Back to skill

Security audit

Productivity Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a local task, pomodoro, and habit tracker whose file writes and delete behavior match its stated purpose.

Install only if you are comfortable with a Chinese-language local tracker that stores its data in ~/.task-tracker. Be aware that the delete command removes local task entries immediately and does not ask for confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill title, description, usage examples, and commands are all presented only in Chinese, which indicates a fixed language/locale for interaction. There is no indication that users may choose another language or that the Chinese-only constraint is justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest’s natural-language fields, including the top-level description and every command description/usage, are written only in Chinese. For a general-purpose task tracker, this imposes a specific language/locale without any opt-in, alternative locale, or stated region-specific justification, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Docstrings, help output, and status messages are presented in Chinese, and the script does not provide any user opt-in or alternative locale selection. This can violate language or locale policy when tools are expected to avoid forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete_task function irreversibly removes a task entry from the local tasks file, but it does so immediately after receiving the task ID. Although it prints a message after deletion, there is no confirmation prompt or pre-action warning before the destructive operation occurs.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/task-tracker.py (reported line 161)May include surrounding context.

python
return
    
    # 更新连续天数
    yesterday = (date.today() - __import__('datetime').timedelta(days=1)).isoformat()
    if habit.get("last_check") == yesterday:
        habit["streak"] += 1
    else:

Static analysis

No suspicious patterns detected.