Task Management

Security checks across malware telemetry and agentic risk

Overview

This is a task-management methodology skill made of Markdown guidance, with no executable code, network behavior, credential use, or hidden persistence.

Before installing, expect this skill to make the agent more structured about plans, task lists, status updates, and dependencies. If you use common words like "todo" or "计划" often, it may activate more frequently than you expect, but the reviewed artifacts do not show hidden code execution, data access, or external communication.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger list includes very broad, everyday terms such as "todo" and "计划" that are likely to appear in many ordinary conversations. This can cause unintended invocation of the skill, leading the agent to switch into task-management behavior when the user did not explicitly request it, which may alter outputs, create unwanted state, or interfere with safer/more relevant skills.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal