Back to skill

Security audit

时迹

Security checks for vulnerabilities and agentic risk

Overview

This TimeFriend skill is coherent, but it can send and modify personal time, diary, and task data through broad conversational triggers that may be invoked unintentionally.

Review this before installing if your TimeFriend data is sensitive. Use explicit TimeFriend commands, avoid sending private diary text casually, keep the TIMEFRIEND_TOKEN secret, and be aware that records and diary entries may be permanently changed on the remote service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:68
Finding

Potential Stored Cross-Site Scripting Through Unescaped Diary Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 68–71
Vulnerability Type: Unsafe HTML construction using unescaped user input
Risk Level: Medium

Complete Code Snippet:

markdown
- 新内容用 `<p>` 标签包裹:`<p>用户说的文字</p>`
- 若今天已有内容,直接在末尾拼接:`{existing_content}<p>新内容</p>`
- 若今天没有内容,直接发:`<p>新内容</p>`
- 内容原文存入,不做 AI 改写,保持用户的原始表达

Technical Analysis

The Skill instructs the agent to place user-controlled diary text directly inside an HTML paragraph and concatenate it with existing HTML. It does not require HTML escaping, validation, or allowlist-based sanitization.

A malicious diary entry could close the paragraph and introduce active markup, for example:

html
</p><img src=x onerror="/* attacker-controlled script */"><p>

The resulting content is submitted to the TimeFriend daily-review API. If the service stores this value and later renders it as HTML without effective server-side or client-side sanitization, the payload could execute in the TimeFriend web origin. The repository does not contain the remote service implementation, so successful script execution depends on how that service sanitizes and renders the submitted HTML.

Attack Path

  1. An attacker persuades a user or agent to save crafted markup as diary content.
  2. The Skill follows its documented rule and inserts the text verbatim into a <p> element.
  3. The agent sends the constructed HTML to PUT /api/daily-reviews/{date}.
  4. The TimeFriend service stores the submitted diary content.
  5. A user opens a page that displays the daily review.
  6. If the application renders the stored value as HTML without adequate sanitization, the injected markup or script executes in the viewer's authenticated browser context.

Impact Assessment

This creates a potential stored cross-site scripting condition. Depending on the remote application's browser security controls and authentication design, exploitation could permit in ...[truncated 461 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat diary text as plain text rather than trusted HTML.
  2. HTML-escape at least &amp;, &lt;, &gt;, &quot;, and &#39; before placing user input inside <p> elements.
  3. Prefer sending structured or plain-text content and let the server perform safe presentation-layer rendering.
  4. Apply server-side allowlist sanitization even if the client or agent already escapes input.
  5. Render untrusted content with safe text APIs rather than raw HTML insertion.
  6. If limited formatting is required, use a well-maintained HTML sanitizer and allow only necessary tags and attributes. Reject scripts, event-handler attributes, dangerous URL schemes, embedded objects, and unsafe CSS.
  7. Add tests covering script tags, event attributes, malformed nested tags, encoded payloads, SVG payloads, and dangerous links.
  8. Deploy a restrictive Content Security Policy as defense in depth, without treating it as a replacement for output encoding and sanitization.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description does not clearly warn users that their activities, diary text, and task data will be transmitted to a third-party remote service. In this context, the omitted notice is significant because the skill handles highly personal productivity and journaling content, so users may disclose sensitive information without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The time-recording triggers are broad enough that ordinary conversational phrases like '帮我记一下' or '刚才做了什么' could activate the skill unintentionally. Because activation leads to transmission of personal activity data to a remote API, accidental invocation can cause unintended disclosure or modification of a user's records.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The diary feature includes very broad activation phrases such as '记一下' plus any reflective text, which creates a high risk of capturing sensitive thoughts or journaling content without clear user intent. Since the skill appends raw user text to a remote diary service, misfires can leak highly personal content and permanently alter stored records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs users to configure a bearer token but does not pair that with warnings about secret handling, storage, rotation, and the consequences of token compromise. Although merely referencing an environment variable is normal, the absence of credential hygiene guidance increases the chance of accidental exposure or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction states that all colloquial times are parsed using Beijing time (UTC+8), which imposes a specific locale/timezone behavior for all users. The file does not offer a user choice or explain that the skill is limited to a China-specific audience, creating a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The todo-creation triggers are somewhat vague and may match casual requests like '记一个任务', causing unintended task creation. While the data sensitivity is lower than diary content, accidental state changes in a productivity system can still mislead the user or clutter their task list.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The statistics query includes the very broad phrase '今天怎么样', which commonly appears in ordinary conversation and could trigger retrieval of private daily logs unexpectedly. This can expose sensitive behavioral summaries to whoever can observe the interaction, even if no data is modified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.