Back to skill

Security audit

Task List

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local task-list assistant, but it asks to persist activation preferences in unspecified main memory outside its declared storage boundary.

Review before installing. The skill appears useful and not malicious, but users should be told clearly whether it will save anything to agent-wide memory, how to opt in, and how to inspect or remove that preference. Keeping all task data and activation settings inside ~/task-list/ would make the privacy boundary clearer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
setup.md:21
Finding

Undeclared Persistent Write Outside the Documented Storage Boundary

Content
View full analysis

Vulnerability Details

File Location: setup.md, lines 21-28
Vulnerability Type: Undeclared external memory persistence and inconsistent storage boundaries
Risk Level: Medium

markdown
### 2. Learn how this should activate

Early in the conversation, learn when this should show up:
- whenever they talk about tasks, todos, follow-ups, or commitments
- only when they ask explicitly
- only for selected work areas or projects

If they want ongoing help, save that activation preference in their main memory so the skill appears in future sessions when it should.

This instruction conflicts with the storage boundary documented in SKILL.md, which states that memory lives in ~/task-list/ and that the Skill does not access files outside that directory for storage.

Technical Analysis

The setup workflow directs the agent to save an activation preference in an unspecified “main memory.” This creates persistent, cross-session behavior outside the Skill's declared ~/task-list/ workspace. The external memory location, retention policy, inspection mechanism, and deletion procedure are not defined.

Although the user must indicate that ongoing assistance is wanted, the Skill does not require separate, explicit consent immediately before writing to this broader memory facility. The mismatch between implemented instructions and the privacy declaration prevents users from accurately understanding or controlling where their preferences are retained.

The issue does not provide arbitrary code execution, elevated operating-system privileges, or network access. Its scope is limited to persistent task-management preferences and future Skill activation behavior.

Attack Path

  1. A user requests ongoing task-list assistance.
  2. The Skill interprets that request as authorization to save an activation preference.
  3. The agent writes the preference to an unspecified main-memory facility outside ~/task-list/.

...[truncated 819 chars]

Remediation
View remediation

Remediation Suggestions

  1. Store activation preferences exclusively in ~/task-list/memory.md, consistent with the declared storage boundary.
  2. If integration with agent-wide memory is necessary, disclose the exact storage scope and purpose before any write occurs.
  3. Require separate, explicit opt-in consent immediately before writing to external or global memory.
  4. Document how users can inspect, update, revoke, and delete the persistent activation preference.
  5. Update the SKILL.md Security and Privacy section so it accurately lists every storage location used by the Skill.
  6. Keep task contents and unrelated personal information out of global memory; retain only the minimum activation setting required.
  7. Add a clear fallback in which declining global-memory integration leaves the Skill manually invokable and stores nothing outside ~/task-list/.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The accepted raw language includes very generic phrases such as "remind me" and "I need to," which commonly occur in ordinary conversation outside a narrow task-capture intent. The file does not provide exclusion conditions or tighter scope to distinguish when these phrases should activate the skill versus when they should be treated as normal dialogue.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · capture-and-clarify.md (reported line 11)May include surrounding context.

md
## Infer silently when confidence is high

Infer without asking when the meaning is obvious:
- explicit dates
- obvious waiting language
- obvious recurring language

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to avoid mentioning file names, folders, setup, or configuration reduces transparency about when the assistant is performing setup-related behavior. This is risky because the same document later contemplates creating local disk state, so hiding operational details can prevent users from understanding or meaningfully consenting to environment changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance is broad enough to trigger on ordinary conversation about tasks, follow-ups, or commitments, which can cause the skill to activate without clear user intent. In a conversational assistant, this can lead to unintended collection of task-related preferences or memory writes, especially because the skill also encourages saving activation preferences for future sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.