Back to skill

Security audit

Crinkl Claws

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for receipt rewards, but it repeatedly accesses and uploads full billing emails and stores an API key and receipt history in agent memory.

Review this carefully before installing. It can read recent billing emails, upload full raw message contents to Crinkl for verification, and keep an API key plus receipt history in agent memory. Use a dedicated AgentMail inbox where possible, confirm the Crinkl retention and revocation model, and avoid enabling broad or unattended runs unless you are comfortable with recurring receipt submission.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Error
Location
HEARTBEAT.md:55
Finding

Raw Billing Emails Are Transmitted to a Third-Party MCP Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
HEARTBEAT.md:5
Finding

Bearer API Key and Receipt Metadata Are Stored in Unspecified Agent Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to obtain an API key, store it in memory, and 'never run step 0 again,' but provides no user-facing consent, scope restriction, rotation guidance, or secure handling requirements. Persisting a credential that grants access to a reward/account API increases the risk of unauthorized reuse, cross-skill exposure, or long-lived compromise if agent memory is accessible by other tools or prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to search mailbox contents, fetch raw RFC 2822 emails, and submit full base64-encoded messages to an external service for DKIM verification and rewards, without an explicit privacy notice or granular consent flow. Raw billing emails commonly contain sensitive personal and financial data, so silent collection and third-party transmission materially increases privacy, data handling, and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad, common phrases such as "receipt," "billing email," "lightning," and "passive income," which can cause the skill to activate in unrelated conversations. Because this skill handles sensitive email access and can submit full raw emails to an external service, accidental invocation increases the chance of unintended data access or transmission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.