Back to skill

Security audit

spec-task

Security checks for vulnerabilities and agentic risk

Overview

This task-management skill is mostly transparent, but it asks for broad workflow control and persistent memory writes that users should review before installing.

Install only if you want this skill to strongly shape agent task workflow and create reusable task history. Before use, confirm where memory files are written, review archive contents before approving them, and disable or avoid history/lesson generation for sensitive projects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Mandatory Workflow and Prompt-Context Hijacking

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
schemas/agent-task/schema.yaml:118
Finding

Unsanitized Task Content Can Be Written to Persistent Agent Memory

Content
View full analysis
.md 2. generate_lessons → write to ${agent.workspace}/memory/task-lessons/.md 3. If auto_archive is false → request confirmation before archiving ${agent.workspace} is the current Agent's workspace path. Archive files use Markdown and contain the task summary, key outputs, and lessons learned. ``` ### Technical Analysis The default configuration enables both task-history recording and generated lessons. The schema directs `task_archive` to place those records under the current Agent's memory directory. Task names, summaries, outputs, capability keywords, and generated lessons may derive from user-controlled or otherwise untrusted task content. No reviewed file defines sanitization, provenance labeling, instruction neutralization, secret filtering, retention limits, or a rule preventing archived Markdown from being interpreted as authoritative instructions when recalled later. Although `auto_archive` is disabled by default and the schema says confirmation should be requested, confirmation alone does not neutralize malicious content. Once archived, attacker-controlled text may survive the current task and be reintroduced during later memory retrieval. The project does not contain the ...[truncated 1679 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire skill instructions are written as mandatory Chinese-language guidance, with no indication that the user may choose another language or locale. Under the policy, language constraints are only acceptable when the skill offers opt-in or clearly documents a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This manifest file contains natural-language comments and guidance exclusively in Chinese, which effectively forces a specific language/locale for users reading or maintaining the skill. The policy allows locale constraints only when documented and justified or when users are offered a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Lines L30 and L33 say the skill does not use CLI tools and does not need CLI-style interactive commands, framing those OpenSpec capabilities as removed. However, L51 states that named scripts are actually executed as corresponding TypeScript tools, which contradicts the earlier claim that CLI/tool execution is not part of the skill model.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title begins in Chinese ("Status.yaml 格式参考"), and the entire document content is written in Chinese without any indication that language selection is optional or that the skill is region-specific. This creates a natural-language policy concern because it effectively forces a specific language/locale on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This YAML manifest is almost entirely written in Chinese, including the top-level description and all user-facing instructions, which imposes a specific language/locale on skill use. The file does not offer a language choice, opt-in, or any justification that the skill is region-specific, so it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The archive phase instructs the agent to write task summaries and lessons into persistent workspace memory paths outside the immediate task output area. This expands the skill from transient task orchestration into long-lived data retention, which can unintentionally persist sensitive project details, user data, or operational context without explicit consent, minimization, or retention controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and there is no indication that the skill offers alternative language support or that Chinese is a required locale. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template includes instructional comments and placeholders in Chinese throughout the file, which effectively imposes a specific language on users of the skill. The policy allows locale constraints only when explicitly justified or when users are given a choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown template uses Chinese instructional text and placeholders throughout, such as '任务名称' and '步骤编号应与 plan.md 的 Steps Overview 对应'. The file does not indicate that the template is region-specific or provide any opt-in or alternative language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template includes instructional text such as '任务名称' and other section guidance exclusively in Chinese. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.