Back to skill

Security audit

Habits Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local habit-tracking CLI, with disclosed local data storage and optional reminder automation, but users should treat habit notes as potentially private data.

Install only if you are comfortable with a local Node.js tool storing habit names, schedules, completion history, and notes in plaintext under ~/.config/habit-tracker. Avoid putting sensitive medical or personal details in notes, review any cron entries before adding them yourself, and be careful with the delete command because it removes associated log history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/habit-cli.js:10
Finding

Habit and Health Data Stored in Plaintext Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
## Usage Scenarios

### Scenario 1: Create and Start Tracking a New Habit
**User input:** "I want to track my daily reading habit — read for 30 minutes every evening"
**Expected output:** The skill provides the exact CLI command (`node scripts/habit-cli.js add "Read 30 minutes" --frequency daily --target 1 --reminder "21:00"`), explains what it records, and suggests a realistic starting target.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction 'When a user asks for habit advice' is broad enough to activate the skill for generic advice requests rather than only explicit habit-tracking intents. Over-broad routing can cause the agent to surface commands, reminders, or local automation guidance in contexts where the user did not clearly request this tool, increasing the chance of inappropriate action suggestions or unintended data handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'Event-based triggers (e.g., after completing a task)' integration guidance is ambiguous and does not define what system emits events, what permissions are required, or what actions are allowed. In an agent environment, vague event triggers can lead to unexpected autonomous invocation and command suggestions tied to unrelated workflows, expanding the skill's operational scope beyond user-initiated habit tracking.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete command removes both the selected habit and all associated log history, which is an irreversible data-loss operation. Although the help text states that deletion will remove logs, the runtime code provides no confirmation step or additional user-facing warning before performing the deletion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.