Back to skill

Security audit

dida365-ticktick-agent

Security checks across malware telemetry and agentic risk

Overview

This appears to be a task-account integration with expected credentials and task changes, but users should treat the copied session cookie as highly sensitive.

Install only if you expect this skill to access and modify your task account. Do not paste the session cookie into shared terminals, scripts, logs, screenshots, or shell history; remove stored credentials when finished and prefer a test or low-risk account if available.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs users to extract a live session cookie from browser developer tools and store authentication material for CLI use, but it provides no guidance on treating these values as secrets, avoiding shell history leakage, or using safer auth flows. Session cookies and client credentials can enable account takeover or unauthorized API access if exposed through terminal history, logs, screenshots, shared shells, or wrapper scripts.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The documented commands perform state-changing operations against the user's remote task account, including creating tasks, completing tasks, and syncing all data, yet the skill does not clearly warn that these actions modify live account data. In an agent or automation context, this raises the risk of unintended writes, destructive mistakes, or surprising account changes if commands are run without confirmation or clear user awareness.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.