Back to skill

Security audit

chore-wheel-genius

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local household chore scheduler whose file use and behavior match its stated purpose.

Reasonable to install if you want a local chore-tracking CLI. Be aware it stores household names, ages, skills, assignments, and skip reasons in plaintext at ~/.chore_wheel.json, and review age-based chore suggestions yourself before assigning chores involving cooking, tools, chemicals, pets, or childcare.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes a command-line tool that reads and writes local state (~/.chore_wheel.json) but does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap: an agent/runtime may grant broader file access than the skill actually needs, increasing the chance of unintended local file reads or writes if the skill is invoked in a more privileged environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide assigns potentially hazardous chores to minors, including cooking, bathroom cleaning, yard work, minor home repairs, babysitting, and walks with pets, but provides little or no explicit safety precautions beyond a few scattered notes such as 'with supervision' or 'with direction' for younger children. In a household-assignment tool, users may treat these recommendations as authoritative defaults, which can normalize unsafe task assignment and increase risk of injury, chemical exposure, or inadequate supervision.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage string says skip <member> <chore> <reason>, implying the chore and reason are distinct arguments. But the implementation sets chore = " ".join(args[1:]), so the reason text is included in the chore match, making the documented invocation fail for multiword reasons and contradicting the advertised command behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring advertises assign [weeks], suggesting callers can request assignments for multiple weeks or a specified week range. The actual cmd_assign function does not read args at all and always uses week_key(0), so the documented interface contradicts the real behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.