Back to skill

Security audit

TickTick Tasks

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TickTick task integration, but its setup tells users to pass an OAuth client secret on the command line and it documents permanent task deletion without any confirmation guidance.

Review this skill before installing. It is meant for TickTick task management, but use care with deletion commands and only delete tasks after verifying the project and task IDs. Avoid putting real OAuth client secrets directly in shell commands where possible; prefer a secure prompt, restricted config file, or credential store if the underlying setup tool supports it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

OAuth Client Secret Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 20
Vulnerability Type: Sensitive information exposure through process arguments and shell history
Risk Level: Medium

Affected Code:

bash
ticktick-setup <client_id> <client_secret>

Technical Analysis

The documented setup procedure instructs users to provide the TickTick OAuth client secret as a command-line argument. Command-line arguments can be exposed through process inspection facilities such as ps, /proc/<pid>/cmdline, process-monitoring software, terminal logging, and audit services. The command may also be retained in the user's shell history.

Consequently, another local user or process with permission to inspect the command line or read the relevant history and logging data could recover the OAuth application secret. This is an insecure secret-handling practice because sensitive credentials should be supplied through a protected interactive prompt, restricted configuration file, operating-system credential store, or another channel that does not expose them in the process argument list.

Attack Path

  1. A user follows the documented setup command and places the real OAuth client secret in the <client_secret> argument.
  2. While ticktick-setup is running, a local attacker or monitoring process observes its command-line arguments through process inspection.
  3. Alternatively, the attacker later obtains access to shell history, terminal logs, audit records, or command telemetry containing the invocation.
  4. The attacker extracts the TickTick OAuth client ID and client secret.
  5. The attacker may impersonate the registered OAuth client in flows accepted by the provider. Account access would additionally depend on obtaining authorization codes, redirect-flow access, or tokens; the documentation alone does not establish that the client secret grants direct access to user tasks.

Impact Assessment

Succ ...[truncated 457 chars]

Remediation
View remediation

Remediation Suggestions

  • Change ticktick-setup to request the client secret through an interactive, non-echoing prompt rather than a positional command-line argument.
  • Support loading the secret from an operating-system credential manager or a configuration file readable only by the owning user, such as a file with mode 0600.
  • If environment-variable input is supported for automation, document that it can still be exposed through process inspection, crash reports, or CI logs and should be handled as a secret by the execution environment.
  • Ensure setup code never logs, prints, or persists the raw client secret in plaintext.
  • Update the documented invocation to a form such as:
    bash
    ticktick-setup --client-id <client_id>
    # The program securely prompts for the client secret.
    
  • Advise users who already followed the documented command to remove affected shell-history entries, review relevant logs, and rotate the OAuth client secret through the TickTick developer console.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
# Add task (inbox)
ticktick add "Buy milk"

# Add task to project with due date
ticktick add "Buy milk" --project <id> --due 2026-01-30

# Complete task

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly documents a permanent delete operation but gives no guidance to confirm destructive actions with the user before execution. In an agent context, this increases the chance of accidental or unauthorized task deletion due to ambiguous prompts, mistaken task IDs, or prompt injection causing destructive actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
## API Reference

Base URL: `https://api.ticktick.com/open/v1`

| Endpoint | Method | Description |
|----------|--------|-------------|

Static analysis

No suspicious patterns detected.