Task Runner

Security checks across malware telemetry and agentic risk

Overview

This task-management skill appears purpose-aligned, with expected local persistence and guarded markdown export behavior.

Install if you want a local persistent task list and markdown exports. Be aware it may activate for broad task or productivity requests, so review where it stores task data and confirm export paths before writing files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises very broad invocation criteria such as organizing work, tracking progress, and maintaining todo lists across sessions. In agent ecosystems, overly broad routing can cause this skill to activate for many ordinary requests, increasing exposure to persistent state changes and file-writing behavior when a narrower skill would suffice.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal