Back to skill

Security audit

Task Weight Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a focused conversation-prioritization skill, with the main caution that it can save thread summaries in the workspace and can be optionally wired to automation.

Before installing, understand that this skill may create or update a local task-weight-manager thread board with summaries of your conversation context. Use explicit commands if you do not want automatic focus steering, and only enable HEARTBEAT, cron, or external LLM helper integrations when you are comfortable with the related persistence, token cost, and transcript-processing behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly describes writing persistent state to task-weight-manager/threads.md, but it does not declare any tool scope or permissions boundary for file-writing. That creates an authorization ambiguity where the agent may persist conversation-derived data to disk without clear user consent or platform enforcement, increasing the risk of unintended data retention or workspace modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The top-level description is broad enough to match many ordinary conversation-management situations, which can cause the skill to activate outside the user's clear intent. Over-broad activation is dangerous because it can silently change agent behavior, including prioritization and persistence decisions, in contexts where the user expected normal assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README guidance says to use the skill when a conversation contains multiple strands of intent and the user wants the agent to stay oriented, but it does not clearly distinguish this from standard assistant behavior. That ambiguity can lead to unnecessary activation and behavior override, especially in routine chats where summarization or simple task tracking would have been sufficient.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The 'Good phrasing pattern' and sample status block are written entirely in Chinese, and the description references a Chinese concept, but the file does not clarify that Chinese is optional or user-selected. This can create an implicit language preference that conflicts with language-choice policy unless the user explicitly opted in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to maintain a persistent thread board in the workspace, but it does not warn the user that conversation-derived content may be written to disk. This is dangerous because thread boards may capture sensitive prompts, priorities, blockers, or personal/project context that persists beyond the session and may be accessible to others or reused unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill enables allow_implicit_invocation without any visible trigger constraints, exclusions, or narrowing conditions. That means the system may invoke this skill opportunistically based on loose relevance, which can let it steer conversation flow, prioritize topics, or suppress side discussions when the user did not explicitly request that behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance recommends periodically fetching transcript slices and sending them to an LLM or external service, but it does not warn about privacy, consent, retention, or third-party data handling. In a coordination skill that monitors conversation state over time, this can lead to unannounced transmission of potentially sensitive user content outside the immediate chat environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The section 'Suggested user commands' says 'These phrases work well with the skill' and then lists example phrases, but it does not clarify whether these are the only intended triggers, merely examples, or how similar phrasing should be handled. Without explicit scope, exclusions, or negative examples, the invocation boundary is ambiguous for a markdown skill reference.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill recommends very short natural-language trigger phrases that are common in ordinary conversation, which increases the chance of accidental invocation or unintended mode switching. In a focus-management skill, an unintended activation could silently reprioritize threads, suppress side topics, or steer the assistant away from the user’s actual intent, causing workflow disruption rather than direct code execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The example command list is exclusively in Chinese, with no indication that other languages are supported or that Chinese is optional. This can create a natural-language policy concern by implicitly steering usage toward a specific language without offering a choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.