Back to skill

Security audit

EffortList AI (Organize Your Life /w Safety)

Security checks for vulnerabilities and agentic risk

Overview

This skill is not obviously malicious, but it gives an agent broad EffortList account and scheduling authority, including destructive and externally visible appointment actions that deserve review.

Install only if you intend to let an agent manage your EffortList account, schedules, booking links, and appointments. Use a dedicated API key, avoid broad autonomous use, require confirmation before deletes, booking-link changes, appointment changes, or public-token actions, and revoke the key from the EffortList dashboard if access is no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:121
Finding

Appointment-Control Tokens Exposed in URL Query Strings

Content
View full analysis
` or `/api/v1/public/cancel?token=`. 2. An intermediary or client component records the complete request URL in browser history, access logs, telemetry, tracing data, or support artifacts. 3. An atta ...[truncated 1180 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises itself as managing folders, tasks, and todos, but its documented capabilities also include access to user profile data, availability configuration, booking links, and appointment actions. This scope mismatch can cause an agent or user to invoke the skill under a narrower trust assumption than the actual privileges it exercises, increasing the risk of unintended sensitive operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation language is broad enough to match many generic productivity or scheduling requests, which raises the chance that the skill is selected when the user did not intend to grant access to this platform. In context, that is more dangerous because the skill supports destructive CRUD actions, undo/redo manipulation, profile reads, and scheduling-related updates, so over-selection can lead to unnecessary data access or unwanted modifications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is framed as a productivity organizer, yet it includes booking-link administration and appointment review features that affect external scheduling and potentially third-party interactions. That expanded operational scope makes the skill more dangerous because a user seeking simple task management may not expect actions that can change public availability or accept/decline appointments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation describes destructive and side-effecting behaviors such as cascading deletes, appointment cancellation, rescheduling, and guest email notifications without corresponding warnings or consent guidance. An agent consuming this reference could trigger irreversible or externally visible actions while the user may think they are making a simple organizational edit.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 70)May include surrounding context.

md
### 📋 Tasks

| Method   | Endpoint        | Description | Params / Body                                                                                |
| :------- | :-------------- | :---------- | :------------------------------------------------------------------------------------------- |
| `GET`    | `/api/v1/tasks` | List tasks  | `?id=`, `?folderId=`, `?archived=`, `?limit=`, `?offset=`                                    |
| `POST`   | `/api/v1/tasks` | Create task | `{ "title", "description"?, "folderId"? }`                                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 81)May include surrounding context.

md
### 📋 Tasks

| Method   | Endpoint        | Description | Params / Body                                                                                |
| :------- | :-------------- | :---------- | :------------------------------------------------------------------------------------------- |
| `GET`    | `/api/v1/tasks` | List tasks  | `?id=`, `?folderId=`, `?archived=`, `?limit=`, `?offset=`                                    |
| `POST`   | `/api/v1/tasks` | Create task | `{ "title", "description"?, "folderId"? }`                                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 75)May include surrounding context.

md
| `GET`    | `/api/v1/tasks` | List tasks  | `?id=`, `?folderId=`, `?archived=`, `?limit=`, `?offset=`                                    |
| `POST`   | `/api/v1/tasks` | Create task | `{ "title", "description"?, "folderId"? }`                                                   |
| `PATCH`  | `/api/v1/tasks` | Update task | `?id=` + `{ "title"?, "description"?, "folderId"?, "completionPercentage"?, "isArchived"? }` |
| `DELETE` | `/api/v1/tasks` | Delete task | `?id=<ID>`                                                                                   |

### ✅ Todos

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 79)May include surrounding context.

md
### ✅ Todos

| Method   | Endpoint        | Description | Params / Body                                                                                                                              |
| :------- | :-------------- | :---------- | :----------------------------------------------------------------------------------------------------------------------------------------- |
| `GET`    | `/api/v1/todos` | List todos  | `?id=`, `?taskId=`, `?from=`, `?to=`, `?limit=`, `?offset=`                                                                                |
| `POST`   | `/api/v1/todos` | Create todo | `{ "title", "taskId", "dueDate"?, "endTime"?, "recurrence"?, "isReminder"?, "url"?, "location"?, "ignoreConflicts"?, "isProtectedTime"? }` |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 84)May include surrounding context.

