Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local habit-tracking CLI that stores user-entered habits and logs on the user's machine, with no evidence of hidden network access or unrelated behavior.
Install only if you are comfortable storing habit names, reminders, completion history, and optional notes as local plaintext JSON files under ~/.config/habit-tracker. Be careful with the delete command because it removes both the habit and its logs immediately.
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
Referenced artifact was not completely inspected
node scripts/habit-cli.js add "Exercise" --frequency daily --target 1 --reminder "08:00"
The skill description is broadly phrased around common productivity tasks like building habits, tracking routines, and generating reports, which could cause the agent to invoke this skill for many generic self-improvement requests. Over-broad activation increases the chance of unintended tool use and unnecessary access to persistent user data or command execution paths, even if the skill itself is not overtly malicious.
The skill explicitly stores habit definitions and completion logs in persistent files under ~/.config/habit-tracker/, creating session persistence across runs. Persistent storage can expose sensitive behavioral data, notes, and routines if accessed by other local processes, reused without user awareness, or retained longer than expected.
## Features
- **Habit Definition**: Create habits with custom frequency (daily/weekly/monthly), targets, and reminders
- **Habit Logging**: Log completions manually with optional notes and custom dates
- **Statistics**: View completion rates, streaks, and trends
- **Progress Reports**: Visual progress bars and summary reports
The delete command permanently removes both a habit and all associated logs immediately after a single CLI invocation, with no confirmation prompt, dry-run mode, or undo capability. In a local productivity CLI this is not code-execution dangerous, but it is still a real safety issue because a mistyped name/ID, scripting error, or accidental invocation can cause irreversible user data loss.
No suspicious patterns detected.