Back to skill

Security audit

Task Router

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple task classifier that prints routing suggestions and does not itself run external tools, persist changes, or access sensitive data.

This appears safe as a lightweight advisory router. Before installing, understand that its classifications are keyword-based and can be overbroad, especially for trading and system-operation requests, so do not let downstream agents execute those suggestions automatically without separate confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/route-task.sh (reported line 83)May include surrounding context.

sh
ing decision
echo "🎯 Route: $ROUTE"
echo "📊 Confidence: $CONFIDENCE"
echo "📝 Reason: $REASON"
echo "🔢 Complexity: $COMPLEXITY (words: $WORD_COUNT)"
echo ""

# Tool suggestion
case "$ROUTE" in
    coding)   TOOL="codex / claude-code / cursor" ;;
    research) TOOL="web_search / exa-plus / browser" ;;
    trading)  TOOL="trading bot / lighter / variational" ;;
    system)   TOOL="exec / crontab / openclaw CLI" ;;
    content)  TOOL="writer / summarizer / translate" ;;
    general)  TOOL="general LLM chat" ;;
esac

echo "🔧 Suggested tool: $TOOL"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises automatic routing for a very broad set of user tasks based primarily on intent keywords and complexity, but it does not define clear activation boundaries, safety gates, or disambiguation rules. In an agent ecosystem, this can cause ordinary requests to be over-captured and forwarded to higher-risk tools or specialized workflows, increasing the chance of unintended tool use, data exposure, or unsafe action selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.