Back to skill

Security audit

cron-precision-scheduler

Security checks across malware telemetry and agentic risk

Overview

This scheduler skill is mostly coherent, but it gives agents broad persistent state and platform-file repair instructions that users should review before installing.

Install only if you are comfortable with a reminder skill that may write persistent timezone memory and guide agents to alter internal scheduler state files. Before using its repair steps, confirm backups and task recreation details, and prefer explicit confirmation before deleting jobs.json or restarting the Agent platform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill goes beyond reminder scheduling and instructs writes to persistent memory and internal state, including modifying MEMORY.md and discussing direct handling of cron state files. That expands its effective privilege boundary from scheduling into persistent configuration/state manipulation, creating unnecessary risk of corruption, unintended persistence, or abuse if invoked in the wrong context.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The troubleshooting guidance tells the agent to back up, delete, or otherwise manipulate internal platform files such as jobs.json under a user path. For a scheduler skill, this is an unjustified maintenance capability that can cause denial of service, loss of scheduled tasks, and unsafe platform-state tampering if followed automatically.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger conditions are overly broad, including common words like '提醒', '定时', and '调度', plus a rule to prioritize this skill whenever such terms appear. This can cause unintended invocation during ordinary conversation, increasing the chance the agent performs scheduling actions or writes state when the user did not explicitly request use of this skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.