Back to skill

Security audit

Type-Based Autonomy

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed task-queue autonomy workflow that writes project tracking and memory notes, with no hidden code execution or exfiltration behavior found.

Install this only in workspaces where you want the agent to autonomously update task, memory, goals, and learning files. Keep queued tasks specific, archive completed tasks when history matters, and do not let checkpoints or learning notes include secrets, credentials, or sensitive personal information.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly says completed tasks in 'Done Today' may be 'simply delete[d] if not needed' without requiring confirmation, retention policy, backup verification, or warning about loss of audit/history data. In an autonomous workflow, this can erase operational history, reduce traceability, and make recovery or post-incident review harder, especially since the same document also uses queue state as part of task tracking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file describes a generalized proactive memory-checkpointing mechanism rather than behavior specific to type-based autonomy routing. While not directly exploitable on its own, this mismatch expands the skill's behavioral scope and can lead the agent to persist conversation state in situations unrelated to the skill's stated function, weakening least-privilege and increasing unintended data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The WAL protocol says to write checkpoints to a memory file before responding once context reaches a threshold, but gives no warning, consent flow, or filtering guidance for sensitive content. That creates a standing instruction to persist potentially sensitive session content automatically, which can expose user data through retention, later retrieval, or cross-task leakage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The checkpoint template explicitly instructs the agent to preserve broad session data such as human goals, constraints, preferences, open questions, and notes. In a type-based task queue skill, that scope is broader than necessary and can cause unnecessary persistence of sensitive conversational context, increasing privacy and data-minimization risk if memory files are later exposed or reused out of context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template encourages storing broad categories of session data, including goals, constraints, preferences, and unresolved questions, without cautioning against secrets or personal information. In practice, this can cause overcollection of sensitive content and create durable memory artifacts that are unnecessary for task execution and risky if accessed by other components or operators.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs autonomous writes to memory/YYYY-MM-DD.md as a mandatory early-step checkpoint without an explicit warning that project files will be modified. Unprompted persistent writes increase the risk of unwanted data alteration, accidental disclosure of sensitive context into logs, and abuse if upstream task content influences what gets written.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

These instructions tell the agent to modify task queue state by moving items between sections and recording progress, but they do so without clearly warning the user that project tracking files will be altered. Because the same workflow later also updates goals and ideas, an autonomous run can silently change planning artifacts and create integrity issues in shared project state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The heartbeat instructs the agent to update broader project state files like GOALS.md and .learnings/ in addition to queue handling. That expands the skill from task routing into persistent project-state modification, which can cause unintended changes, goal drift, or unauthorized tampering if task content is adversarial or the agent misinterprets relevance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The template states 'Autonomy mode: Type-based' with active types 'research, writing, analysis' but does not define concrete trigger phrases, boundaries, or negative examples for when a task should or should not be treated as one of these autonomous types. These category names are broad and overlap with common work activities, which can lead to unintended pickup of tasks that were not meant for autonomous handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown instructs the skill to 'Update GOALS.md with progress notes' but does not include any warning that the skill may modify user files. Because this behavior affects project content, the description should disclose it so users understand that existing files may be changed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The section explicitly tells the skill to add records to '.learnings/' after task completion, which is a file-writing action. The document provides formatting instructions but no user-facing warning that task execution will create or update files in that directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.