Back to skill

Security audit

个人待办管理

Security checks for vulnerabilities and agentic risk

Overview

This is a file-backed personal todo skill whose writes, deletes, and optional GitHub/path tracking fit its stated purpose, though users should be careful with broad triggers and deletions.

Install this if you want a Chinese-language todo manager that stores task data in JSON files in the current workspace. Avoid putting sensitive local paths or private issue links into tasks unless you are comfortable storing them there, and use precise item names or IDs for delete/status changes because fuzzy matching and immediate deletion can remove the wrong todo.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common conversation about tasks, plans, or TODOs, which can cause the skill to activate when the user did not explicitly intend to use a file-writing task manager. In this skill, unintended activation is more dangerous because the documented workflow includes creating, moving, and deleting records in workspace files, so an ambiguous invocation could lead to unwanted state changes or data creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill performs persistent writes and deletions in workspace JSON files, but the user-facing description does not clearly warn that invoking the skill will modify stored data. This reduces informed consent and increases the chance that users trigger destructive operations such as deletion or status transitions without realizing the skill maintains persistent state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example documents capabilities beyond simple todo management by collecting GitHub issue links and probing local git repositories/branches from user-supplied paths. This expands the skill’s effective scope into repository inspection and local environment discovery, which increases privacy and capability risk if implemented without explicit consent, documentation, and access controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The examples show the skill accepting a local filesystem path and then automatically detecting whether it is a git project and what branch is checked out. Even if only metadata is read, this is local environment enumeration unrelated to core todo storage and can expose sensitive project names, directory layouts, and workflow state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The deletion flow removes a todo immediately after a natural-language request with no confirmation or undo step. This makes the skill vulnerable to accidental, ambiguous, or injected deletion requests, leading to integrity loss of user task data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains all user-facing documentation in Chinese, with no note that the skill supports multiple languages or that Chinese is an intentional, opt-in locale choice. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

All user and assistant examples are presented exclusively in Chinese, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Manifest 触发场景只列出新增、查看列表、开始/完成/删除、标记状态等基础待办操作,没有提到统计汇总或分析查询。示例增加了按状态占比和本周完成数的统计输出,说明技能范围比声明更宽。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.