Back to skill

Security audit

cron-mastery

Security checks across malware telemetry and agentic risk

Overview

This scheduling skill is not malicious, but it asks agents to create persistent reminders, send external messages, and perform broad troubleshooting actions with overly broad activation rules.

Review this before installing if you do not want broad reminder-related phrases to activate a persistent scheduler. Use it only where agents are allowed to create and clean up cron tasks, write timezone preferences to memory, and send messages to configured enterprise chat recipients; require confirmation for external delivery and platform-state repair steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Including restart and filesystem-maintenance instructions normalizes privileged operational actions that exceed the stated purpose of scheduling reminders. In an agent with Bash/Write/Edit access, this broadens the path from a simple reminder request to service-affecting actions, increasing the chance of misuse or harmful automation.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Including restart and filesystem-maintenance instructions normalizes privileged operational actions that exceed the stated purpose of scheduling reminders. In an agent with Bash/Write/Edit access, this broadens the path from a simple reminder request to service-affecting actions, increasing the chance of misuse or harmful automation.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases include very common words such as '提醒', '定时', '调度', and related everyday scheduling language, making unintended invocation likely. This is dangerous because the skill has write, edit, bash, memory-modification, and external delivery behaviors, so accidental activation can lead to file changes, persistent tasks, or outbound messages without clear user intent.

Vague Triggers

High
Confidence
96% confidence
Finding
The forced-trigger rule tells the agent to prioritize this skill whenever generic scheduling-related words appear and to default into cron mode for broad time expressions. That ambiguity creates an overreach vulnerability: ordinary conversation can be converted into persistent scheduled actions, especially dangerous given the skill's ability to write MEMORY.md and send messages to external channels.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill can write timezone data to MEMORY.md and send messages through enterprise chat platforms, but it does not prominently warn users about persistence, recipients, or privacy implications. Without clear disclosure and consent, users may not realize their data is being stored locally or delivered externally, increasing the risk of privacy leaks and unintended disclosure.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.