Back to skill

Security audit

Cron Scheduler Pro Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local scheduling helper, but users should review scheduled tasks carefully because the agent may later execute whatever task text they configure.

Install only if you are comfortable letting your agent maintain a local schedule file and act on due tasks during sessions. Avoid scheduling deletion, backups, account changes, or external notifications unless the task text is precise and you want the agent to perform it later.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims it is 'local-only' and does not involve cloud calls or extra API keys, yet later states it uses GPT-4o-mini model routing via an LLM API. This inconsistency can mislead users about data flow and privacy boundaries, causing them to disclose sensitive task contents under a false assumption that nothing leaves the local environment.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill includes a scheduled backup workflow that also deletes backups older than 30 days, but it does not prominently warn users that this behavior is destructive. In a scheduling skill, automating deletion increases risk because once configured, removal may occur later without fresh user confirmation, potentially causing irreversible data loss.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.