Back to skill

Security audit

todo-tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only task-management skill with no executable code, network behavior, credential handling, or persistence beyond normal task-list concepts.

Before installing, treat this as a lightweight task-management prompt, not a full storage system. Be aware that its licensing terms are confusing and that broad trigger words may invoke it in generic task discussions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
| 文档与理论文本 | 本 `SKILL.md`、`README.md`、其中「理论依据」段与一切理论表述 | **不在 MIT 覆盖范围内**:保留所有权利(All rights reserved) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

Line L009 states licensing information as "代码(.py 文件)MIT;本 SKILL.md 与其中理论文本不在 MIT 覆盖范围内" and the document is predominantly Chinese despite multiple languages being declared, which may indicate a default language constraint. Because the file does not explicitly offer a user language choice in the natural-language instructions, this can conflict with language/locale choice policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger keywords are very generic (for example, 'todo', 'tracker', and common task-management terms) and there are no activation constraints or disambiguation rules. This can cause unintended invocation in unrelated conversations, leading the agent to apply this skill out of context and potentially override better-matched instructions or user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file begins with binding policy-style licensing scope language written in Chinese, while the rest of the license text is in English. This creates a language/locale constraint for understanding the operative scope notice without any user opt-in or documented justification for restricting that instruction to Chinese.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.