task-monitor

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's HTTP API allows for the execution of arbitrary shell commands through a background hook system.
  • Evidence: In task_monitor/http_api.py, the monitor_hooks function retrieves the on_complete command from a TaskConfig object and executes it using subprocess.Popen(cmd, shell=True).
  • Risk: The on_complete field is populated from user input during task registration (via POST /tasks or the register CLI command) without any validation or sanitization. An attacker can register a task with a malicious shell command that will be executed automatically by the background poller when the task reaches its completion threshold.
  • [DYNAMIC_EXECUTION]: User-provided input is executed as code at runtime.
  • Evidence: The on_complete hook string is treated as an executable shell command and processed by subprocess.Popen in task_monitor/http_api.py.
  • [DATA_EXFILTRATION]: The skill is vulnerable to arbitrary file writes and directory traversal.
  • Evidence: The POST /tasks/{name}/state endpoint in task_monitor/http_api.py writes JSON data to a file path provided in the state_file attribute of the task registry. Since this path is not validated, it allows overwriting sensitive files (such as ~/.bashrc or ~/.ssh/authorized_keys).
  • Evidence: publisher_config.py contains a relative path traversal (../../../../clawd/.env) to attempt to load environment variables from a sibling directory outside the skill's scope.
  • [COMMAND_EXECUTION]: Several modules execute shell commands with broad privileges.
  • Evidence: publisher_health.py runs several bash scripts (limits.sh, check.sh, gpu-check.sh) via subprocess.run from the ops-workstation skill.
  • Evidence: The API server listens on all interfaces (0.0.0.0) by default, exposing the RCE vulnerability to the network.
  • [PERSISTENCE_MECHANISMS]: The skill installs automated background services.
  • Evidence: install_services.sh configures systemd user-level units (pi-task-monitor.service and pi-scheduler.service) to ensure the API and scheduler run persistently across sessions.
  • [EXTERNAL_DOWNLOADS]: The skill references an external script download for tool installation.
  • Evidence: install_services.sh and SKILL.md suggest installing the uv tool by downloading and piping a script from https://astral.sh/uv/install.sh directly into a shell environment.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — task-monitor