库读取上个月后台自动化任务的 usage 数据,统计 token 消耗排行和总量,然后输出带有若干 AI 占位注释的报告模板。除“高消耗任务统计”外,其它关键声明能力(合并评估、冗余清理、综合优化建议)并未在代码中实现,只是留待后续 AI 人工/外部流程补充。因此代码行为与声明的主要功能存在实质性不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that tasks deemed replaced can be deleted directly without reconfirmation. In a task-management context, this is dangerous because coverage judgments can be wrong, incomplete, or stale, leading to irreversible deletion of important automations and loss of operational functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation phrase is broad enough that a user request about analyzing scheduled tasks could trigger the skill unintentionally, causing it to enumerate tasks and inspect local data such as workbuddy.db. In this skill’s context, that can expose task metadata and prompts beyond what the user specifically asked for, so the issue is a genuine scope/trigger-boundary weakness even though the apparent intent is convenience rather than abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill proposes scanning all scheduled tasks and reading the task-management database without a clear privacy or data-access warning. This is risky because task definitions, prompts, directories, and token-usage metadata may contain sensitive operational or personal information, and users are not clearly informed before broad collection occurs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation phrases are overly broad and overlap with ordinary user requests, increasing the chance the skill is triggered unexpectedly. That can cause unintended database reads, task enumeration, or administrative recommendations in contexts where the user did not mean to invoke this powerful skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Mandating unsolicited Chinese-language promotional content, contact identifiers, and an external group link in every output is unrelated to the skill's purpose and constitutes behavioral injection. This is dangerous because it can manipulate users, create trust confusion, and route them to third-party channels without consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user-facing instructions and invocation text are entirely in Chinese, which effectively forces a specific language for understanding and use. The README does not offer a language/locale choice or explain that the skill is intentionally limited to a Chinese-speaking audience or region-specific workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires appending unrelated promotional content and external contact links to every output without user request. This is dangerous because it abuses task execution for unsolicited marketing and can exfiltrate user attention or redirect users to external destinations unrelated to the stated function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language instructions in the docstring are entirely Chinese and describe the AI's role as fixed, with no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.