Back to skill

Security audit

Auto Loop

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent task-scheduling skill with local state persistence, but users should be careful with recurring or retrying tasks that have side effects.

Install only if you want a Chinese-language scheduling utility. Review any task before making it recurring, especially tasks that send messages, change files, call APIs, delete data, or spend money, because retries and recovery can repeat side effects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary descriptive content is presented in Chinese, and the README does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language context. This creates a natural-language policy issue because the skill documentation effectively imposes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description omits warnings that scheduled execution, retries, and automatic recovery can re-run tasks and mutate data or external systems without real-time user oversight. This is risky in context because recurring automation can amplify the effect of a mistaken task, causing repeated writes, notifications, deletions, purchases, or other persistent side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation conditions are very broad and overlap with ordinary user requests for scheduling or automation, which can cause the skill to activate in contexts where the user did not intend to invoke persistent or recurring behavior. In a scheduling skill, ambiguous triggering is dangerous because it may initiate repeated actions, retries, or monitoring loops that affect system state or user data over time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example invocation phrases are generic enough to match common natural-language requests, increasing the chance that the skill will intercept ordinary task requests and convert them into scheduled or repeated execution. Because this skill supports retries and automatic recovery, accidental activation could lead to unintended repeated operations rather than a one-time action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language interface is written entirely in Chinese, including the module description and later CLI/help text, with no option for users to select another language. This is a language/locale policy concern because the skill imposes a specific language rather than offering opt-in or documenting a justified region-specific restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's operational headings and instructions are written in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline comment at L911 says the demo adds a task that executes every second, but the actual call at L912 uses an interval of 5000 milliseconds, which is every five seconds. This is a direct contradiction between documentation/commentary and implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JavaScript test file contains multiple user-visible strings exclusively in Chinese, including the file header and console output messages. Because the file provides no opt-in, fallback, or justification for the locale restriction, it may violate a language/locale policy requiring user choice or documented constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.