Back to skill

Security audit

HZL

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with its task-ledger purpose, but it includes instructions for an always-on network-reachable dashboard that can persist after logout.

Review before installing. Use the basic hzl CLI only if you want a persistent task ledger. Do not let an agent enable the always-on dashboard, systemd service, login lingering, gateway, or cloud sync unless you explicitly need those features and have checked host binding, authentication, token handling, and how to disable the service. Prefer verified or pinned package versions where possible.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
SKILL.md:369
Finding

Persistent Always-On Web Service Enabled Across Login Sessions

Content
View full analysis
~/.config/systemd/user/hzl-web.service systemctl --user daemon-reload systemctl --user enable --now hzl-web loginctl enable-linger $USER ``` ### Technical Analysis The documented procedure creates a systemd user unit, reloads the user service manager, enables and immediately starts the HZL web service, and then enables lingering for the current user. Enabling lingering allows the user's systemd service manager to remain active when the user is not logged in. Consequently, the HZL web server can continue running after the initiating agent session or interactive login has ended and may start again on subsequent boots. Although the section describes this as an always-on dashboard configuration, these commands establish cross-session persistence. The instructions do not require an explicit confirmation immediately before enabling persistence, do not restrict the generated service to the loopback interface, and do not document authentication requirements or a removal procedure. ### Attack Path 1. An agent loads the skill and follows the “Web dashboard (always-on, Linux)” procedure. 2. `hzl serve --print-systemd` generates a user service definition. 3. The generated definition is written to `~/.config/systemd/user/hzl-web.service`. 4. `systemctl --user enable --now hzl-web` enables the service for future starts and starts it immediately. 5. `loginctl enable-linger $USER` permits the user service manager and the HZL service to remain active without an interactive login. 6. The service persists beyond the skill run and may expose the task ledger or connected gateway functionality for as long as it remains enabled. ### Impact Assessment The resulting service runs with the privileges of the affected user rather tha ...[truncated 488 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned Executable Dependencies Installed from Mutable Package Registries

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
| Command | Effect |
|---------|--------|
| `hzl init --force` | **DELETES ALL DATA.** Prompts for confirmation. |
| `hzl init --force --yes` | **DELETES ALL DATA WITHOUT CONFIRMATION.** |
| `hzl task prune ... --yes` | **PERMANENTLY DELETES** old done/archived tasks and history. |

**Never run these unless the user explicitly asks you to delete data. There is no undo.**

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

Workflow commands (HZL v2+)

bash
# Hand off to another agent or pool — complete current, create follow-on atomically
hzl workflow run handoff \
  --from <task-id> \
  --title "<new task title>" \

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest frames HZL as a persistent task ledger for planning, checkpointing, and coordinating agents. However, the skill documentation also instructs use of webhook delivery, websocket gateway connections, and optional cloud database sync, which extend behavior beyond a purely local ledger into networked notification and remote synchronization features.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs enabling a persistent systemd user service and lingering, which causes the dashboard to survive session termination and system logout. In an agent-execution context, this creates unauthorized persistence and expands attack surface by keeping a service continuously available, especially because the dashboard is later described as reachable over the network.

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

bash
hzl serve --print-systemd > ~/.config/systemd/user/hzl-web.service
systemctl --user daemon-reload
systemctl --user enable --now hzl-web
loginctl enable-linger $USER

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The introductory documentation characterizes HZL as a 'local-first task ledger', which implies primarily local operation. Later sections document exposing a web dashboard over the network, connecting to a gateway, and syncing to a remote libsql/Turso instance, creating a tension with the earlier characterization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.