Back to skill

Security audit

TickTick API

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TickTick task-management integration, but it asks users to pass an OAuth client secret on the command line and relies on unspecified external commands.

Review before installing. Use only a trusted `ticktick`/`ticktick-setup` implementation, avoid putting real client secrets directly on the command line if possible, confirm destructive deletes explicitly, and verify where OAuth tokens are stored and how to revoke them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

OAuth Client Secret Exposed Through Command-Line Arguments

Content
View full analysis
``` ### Technical Analysis The documented setup procedure instructs users to supply the TickTick OAuth client secret directly as a command-line argument. Secrets passed this way may be exposed through: - Shell history files and history synchronization systems - Process listings or process-monitoring utilities while the command is running - Terminal session recordings - Command auditing and endpoint telemetry - Diagnostic logs that capture complete command lines The project contains only documentation, so the behavior of the referenced `ticktick-setup` executable and its subsequent token-storage mechanism could not be verified. Nevertheless, the documented invocation itself creates a credential-exposure risk. ### Attack Path 1. A user follows the documented setup procedure and executes `ticktick-setup` with the real OAuth client secret as an argument. 2. The command, including the secret, is retained in shell history, monitoring telemetry, an audit log, or a terminal recording, or is observed through process inspection while running. 3. An attacker with access to that local account, log source, monitoring system, or process metadata retrieves the client secret. 4. The attacker uses the exposed secret to impersonate the registered OAuth client in applicable TickTick OAuth interactions. ### Impact Assessment Exposure compromises the confidentiality of the TickTick application's OAuth client credential. An attacker may impersonate the OAuth application or abuse OAuth flows associated with that client, subject to TickTick's authorization controls and the attacker's possession of any other required authorization artifacts. The secret alone is not demonstrated to grant ...[truncated 324 chars]
Remediation
View remediation
# The program then securely prompts for the client secret without echoing it. ``` - Document how OAuth tokens and client credentials are stored, encrypted, rotated, and revoked. - Advise users who already followed the original command to remove affected shell-history entries and rotate the exposed OAuth client secret. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
# Add task (inbox)
ticktick add "Buy milk"

# Add task to project with due date
ticktick add "Buy milk" --project <id> --due 2026-01-30

# Complete task

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly documents a destructive delete command but provides no warning, confirmation step, or note that deletion may be irreversible. In a task-management context this increases the likelihood of accidental data loss, especially if an agent invokes the command on the user's behalf.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
## API Reference

Base URL: `https://api.ticktick.com/open/v1`

| Endpoint | Method | Description |
|----------|--------|-------------|

Static analysis

No suspicious patterns detected.