Claude Task Runner
PassAudited by VirusTotal on Mar 29, 2026.
Findings (1)
The skill bundle facilitates headless Claude Code execution using the `bypassPermissions` flag, which allows the agent to execute shell commands and modify files without user intervention. While these capabilities are aligned with the stated purpose of a task runner, they represent high-risk behaviors under the provided criteria. Additionally, the files (SKILL.md and run-task-example.sh) contain hardcoded paths for a specific local user (`/Users/zhengweidong/`) and reference an external model API (`open.bigmodel.cn`), though no explicit evidence of malicious intent or data exfiltration is present.
