Back to skill

Security audit

Todo Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a local todo/reminder skill whose file storage, heartbeat reminders, and cleanup behavior are mostly disclosed and aligned with its purpose, with one retention bug users should understand.

Install only if you are comfortable with the agent storing reminder text and context in memory/todo.json and checking it during heartbeat runs. Review the routing phrases and fix or account for the cleanup bug before relying on 24-hour deletion of cancelled items.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/todo-cleaner.py:72
Finding

Cancelled Todo Records Are Not Deleted After the Documented Retention Period

Content
View full analysis
Remediation
View remediation
'), 'terminal_at': terminal_at_str, 'error': str(e), }) to_keep.append(item) ``` Additional hardening should include: 1. Add tests for expired and recent `completed` records. 2. Add tests for expired and recent `cancelled` records. 3. Validate that each terminal status has its corresponding timestamp. 4. Report malformed terminal records clearly without deleting them silently. 5. Restrict permissions on `memory/todo.json` because its descriptions and context may contain sensitive user information. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is reminder/follow-up management, but the skill behavior includes persistent storage mutation and automatic deletion of items, while providing no concrete heartbeat trigger or reminder mechanism. This mismatch can mislead users and host agents about what the skill actually does, causing silent data loss or unauthorized state changes under the guise of a simple reminder tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises autonomous reminder behavior and persistent JSON storage but does not disclose data retention, local file modification, or consent expectations. In an agent skill, this can lead users or deployers to unknowingly allow ongoing storage of potentially sensitive follow-up items and background-triggered actions, increasing privacy and integrity risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The usage example shows both user and agent communication entirely in Chinese, which can indicate a language-specific behavior or expectation. Because the README does not say the skill is region-specific or that users may choose their preferred language, this conflicts with the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs reading and writing persistent workspace data (memory/todo.json) and references a cleanup script, but it declares no explicit tool scope or permissions. This creates a trust and authorization gap: an agent may perform file operations users did not clearly consent to, increasing the risk of unintended data exposure or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation guidance is broad and ambiguous, effectively saying to use the skill whenever users mention reminders, follow-ups, or todos, plus unspecified heartbeat checks. Weak trigger boundaries make over-invocation more likely, which in this skill is risky because invocation can lead to persistent storage writes and eventual deletion behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions and headings for operational guidance are written in Chinese, with no indication that the user can choose another language. This can violate language/locale policy if the skill implicitly constrains interaction to one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill stores all items in persistent memory and automatically deletes completed/cancelled items after 24 hours, yet the description does not clearly warn users about retention and deletion. In a todo context, users may reasonably expect their reminders to persist unless told otherwise, so omission of this behavior can cause unexpected loss of records and privacy concerns around stored task content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples explicitly show persistent storage in todo.json and heartbeat-based autonomous reminders, but they provide no disclosure, consent flow, or retention guidance. This can mislead users about background behavior and data persistence, creating privacy and transparency risks if personal follow-up items are stored or surfaced later without clear expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The heartbeat instructions specify automatic deletion of completed or cancelled todo items after 24 hours, but the setup guide does not require explicit user notice, consent, or retention configuration. This creates a real risk of silent data loss, especially because heartbeat automation may run routinely without the user realizing historical task records will be removed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The routing table includes very broad, common phrases such as '提醒我', '跟进', '别忘了', and '待办', which can cause the skill to activate in situations the user did not intend. In an agent environment, overly generic triggers can lead to misrouting of user requests, unintended reads or writes to memory/todo.json, and confusion about which skill is handling sensitive task data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user and agent examples are presented exclusively in Chinese, and the reminder address form on L17 suggests a fixed language/persona style without any indication that users can choose another language. The policy requires flagging language or locale constraints when the skill appears to enforce them without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains its description, comments, argparse help text, and printed status/error messages in Chinese only. The policy for natural-language issues applies to all file types, and there is no indication that the skill offers a language/locale choice or that the locale restriction is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.