Back to skill

Security audit

personal-assistant

Security checks for vulnerabilities and agentic risk

Overview

This personal-assistant skill is not malicious, but its broad triggers and broad local read/write authority could expose or alter private planning records unintentionally.

Install only if you are comfortable letting the assistant read and update local schedule or todo records. Use clear confirmations before any write, and prefer configuring a dedicated notes path so broad file tools do not touch unrelated private files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The trigger keyword list contains highly generic words such as '记录', '安排', '进度', 'todo', and 'assistant', which are likely to appear in many unrelated conversations. This increases the chance of unintended skill activation, and in this skill's context that means unsolicited access to local records and possible writes to persistent notes after ordinary dialogue, exposing sensitive personal-planning data or polluting stored tasks.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill triggers on broad intent categories like schedule, todos, progress, and any request to record a new item, which are common in everyday conversation and can easily match unrelated user requests. Because the skill is configured with disable-model-invocation and allowed write capability, accidental activation could cause the agent to read or persist local notes when the user did not intend to invoke this skill, creating privacy and integrity risks.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises many broad, everyday trigger phrases such as '今天安排', '我的日程', 'schedule', and '私人助理', which can cause the skill to activate during ordinary conversation even when the user did not explicitly intend to invoke it. In a personal-assistant context, unintended activation is more dangerous because the skill may access or summarize sensitive schedule, reminder, or progress information, creating privacy and integrity risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is written entirely in Chinese and presents the assistant as a general-purpose personal assistant, but it does not indicate that language choice is optional or that the skill is restricted to a Chinese-speaking context. For a general-purpose skill, this can constitute a language/locale policy issue because it implies a fixed language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file begins with a Chinese-language scope notice and licensing explanation, while the formal MIT text below is in English. This creates a language-specific policy concern because the explanatory licensing terms are presented in a fixed language without any user opt-in or stated region-specific need.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.