task-monitor
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's HTTP API allows for the execution of arbitrary shell commands through a background hook system.
- Evidence: In
task_monitor/http_api.py, themonitor_hooksfunction retrieves theon_completecommand from aTaskConfigobject and executes it usingsubprocess.Popen(cmd, shell=True). - Risk: The
on_completefield is populated from user input during task registration (viaPOST /tasksor theregisterCLI command) without any validation or sanitization. An attacker can register a task with a malicious shell command that will be executed automatically by the background poller when the task reaches its completion threshold. - [DYNAMIC_EXECUTION]: User-provided input is executed as code at runtime.
- Evidence: The
on_completehook string is treated as an executable shell command and processed bysubprocess.Popenintask_monitor/http_api.py. - [DATA_EXFILTRATION]: The skill is vulnerable to arbitrary file writes and directory traversal.
- Evidence: The
POST /tasks/{name}/stateendpoint intask_monitor/http_api.pywrites JSON data to a file path provided in thestate_fileattribute of the task registry. Since this path is not validated, it allows overwriting sensitive files (such as~/.bashrcor~/.ssh/authorized_keys). - Evidence:
publisher_config.pycontains a relative path traversal (../../../../clawd/.env) to attempt to load environment variables from a sibling directory outside the skill's scope. - [COMMAND_EXECUTION]: Several modules execute shell commands with broad privileges.
- Evidence:
publisher_health.pyruns several bash scripts (limits.sh,check.sh,gpu-check.sh) viasubprocess.runfrom theops-workstationskill. - Evidence: The API server listens on all interfaces (
0.0.0.0) by default, exposing the RCE vulnerability to the network. - [PERSISTENCE_MECHANISMS]: The skill installs automated background services.
- Evidence:
install_services.shconfigures systemd user-level units (pi-task-monitor.serviceandpi-scheduler.service) to ensure the API and scheduler run persistently across sessions. - [EXTERNAL_DOWNLOADS]: The skill references an external script download for tool installation.
- Evidence:
install_services.shandSKILL.mdsuggest installing theuvtool by downloading and piping a script fromhttps://astral.sh/uv/install.shdirectly into a shell environment.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata