Back to skill

Security audit

定时调度专家

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a local scheduler rather than malware, but its broad activation scope, command/file authority, persistent jobs, auto-cleanup, and mixed API-key guidance should be reviewed before installation.

Install only if you want an agent to maintain a local recurring-job database and potentially execute scheduled tasks later. Review the exact jobs, storage path, cleanup policy, timezone, and any API credentials used by downstream tasks; avoid high-stakes unattended actions until scope and confirmation controls are tightened.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill gives contradictory guidance about whether API keys are required, which can mislead operators about the trust boundary and data flows involved. In a scheduling skill that may trigger downstream tasks, this confusion can cause unsafe deployment, accidental credential exposure, or use in environments where network/API access was assumed absent.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill is presented as local-first and cloud-independent, but other sections imply built-in API/network-oriented capabilities and troubleshooting paths. This inconsistency obscures the actual attack surface and may cause users to grant network trust or permissions under false assumptions about purely local operation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance is overly broad and can cause the skill to activate in general AI/LLM development contexts unrelated to cron scheduling. Because the skill has exec and write capabilities, over-triggering increases the chance of unnecessary command execution, filesystem modification, or user confusion about why a scheduler is being invoked.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The keyword-based scope is vague and expansive, making it difficult to predict when the skill should engage. In a skill that can write files and execute commands, ambiguous scope raises the risk of unintended activation and actions outside the user's actual request.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The markdown describes local file creation, modification, archival, and deletion behavior without a prominent user-facing warning. Users may not realize the skill persists data under their home directory and may automatically delete archived items, which can lead to unexpected data loss or policy violations.

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill declares exec and write tool usage but does not provide a concise upfront warning that it may run commands and modify the filesystem. In practice, this reduces informed consent and can lead users or calling agents to invoke a capability with stronger side effects than expected.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.