Back to skill

Security audit

Tasker

Security checks for vulnerabilities and agentic risk

Overview

This is a broad but transparent workflow-guidance skill with no executable payload, credential access, or hidden persistence found in the inspected artifacts.

Install this if you want a broad, opinionated workflow layer that may activate for many task types. Review the auto-discovery breadth and bilingual templates, and rely on the skill's confirmation gates before allowing it to perform file changes, ops actions, multi-agent handoff, or scheduled-task delegation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · RELEASE_v1.2.0.md (reported line 37)May include surrounding context.

md
#### 3. Context-Aware Risk Sizing (Intent + Modifiers)
- **Base:** Keyword-weighted S/M/L scoring (unchanged).
- **New modifiers:** `Session Context` (parent task level, prior failures), `Path Modifier` (sensitive directories like `config/`, `.env/`, `ssh/`), and `User Modifier` (production mentions, user downgrades).
- Reduces false positives (e.g., "modify login page color" was L, now correctly manageable) and catches hidden risks (e.g., "view this file" pointing to `/etc/passwd`).

#### 4. Dissatisfaction Root-Cause Classification & Improvement Tracking
- **5 dissatisfaction classes:** Result Error, Process Error, Comprehension Error, Communication Error, Performance Error.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

md
#### 3. Context-Aware Risk Sizing (Intent + Modifiers)
- **Base:** Keyword-weighted S/M/L scoring (unchanged).
- **New modifiers:** `Session Context` (parent task level, prior failures), `Path Modifier` (sensitive directories like `config/`, `.env/`, `ssh/`), and `User Modifier` (production mentions, user downgrades).
- Reduces false positives (e.g., "modify login page color" was L, now correctly manageable) and catches hidden risks (e.g., "view this file" pointing to `/etc/passwd`).

#### 4. Dissatisfaction Root-Cause Classification & Improvement Tracking
- **5 dissatisfaction classes:** Result Error, Process Error, Comprehension Error, Communication Error, Performance Error.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares an extremely broad purpose spanning execution, debugging, analysis, planning, review, and user dissatisfaction handling, making it eligible for a very large fraction of ordinary interactions. In systems with automatic skill routing, this increases the chance the skill is invoked when a narrower, safer skill should have been used, expanding attack surface and enabling unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The auto-discovery section tells the model to infer intent from tone, context, and task shape across a wide range of generic verbs and emotional states. This broad inferred-trigger design can cause the skill to activate opportunistically for normal conversation, complaints, or vague requests, which is dangerous because the skill also contains execution logic and side-effect handling guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The release note describes Tasker as a general workflow skill for coding, ops, analysis, writing, planning, review, and dissatisfaction handling, which creates an extremely broad invocation scope. In agent ecosystems, overbroad skills can capture tasks outside their safe competence boundary, increasing the chance of unsafe delegation, excessive authority assumptions, or misuse in sensitive workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description forces bilingual output/content in English and Chinese, and similar mixed-language directives appear throughout the file, but there is no statement that language should follow user preference. This can violate language or locale policy when users have not opted into bilingual or Chinese content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.