Back to skill

Security audit

cron表达式助手(专业版)

Security checks for vulnerabilities and agentic risk

Overview

This cron helper is mostly documentation, but it asks for broad agent tools and uses an overly broad trigger that could activate it outside cron-related tasks.

Review this skill before installing. It appears to be a cron-expression assistant rather than malware, but its activation scope should be narrowed to cron tasks and its requested tools should be reduced or clearly justified. Do not rely on the stated command or network safety claims unless the publisher adds actual enforcement details.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill's security section claims command-execution whitelisting and HTTPS-based network protections, but the documented implementation does not actually enforce those controls. This creates a trust gap: integrators may rely on non-existent safeguards and expose Bash or callback behavior under false assumptions, increasing the chance of unsafe deployment or misuse.

Vague Triggers

High
Confidence
95% confidence
Finding
The description includes a very broad trigger phrase such as using the skill whenever AI models, agent orchestration, or LLM applications are involved, which is unrelated to cron-specific functionality. In agentic systems this can cause the skill to be selected in many unintended contexts, unnecessarily granting access to sensitive tools like Read, Write, Edit, and Bash and expanding the attack surface.

Static analysis

No suspicious patterns detected.