Back to skill

Security audit

Task Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese-language task planning skill with no executable code, network behavior, credential handling, or hidden destructive actions.

Use this if you want a Chinese-language planner that asks for tasks, schedule constraints, and energy patterns. Be aware it may write or overwrite a local daily-plan JSON output containing personal planning details, so avoid including sensitive private information you do not want stored in a plan file.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill description includes broad trigger phrases like “帮我理一下” and “做一次规划”, which can overlap with many ordinary planning or help-seeking requests. This can cause the planner skill to activate when a narrower or safer skill would be more appropriate, leading to unintended data collection, unnecessary workflow expansion, or incorrect tool selection.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill content is entirely in Chinese and prescribes Chinese-language prompts without offering any mechanism to detect or honor the user's preferred language. This can cause users to miss important planning instructions or provide incomplete information, reducing usability and potentially leading to incorrect task scheduling decisions. In this task-planning context, the issue is less severe than in a safety-critical or financial workflow, but it is still a genuine quality and accessibility vulnerability.

Static analysis

No suspicious patterns detected.