md
| `GET`    | `/api/v1/todos` | List todos  | `?id=`, `?taskId=`, `?from=`, `?to=`, `?limit=`, `?offset=`                                                                                |
| `POST`   | `/api/v1/todos` | Create todo | `{ "title", "taskId", "dueDate"?, "endTime"?, "recurrence"?, "isReminder"?, "url"?, "location"?, "ignoreConflicts"?, "isProtectedTime"? }` |
| `PATCH`  | `/api/v1/todos` | Update todo | `?id=` + `{ "title"?, "taskId"?, "dueDate"?, "endTime"?, "ignoreConflicts"?, "isProtectedTime"?, "location"?, "url"?, ... }`               |
| `DELETE` | `/api/v1/todos` | Delete todo | `?id=<ID>`                                                                                                                                 |

### 📅 Booking Links & Availability

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 88)May include surrounding context.

md
| `GET`    | `/api/v1/todos` | List todos  | `?id=`, `?taskId=`, `?from=`, `?to=`, `?limit=`, `?offset=`                                                                                |
| `POST`   | `/api/v1/todos` | Create todo | `{ "title", "taskId", "dueDate"?, "endTime"?, "recurrence"?, "isReminder"?, "url"?, "location"?, "ignoreConflicts"?, "isProtectedTime"? }` |
| `PATCH`  | `/api/v1/todos` | Update todo | `?id=` + `{ "title"?, "taskId"?, "dueDate"?, "endTime"?, "ignoreConflicts"?, "isProtectedTime"?, "location"?, "url"?, ... }`               |
| `DELETE` | `/api/v1/todos` | Delete todo | `?id=<ID>`                                                                                                                                 |

### 📅 Booking Links & Availability

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The API reference exposes capabilities well beyond the skill’s declared purpose, including availability management, bookings, appointments, and chats. This scope expansion increases the chance that an agent using the skill could perform sensitive actions the user did not reasonably expect from a folders/tasks/todos organizer, creating over-privilege and unintended-action risk.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 90)May include surrounding context.

md
| Method   | Endpoint                      | Description          | Params / Body                                                                                                                                 |
| :------- | :---------------------------- | :------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------- |
| `GET`    | `/api/v1/availability/links`  | List links           | `?id=`                                                                                                                                        |
| `POST`   | `/api/v1/availability/links`  | Create link          | `{ "slug", "title", "linkedTaskId", "duration"?, "durationOptions"?, "meetingType"?, "location"?, "isActive"?, "requireEmailVerification"? }` |
| `PATCH`  | `/api/v1/availability/links`  | Update link          | `{ "id", "title"?, "duration"?, "durationOptions"?, "meetingType"?, "isActive"?, "requireEmailVerification"? }`                               |
| `DELETE` | `/api/v1/availability/links`  | Delete link          | `{ "id" }`                                                                                                                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 93)May include surrounding context.

md
| `GET`    | `/api/v1/availability/links`  | List links           | `?id=`                                                                                                                                        |
| `POST`   | `/api/v1/availability/links`  | Create link          | `{ "slug", "title", "linkedTaskId", "duration"?, "durationOptions"?, "meetingType"?, "location"?, "isActive"?, "requireEmailVerification"? }` |
| `PATCH`  | `/api/v1/availability/links`  | Update link          | `{ "id", "title"?, "duration"?, "durationOptions"?, "meetingType"?, "isActive"?, "requireEmailVerification"? }`                               |
| `DELETE` | `/api/v1/availability/links`  | Delete link          | `{ "id" }`                                                                                                                                    |
| `GET`    | `/api/v1/availability`        | Get settings + links | -                                                                                                                                             |
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 94)May include surrounding context.

