Back to skill

Security audit

pre-departure-tasks

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed offline-preparation workflow with local state updates and user-confirmed email sending, and its risks are mainly broad triggering and confusing wording rather than hidden or malicious behavior.

Install only if you use this Chinese WorkBuddy offline-preparation workflow. Before running it, ask the agent for a dry-run list of files, automations, scripts, and outbound emails it will touch, and approve any email send or persistent automation change explicitly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill activates on broad natural-language phrases such as '出差/休假/明天不登录/长时间离线' and '把明天的任务现在执行', which are common planning statements and can be mentioned hypothetically or conversationally. In this skill's context, activation can lead to pre-executing tasks, sending emails, updating state files, and modifying reminders, so accidental triggering can cause unintended side effects and duplicate or premature actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Step 6 at L98-L100 instructs the operator to run eod_runner.py as part of the workflow, which reads as a mandatory pre-departure action. However L123 says the closing safeguard should not be run in advance for the offline period and that missing it while offline is normal. That creates an intent contradiction about whether the workflow should proactively execute this mechanism before departure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L118 states that logging in after returning will trigger tasks missed during the offline period, creating a duplicate-output risk unless deduplication is added. But the same document's revised core conclusion at L21-L24 and L31 says that for >=3 days offline, missed tasks are not replayed at all and must be treated as lost. These statements actively conflict about the system behavior the workflow is designed around.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing descriptive and instructional text in the skill is presented only in Chinese, and there is no indication that the user may choose another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.