Back to skill

Security audit

个人日程秘书

Security checks across malware telemetry and agentic risk

Overview

This appears to be a task-organization skill that writes local task files as part of its intended workflow, but users should invoke it explicitly because its trigger is broad.

Install if you want an agent to maintain local task-management files. Use explicit task-focused prompts, keep the inbox/workspace scope clear, and review planned file changes before allowing large reorganizations or archive updates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "帮我整理一下" is overly generic and can easily appear in ordinary conversation unrelated to task management. That creates a real risk of unintended skill activation, after which the skill may begin scanning inbox content and modifying task, index, dashboard, archive, and log files without the user explicitly asking for those filesystem operations.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill is designed to create and modify multiple files across the workspace, including archiving and updating embedded data, but it does not require clear user disclosure or confirmation before performing those writes. In the context of a broadly triggered personal assistant skill, this increases the chance of silent or surprising persistence, accidental data alteration, and hard-to-notice workspace changes.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.