Back to skill

Security audit

Sedentary Reminder

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent sedentary-break reminder skill with disclosed local reminder-state updates and no evidence of hidden execution, credential use, exfiltration, or destructive behavior.

Before installing, confirm you are comfortable with an implementation maintaining a local reminder state file and, if connected to automation, using presence or idle-style signals to decide when to remind. The reviewed artifact does not contain executable code or hidden network behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly includes 'direct state-editing rules' that map chat commands into heartbeat-state updates, implying user input can cause persistent state changes. Without explicit consent prompts, clear scope limits, validation rules, or warnings about side effects, a user may unknowingly trigger file-backed configuration changes or state corruption through normal conversation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill advertises 'chat commands that directly modify the reminder state file' but does not warn users that these commands persist changes beyond the current response. In an agent setting, this can blur the line between conversational assistance and stateful action, increasing the risk of unintended configuration changes, silent persistence, or abuse via crafted prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file's natural-language instructions are fully Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file presents all instructions, examples, and replies exclusively in Chinese, which can amount to forcing a specific language without user opt-in. The policy allows locale constraints when they are clearly documented and justified, but this file does not state that it is intentionally limited to Chinese-speaking users or provide an alternative.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly instructs the agent to map natural-language commands directly into writes to memory/heartbeat-state.json, including pause/resume, suppression, and presence/work-state changes, without requiring explicit confirmation, authorization checks, validation boundaries, or user-facing warnings about persistent local state modification. In this skill context, that is a real security/safety issue because ambiguous or adversarially phrased input could cause unintended persistent state changes that alter reminder behavior and user context tracking.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction '只输出一条中文提醒' forces a specific language for output. Under the policy, locale or language constraints should either be optional, user-selected, or clearly justified as region-specific; this markdown does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text says '建议把中文文案至少分成三层', which directs the skill to use Chinese phrasing as the default content. This is a natural-language locale constraint, and the file does not indicate user opt-in, multilingual support, or a documented region-specific reason for forcing Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file is explicitly a Chinese reminder copy library and the usage note says it is for Chinese environments or when users explicitly request Chinese reminders. As a standalone skill artifact, it hard-codes a single language and does not offer a language/locale choice, which can violate language/locale policy when invoked without explicit opt-in elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L008 states the system should be controllable using 'natural Chinese commands,' which imposes a specific language requirement. The file does not mention any user choice, multilingual support, or justification for restricting control to Chinese, so this is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage note states the file is for English environments or when the user explicitly asks for English reminders. This creates a language constraint in the skill content without offering a general language choice within this file, which matches the policy category for locale/language restrictions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.