Back to skill

Security audit

Nag

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed persistent reminder helper whose cron jobs, heartbeat checks, and state file match its stated purpose.

Before installing, make sure you are comfortable with adding cron jobs and a heartbeat block that can keep reminding you across sessions. Review each reminder's schedule, confirmation phrases, and tone, and remove the related cron job plus nag-config/state entries when you no longer want it active.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
|-------|----------|-------------|
| `id` | yes | Unique identifier, used as key in state file |
| `label` | yes | Human-readable name for display |
| `cronFirst` | yes | Cron expression for initial reminder (create a cron job for this) |
| `nagAfter` | yes | Time (HH:MM, 24h) after which heartbeat nags begin |
| `confirmPatterns` | yes | Array of phrases that mark the reminder as done (case-insensitive, substring match) |
| `tone` | no | Personality guidance for generating nag messages. If absent, use a neutral friendly tone. The model has creative liberty to vary the wording each nag. |

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
### 3. Wire Up Cron + Heartbeat

**For each reminder**, create a cron job that fires `messages.first` at the `cronFirst` schedule.

**In HEARTBEAT.md**, add a nag check block:

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
## Adding a New Reminder

1. Add entry to `nag-config.json`
2. Create a cron job for the `cronFirst` schedule
3. The heartbeat nag block handles everything else automatically

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
## Adding a New Reminder

1. Add entry to `nag-config.json`
2. Create a cron job for the `cronFirst` schedule
3. The heartbeat nag block handles everything else automatically

## Removing a Reminder

Static analysis

No suspicious patterns detected.