Back to skill

Security audit

Linsoai Track

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent task scheduler, but it can create and change persistent automated jobs and send results externally without strong confirmation or scoping guidance.

Review generated schedules, task messages, notification targets, and destructive actions before enabling them. Avoid bulk-importing untrusted task descriptions, do not put secrets or sensitive output in notifications, and use explicit confirmations for delete, edit, manual run, webhook, email, and backup-cleanup tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README encourages users to create, delete, manually run, and bulk-import scheduled tasks that can trigger autonomous actions and notifications, but it does not warn about review, scoping, or confirmation for potentially destructive or high-impact automations. In a scheduling skill, natural-language task creation increases the risk of unintended recurring actions, accidental task deletion, or mass import of harmful jobs if users paste untrusted or mistaken descriptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata advertises very broad keywords such as reminders, notifications, timing, automation, and tracking, which can overlap with common user requests unrelated to cron management. In an agentic environment, this raises the chance of accidental invocation and unintended task creation or modification, especially because the skill can trigger persistent scheduled actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says users may describe task needs in natural language, but it does not clearly constrain what kinds of requests should activate this skill versus being handled as ordinary conversation. Because the skill can create and manage recurring jobs, ambiguous activation increases the risk of misinterpreting casual statements as commands with lasting side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes state-changing operations including pause, resume, delete, edit, and manual execution, but provides no requirement for confirmation, preview, or safety checks. This is dangerous because an accidental or ambiguous request could delete tasks, alter schedules, or trigger actions immediately, causing unintended execution or loss of configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill routes notifications through IM platforms and email, including by embedding instructions to invoke another skill, but does not warn that task content may be transmitted to third-party services. Scheduled task messages can contain sensitive operational details, so silent external delivery creates confidentiality and compliance risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The email notification section walks users through SMTP setup and sending task content by email, but it omits any notice that recipient addresses, subjects, and message bodies may be transmitted through external mail providers. Because this skill automates task execution and reporting, users could unknowingly route sensitive outputs through third-party email infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The webhook examples explicitly instruct sending task-derived data to external servers via curl, but they do not warn users that summaries, alerts, or other task content may leave the local environment and be processed by third parties. In a scheduling/monitoring skill, this is a real privacy and data-handling risk because users may include sensitive operational details in notifications without understanding the disclosure boundary.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This example demonstrates direct external transmission of task-related data to a remote webhook endpoint. In the context of an automation and notification skill, that increases the chance that generated summaries, monitoring results, or internal metadata are exfiltrated outside the local trust boundary without sufficient disclosure or data minimization guidance.

Content

Scanner excerpt · references/NOTIFICATIONS.md (reported line 111)May include surrounding context.

在任务中使用

text
"...如果{条件},用 curl 发送 POST 请求:
curl -X POST https://your-server.com/webhook \
  -H 'Content-Type: application/json' \
  -d '{\"event\": \"task_alert\", \"message\": \"{摘要}\"}'"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions, examples, and labels only in Chinese. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/TEMPLATES.md (reported line 39)May include surrounding context.

text
"每3小时检查以下服务的状态:
1. https://api.example.com/health — 期望返回 200
2. https://app.example.com — 期望页面正常加载
记录响应时间,如果任何服务异常或响应超过5秒,立即通知我。"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The backup template instructs automatic deletion of backups older than 7 days but does not include any warning, confirmation step, retention safeguards, or verification that newer backups are valid before cleanup. In a scheduling/automation skill, users may copy this template directly, so a misconfigured or misunderstood retention rule could cause unintended data loss and reduce recovery options after backup corruption or operational errors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill description and all example invocations are presented exclusively in Chinese natural language, which can imply a forced language/locale expectation. The file does not state that the skill is Chinese-only for a justified regional reason, nor does it offer users a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

L34 指定“询问用户时区,默认 Asia/Shanghai”。虽然先询问用户可降低风险,但在未明确选择时直接采用特定地区默认值,属于 locale 偏向设置,可能不符合面向广泛用户的语言/区域选择政策。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file presents all instructions in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Per the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.