Back to skill

Security audit

Cron 精确调度

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent scheduling/reminder helper, but it asks agents to use broad scheduling authority and includes unsafe recovery/elevation guidance that users should review before installation.

Install only if you are comfortable with an agent creating and managing scheduled tasks. Before use, require explicit confirmation for creating, changing, or deleting jobs; avoid following the state-file deletion and administrator-running advice unless an administrator has reviewed the exact path, backup, and recovery plan.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:35
Finding

Overbroad Trigger Rules Can Hijack Skill Selection

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:123
Finding

Persistent Timezone Writes Can Poison Future Scheduling State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:138
Finding

Destructive Scheduler Recovery Can Delete Unrelated Tasks

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:364
Finding

Generic Administrator Execution Advice Violates Least Privilege

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The activation criteria are broad enough to match common conversational words like '提醒', '定时', or '调度', making unintended invocation likely. Over-broad triggering increases the chance that the skill takes over unrelated tasks and applies scheduling behaviors or tool usage where the user did not want them.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The forced activation rule mandates priority invocation for ambiguous keywords and prescribes behavior changes such as banning act:wait in certain cases. This reduces agent discretion and can cause the skill to override safer or more appropriate workflows based on weak lexical matches.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The troubleshooting flow recommends deleting local state files without a prominent warning that this may destroy scheduled jobs and require manual reconstruction. In a tool-enabled agent environment, such instructions can directly lead to irreversible data loss from routine support interactions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill branding, description, and examples are written as if the skill is inherently for Chinese-language and China-oriented messaging platforms, but there is no opt-in or alternative locale/language path. This can violate language/locale policy when a skill implicitly forces a specific language or regional workflow without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs storing user timezone data in MEMORY.md without clear notice, consent, retention limits, or scope controls. Although timezone is not highly sensitive by itself, persistent storage of user attributes in shared memory can create privacy and context-leakage risks across future sessions or tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill goes beyond reminder guidance and instructs operators to back up and delete local cron state files and restart the platform. In an agent context with Bash/Write/Edit tools, this can cause accidental destructive maintenance actions, loss of scheduled jobs, and unsafe normalization of direct state-file manipulation without guardrails or validation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The FAQ introduces OS-level cron/crontab and @reboot guidance even though the skill says it only operates within the Agent platform. That mismatch can cause an agent or user to apply instructions to the host system, expanding scope from in-platform scheduling to system-level persistence and task execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document presents conflicting execution models, describing both command-execution capability and pure Markdown guidance. This ambiguity can mislead an agent into taking more privileged actions than intended, especially when the skill advertises Bash access elsewhere.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Persisting timezone in shared memory creates a retention and cross-context privacy risk because user attributes may be reused beyond the immediate scheduling task. In isolation the sensitivity is low, but the pattern normalizes storing personal context without lifecycle controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.