md
| `POST`   | `/api/v1/availability/links`  | Create link          | `{ "slug", "title", "linkedTaskId", "duration"?, "durationOptions"?, "meetingType"?, "location"?, "isActive"?, "requireEmailVerification"? }` |
| `PATCH`  | `/api/v1/availability/links`  | Update link          | `{ "id", "title"?, "duration"?, "durationOptions"?, "meetingType"?, "isActive"?, "requireEmailVerification"? }`                               |
| `DELETE` | `/api/v1/availability/links`  | Delete link          | `{ "id" }`                                                                                                                                    |
| `GET`    | `/api/v1/availability`        | Get settings + links | -                                                                                                                                             |
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |
| `POST`   | `/api/v1/availability/blocks` | Block email          | `{ "email", "reason"? }`                                                                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 96)May include surrounding context.

md
| `POST`   | `/api/v1/availability/links`  | Create link          | `{ "slug", "title", "linkedTaskId", "duration"?, "durationOptions"?, "meetingType"?, "location"?, "isActive"?, "requireEmailVerification"? }` |
| `PATCH`  | `/api/v1/availability/links`  | Update link          | `{ "id", "title"?, "duration"?, "durationOptions"?, "meetingType"?, "isActive"?, "requireEmailVerification"? }`                               |
| `DELETE` | `/api/v1/availability/links`  | Delete link          | `{ "id" }`                                                                                                                                    |
| `GET`    | `/api/v1/availability`        | Get settings + links | -                                                                                                                                             |
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |
| `POST`   | `/api/v1/availability/blocks` | Block email          | `{ "email", "reason"? }`                                                                                                                      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 95)May include surrounding context.

md
| `PATCH`  | `/api/v1/availability/links`  | Update link          | `{ "id", "title"?, "duration"?, "durationOptions"?, "meetingType"?, "isActive"?, "requireEmailVerification"? }`                               |
| `DELETE` | `/api/v1/availability/links`  | Delete link          | `{ "id" }`                                                                                                                                    |
| `GET`    | `/api/v1/availability`        | Get settings + links | -                                                                                                                                             |
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |
| `POST`   | `/api/v1/availability/blocks` | Block email          | `{ "email", "reason"? }`                                                                                                                      |
| `DELETE` | `/api/v1/availability/blocks` | Unblock              | `?email=`                                                                                                                                     |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 97)May include surrounding context.

md
| `GET`    | `/api/v1/availability`        | Get settings + links | -                                                                                                                                             |
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |
| `POST`   | `/api/v1/availability/blocks` | Block email          | `{ "email", "reason"? }`                                                                                                                      |
| `DELETE` | `/api/v1/availability/blocks` | Unblock              | `?email=`                                                                                                                                     |

### 🤝 Appointments (Host Actions)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/api.md (reported line 98)May include surrounding context.

md
| `PATCH`  | `/api/v1/availability`        | Update settings      | `{ "weeklySchedule", "timezone", "minimumNotice"? }`                                                                                          |
| `GET`    | `/api/v1/availability/blocks` | List blocks          | -                                                                                                                                             |
| `POST`   | `/api/v1/availability/blocks` | Block email          | `{ "email", "reason"? }`                                                                                                                      |
| `DELETE` | `/api/v1/availability/blocks` | Unblock              | `?email=`                                                                                                                                     |

### 🤝 Appointments (Host Actions)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Chat deletion is unrelated to the stated purpose of managing folders, tasks, and todos, yet it permits destructive actions against another data domain. This mismatch raises the risk of accidental or abusive deletion of conversational records by an agent operating under a seemingly narrower mandate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Public booking and appointment endpoints enable external-party scheduling flows that affect people beyond the authenticated user, including appointment creation, rescheduling, cancellation, and OTP verification. In the context of a personal organization skill, this expands impact from private task management into externally visible actions and can lead to misuse, spam, or unauthorized scheduling changes if exposed through the agent without tight controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.