Back to skill

Security audit

推送到负一屏

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it advertises by pushing task results to a phone-facing surface, but it also forces scheduled-task pushes without confirmation and exposes serious command-injection and data-leakage risks.

Review carefully before installing. Only use this in an environment where automatic scheduled-task result pushing is intended, avoid sending secrets or private content, disable DEBUG, configure only a trusted HTTPS API endpoint, and prefer a version that avoids shell interpolation and asks for confirmation before sending scheduled-task outputs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:112
Finding

Mandatory Automatic Transmission of Scheduled-Task Data Without User Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools.json:6
Finding

Shell Command Injection Through Unescaped Tool Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cli.js:57
Finding

Authentication Token Exposed in Debug Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cli.js:61
Finding

Authentication Token and Task Data Can Be Sent to an Untrusted or Plaintext Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:23
Finding

Unpinned Package Execution Through npx Compilation Instructions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad activations such as “推送到手机”, which can plausibly match ordinary user conversation and cause the agent to invoke an external-push skill unexpectedly. Because this skill transmits task results and identifiers to an external API, accidental activation can lead to unintended data disclosure or user actions without sufficiently explicit consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes the outbound API payload, including auth token use, message content, message IDs, schedule task identifiers, and task names, but it does not clearly warn users that invoking the skill sends this data to an external service. In a skill whose purpose is exfiltration-by-design to a third-party endpoint, missing disclosure materially increases privacy and consent risk and makes accidental leakage from broad triggers more dangerous.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill uses environment variables for authentication and performs outbound result pushing, but it does not declare any explicit tool scope or permission boundary. That makes the skill's effective capabilities less transparent to users and reviewers, increasing the chance that networked data exfiltration occurs without appropriate scrutiny or policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several trigger phrases are broad enough to match ordinary conversation, such as generic references to pushing to a phone or the phone's Today screen. This increases the likelihood of accidental activation, which in this skill directly leads to transmitting task results externally and therefore raises the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates automatic pushing of scheduled task results to a phone-facing surface without any user-facing notice, opt-in, or privacy warning. Scheduled tasks often process summaries, reports, or other sensitive content, so silently transmitting those results creates a real privacy and data-leakage risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs automatic pushing of full task results from session context to a phone-visible destination, without confirmation or content sensitivity checks. Because session results may contain secrets, personal data, internal analysis, or security findings, this creates a natural-language exfiltration path from the assistant context to an external surface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command description, option help text, and later validation require Chinese-only strings such as '任务执行成功' and '任务执行失败'. This imposes a specific language/locale on all users with no alternative or opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill transmits user-supplied task content, summary, identifiers, and an auth code to an external endpoint, and the destination can be overridden via AS_TODAY_API_URL without any validation or allowlist. In this skill's context, outbound transmission is expected, but the combination of sensitive payload contents and unrestricted endpoint selection increases the risk of accidental or malicious exfiltration to an attacker-controlled server.

Content

Scanner excerpt · scripts/cli.js (reported line 60)May include surrounding context.

js
console.error('[DEBUG] 请求 Payload:');
        console.error(JSON.stringify(payload, null, 2));
    }
    const apiUrl = process.env.AS_TODAY_API_URL || 'https://api.example.com/push2today';
    try {
        console.error('正在推送至负一屏...');
        const response = await fetch(apiUrl, {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This manifest defines a shell-executed tool that pushes task execution results to another surface and invokes a Node CLI, but the description only states what it does and does not warn that it executes a shell command or transmits task content. For manifest files, SQP-1 applies but SQP-2 does not directly; however the user asked to analyze this skill file, and the missing disclosure is evident in the natural-language description associated with the tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a result-pushing skill, but this file additionally depends on reading an auth token from process environment state. While authentication may support the push operation, accessing environment-held credentials is a separate capability not reflected in the stated purpose and can exceed user expectations about what the skill touches.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The only natural-language description for the tool is in Chinese and the result enum values are fixed Chinese strings, which suggests a locale-specific behavior without any opt-in or justification. Under the policy rule, forcing a specific language or locale can be a violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/cli.js:23