Back to skill

Security audit

stand up reminder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed stand-up reminder workflow that creates ongoing cron reminders, with no bundled code, credential access, or hidden data handling found.

Before installing, make sure you want an ongoing cron reminder, check the default timezone/language and work hours, and use the documented list, update, pause, or remove commands if the reminders are no longer wanted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes common, everyday phrases such as '提醒我站起来' and '健康提醒' that could plausibly appear in normal conversation outside an explicit request to install or configure this skill. That can cause unintended activation and automatic creation of recurring cron reminders, which is a real safety and UX issue even though it does not appear malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises activation via natural phrases like "提醒我每小时站起来活动一下" and similar broad variants, but it does not define clear invocation boundaries or require explicit confirmation before creating a persistent cron reminder. This can cause accidental triggering during ordinary conversation or when discussing reminders hypothetically, leading to unintended scheduled actions that persist beyond the current interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list ends with an open-ended “等”, which makes the activation scope ambiguous and can cause the skill to match broader phrases than users expect. In a skill that creates persistent cron jobs automatically, over-broad triggering increases the chance of unintended task creation and user surprise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to automatically create a persistent weekday cron task, but the description does not clearly warn the user that this will install an ongoing scheduled action on their system/account. This creates a consent and persistence risk: users may invoke the skill casually without realizing it will continue to run and generate reminders until manually removed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance hard-codes Chinese holiday rules and a Chinese-language reminder in the execution payload without requiring explicit user selection of locale, country, or language. This can cause the agent to apply the wrong work/holiday calendar or send reminders in an unexpected language, creating incorrect automation behavior and potentially exposing sensitive assumptions about the user's region or preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document sets the default language to zh (Chinese) even though the skill supports multiple languages. This imposes a language preference by default rather than explicitly asking the user or obtaining opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.