Back to skill

Security audit

工作日薪看板 Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a local wage and Pomodoro browser widget with disclosed local settings storage, font CDN loading, and notifications, and I found no hidden execution, exfiltration, or destructive behavior.

Before installing, be aware that opening the widget will contact the configured font CDN, may request browser notification permission when the Pomodoro timer completes, and stores salary/work schedule settings in that browser's localStorage. Avoid entering sensitive salary data on shared browser profiles, and treat the weather-bot note as optional unless you intentionally add such automation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
本文件是 `daily_wage.html` 的权威参考。路径:`references\daily_wage.html`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description is written as a Chinese-only presentation of the skill and does not indicate that the user may choose another language or locale. Under the policy, forcing a specific language without opt-in is a language/locale policy concern unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are very broad, covering generic terms like widget, glass card, Pomodoro, and wage-board concepts, which can cause the skill to activate on ordinary requests outside its intended narrow context. Over-broad routing can hijack user intent, override more appropriate skills, and increase the chance that embedded instructions from this skill influence unrelated conversations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest frames this skill as a local personal productivity widget centered on wage calculation and Pomodoro features in a single referenced HTML file. Line L063 expands behavior to include weather data acquisition via a bot periodically fetching weather information into a JSON file, which is outside the core stated scope of a wage/Pomodoro widget.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

A wage board and focus timer do not inherently require network-backed weather retrieval. The suggestion that a bot should regularly fetch weather data for the widget adds a capability unrelated to the manifest's declared purpose of personal salary tracking and concentration timing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language guideline explicitly specifies a Chinese font, which can be interpreted as enforcing a locale-specific presentation choice. The file does not mention user opt-in or explain that the skill is intended only for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file states that the pomodoro timer triggers browser desktop notifications, which affects user attention/privacy on the local device. The description explains the feature but does not include any warning or note that notification permission may be requested or that alerts will be shown outside the page.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown explicitly says all settings are persisted via localStorage, and the configurable fields include salary and work hours. Because this behavior stores potentially sensitive personal data on the device, the skill description should disclose that the data remains in the browser until cleared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The visual specification explicitly fixes the UI language/font to Chinese ('中文:Noto Sans SC'), which can be interpreted as forcing a specific language/locale in the skill guidance. There is no opt-in, alternative locale path, or justification in this file for restricting the presentation to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The root HTML element declares lang="zh-CN", and the visible UI text throughout the page is fixed in Simplified Chinese. Under the policy rule, forcing a specific language/locale without opt-in is a natural-language policy concern unless the file clearly documents that it is intended only for a Chinese-specific context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The widget loads fonts from external third-party domains, which creates unnecessary outbound network requests for a local personal productivity tool. This exposes user metadata such as IP address, user agent, timing, and referrer context to those providers, and also introduces a supply-chain/dependency risk if the remote resource changes or becomes unavailable.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a wage widget with pomodoro focus interaction, but does not mention requesting notification permission or emitting system/browser notifications. Notification capability goes beyond straightforward rendering and timing logic for a local widget and is therefore an unjustified extra capability relative to the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.