Back to skill

Security audit

Agent Autonomy Kit

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly about autonomous agent work, but it recommends persistent unattended scheduled runs without enough safeguards or cleanup guidance.

Install only if you intentionally want autonomous scheduled agent work. Before enabling the cron examples, restrict what queued tasks may do, require confirmation for external messages, agent spawning, destructive changes, or sensitive data access, set your own timezone and active hours, and document how to list and remove every scheduled job.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
README.md:311
Finding

Persistent Unattended Agent Execution Through Scheduled Jobs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to configure cron-triggered autonomous work sessions that run without a human prompt, including overnight execution and task selection. In an agent-autonomy skill, unattended operation materially increases the risk of unintended actions, unauthorized external communications, excessive resource consumption, and unsafe task execution unless there are strong scope limits, approval gates, and prominent warnings.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description "Stop waiting for prompts. Keep working." encourages autonomous behavior without stating any boundaries, approval requirements, or stopping conditions. In agent environments, vague activation language can cause unintended invocation or over-broad operation beyond the user's current intent, increasing the risk of unauthorized actions or resource misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly promotes proactive and continuous work ("Do work, don't just check" and "Work until limits hit") without documenting safeguards, human approval gates, or operational boundaries. This makes the context more dangerous than a normal productivity skill because it normalizes persistent autonomous execution, including cron-driven operation, which can lead to unintended actions, runaway task execution, or activity outside the user's expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The template explicitly instructs the agent to read, modify, and update project files (tasks/QUEUE.md, memory/YYYY-MM-DD.md, and the task queue) during idle time without any safety guardrails about scope, authorization, or preserving user/project data. In an autonomy-oriented skill, this can normalize unsupervised file changes and cause accidental corruption, inappropriate edits, or persistence of misleading state, especially when the agent acts without a fresh user prompt.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The cron examples hard-code the time zone to America/Vancouver without instructing the user to choose their own locale. This can cause autonomous jobs to execute at unexpected local times, which is especially risky in a skill designed for unattended operation because actions may occur outside intended business hours or supervision windows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.