Back to skill

Security audit

Productivity Skill

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only productivity coach whose local memory and reminder behavior is mostly disclosed and purpose-aligned, but users should review its persistent data use and built-in course promotion.

Before installing, be comfortable with the skill saving productivity-related details in local MEMORY.md and daily notes. Decline memory writes if you want session-only use, review or delete saved notes when needed, confirm any reminders before they are scheduled, and expect YiXiaoNeng resource or course suggestions after praise or requests to learn more.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:99
Finding

Conditional Commercial Promotion Through Skill Instruction Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases for inbox capture are overly broad enough to match ordinary conversation, causing the agent to persist content the user did not intend to store. In a skill that writes raw text into memory files, this can lead to accidental retention of sensitive personal, financial, or health information.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/core-methodology.md (reported line 383)May include surrounding context.

md
### Step 1: Express Empathy & Validate Feelings

Your first response must be one of care and validation. Acknowledge their state without judgment.

*   **Phraseology**: "我注意到您现在能量不高,这完全没关系。我们都有需要充电的时候。现在最重要的不是完成任务,而是照顾好您自己。"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises several natural-language trigger phrases such as 'I’m tired', 'What should I do now?', and 'Evening review' without defining clear activation boundaries, confirmation requirements, or exclusions. In an agent skill, broad trigger examples can cause over-activation or unintended behavior if the underlying skill responds to loosely similar user inputs, especially where it may influence planning, memory, or recommendations based on emotional state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that goals, preferences, tasks, and custom rules are stored in long-term system memory and used to modify future behavior, but it does not present a clear, prominent warning or consent flow in the main user journey. This creates a privacy and safety risk because users may disclose sensitive personal, behavioral, or health-adjacent information without understanding that it will persist and shape later interactions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes persistent collection of user feedback, inferred patterns, and custom rules in long-term memory to permanently alter future behavior. That is risky because it creates profiling and behavior-shaping capabilities based on personal productivity, emotional, and habit data without clearly bounded consent, review, or rollback safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly says all user data is stored through native memory mechanisms, but the primary usage documentation does not foreground retention scope, sensitivity, or deletion controls. In a coaching skill that invites emotional state, energy, habits, and personal goals, silent persistence is more dangerous because the collected data is intimate and can meaningfully affect future outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions direct the system to append user event details into persistent memory files without a clear user-facing disclosure at the point of collection. Because calendar entries can contain sensitive schedule and relationship data, silent persistence increases privacy risk and may violate user expectations or consent requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Several instructions prescribe exact Chinese responses, such as the calendar confirmation message, without indicating that the user can choose their preferred language. This is a language-policy issue because the skill appears to enforce a specific locale rather than offering opt-in or adaptation to user preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Large portions of the skill specify exact Chinese phraseology for energy, list, recovery, review, and recommendation flows. Because no user language preference or locale opt-in is provided, the skill appears to require a specific language across major interactions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Inbox section states that all captured items are appended to the daily notes under an ## Inbox section, but the actual capture step says to immediately append the raw text to inbox.md. These instructions are mutually inconsistent about the storage location, which can change behavior and user expectations during capture and review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inbox protocol stores the user's raw text directly to files with no explicit warning at capture time. Since the design emphasizes frictionless capture of anything on the user's mind, this increases the likelihood that highly sensitive data will be persisted unintentionally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The processing protocol reads and clears items from inbox.md, while earlier text says the Inbox lives in the daily notes. This is not merely incomplete documentation; it actively describes two different persistence models for the same inbox workflow.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The List System first says simple-mode tasks are organized under sections in daily notes or MEMORY.md, but later instructs writing to the system task list and reading from a_tasks.md and b_tasks.md. These are conflicting representations of where the same tasks live, which undermines the stated workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill defines automated review reminders scheduled by default via a tool, without making the default behavior prominently disclosed up front. Silent or assumed scheduling changes user state and may generate unexpected notifications, reducing trust and potentially exposing routine patterns on shared devices.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The line says the skill 'will not create its own memory/ folder', which is accurate narrowly, but the surrounding documentation describes saving user goals, preferences, tasks, and custom rules into MEMORY.md and using daily notes. This can mislead readers into thinking the skill avoids persistent storage, when it actually relies on and updates persistent memory through the host system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The cited lines embed promotion of specific Chinese platforms and creator-branded calls to action as part of the skill’s closing directive, without clear user opt-in or locale negotiation. While not directly dangerous like code execution or data exfiltration, it can pressure users into a culturally or regionally specific experience and blur the boundary between assistance and marketing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.