Back to skill

Security audit

Tasker

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only workflow skill with broad task-management scope, disclosed confirmation gates, and no executable payloads, credentials, or hidden network behavior.

Install only if you want a broad workflow-management skill that can guide agents through coding, ops, review, and planning tasks. For sensitive work, require explicit confirmation before side effects, review any tasker_handoff.md file before another skill uses it, and avoid including secrets, credentials, or sensitive paths in handoff context.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The skill authorizes a general-purpose workflow skill to suggest or trigger other skills and persist a handoff file in the workspace. That expands authority and data flow beyond a narrowly scoped task executor, increasing the chance of unintended capability escalation, cross-skill prompt injection propagation, and unnecessary persistence of sensitive task context.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill advertises itself as suitable for end-to-end task execution across coding, ops, analysis, writing, planning, and review, which makes its invocation scope extremely broad. In an agent ecosystem, such a catch-all scope can cause the skill to be selected for sensitive or high-risk tasks beyond its narrowly defined controls, increasing the chance of unsafe delegation, policy bypass, or over-privileged workflow execution.

Vague Triggers

High
Confidence
95% confidence
Finding
The auto-discovery guidance is intentionally broad and tells the model to infer activation from general intent, tone, and task shape rather than clear boundaries. This makes the skill prone to over-activation, causing it to intercept unrelated requests and apply its own workflow, side-effect, or escalation logic where a narrower skill or direct model response would be safer.

Vague Triggers

High
Confidence
96% confidence
Finding
The primary description and usage scope cover nearly all common agent activities, from coding and ops to analysis, writing, planning, and complaint handling. A skill with such an undifferentiated scope can become a catch-all controller, bypassing safer specialization and increasing the risk that high-impact workflows are handled under overly generic rules.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill treats lack of user response as implicit acceptance, even though the same workflow may involve external side effects or incomplete human review. This can normalize closing risky tasks without explicit confirmation, allowing unreviewed changes to be treated as approved.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The handoff design writes structured task details into the workspace but does not prominently warn the user that task context will be persisted. That creates avoidable confidentiality and retention risk, especially when goals, constraints, paths, or validation data may contain sensitive project information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.