Back to skill

Security audit

clawlist

Security checks for vulnerabilities and agentic risk

Overview

This task-management skill is mostly transparent, but it tries to take over too many agent interactions and can create ongoing/persistent task state without clear opt-in.

Install only if you want an opinionated project-management workflow that may add planning, verification, memory files, recurring task tracking, and parallel-agent steps. Review or narrow its triggers before use, and require explicit approval before it saves project details, schedules ongoing work, or dispatches subagents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
doing-tasks/SKILL.md:10
Finding

Unconditional Skill Invocation and Agent Workflow Hijacking

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger description says to use this skill when executing any task, which is so broad that it can match almost every user request. Overbroad triggers are dangerous because they enable unintended interception of normal interactions and can force unnecessary workflow steps that degrade correctness and safety.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The rule 'even 1% chance' sets an excessively sensitive and ambiguous threshold for invoking a skill. This effectively guarantees over-invocation, making the agent easy to steer into unnecessary or recursive skill usage and reducing reliable user-intent handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The metadata description says the skill 'MUST use for any multi-step project, long-running task, or infinite monitoring workflow,' which is an overly broad trigger that can cause the agent to invoke this skill in many situations without sufficient user intent or task-specific need. This increases the chance of unnecessary workflow takeover, context pollution, and unintended file/state modifications such as task tracking updates.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The 'ALWAYS use clawlist when' section is ambiguous and expansive, covering common situations like 'starting any new project' or 'breaking down complex goals.' In an agent environment, such mandatory language can bias routing and override more appropriate skills or direct handling, leading to over-invocation and unintended persistence/automation behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares a broad mandatory trigger: 'MUST use before any creative work - creating features, building components, adding functionality, or modifying behavior.' This can inappropriately force invocation across a very wide range of tasks, reducing user or orchestrator discretion and enabling prompt-routing hijack or workflow interference even when brainstorming is unnecessary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented as an execution core, but its actual content imposes broad meta-policy about mandatory skill selection for nearly any task. This mismatch can cause the agent to invoke this skill in contexts where it is not appropriate, creating policy confusion and increasing the chance of incorrect or cascading skill use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although labeled as an execution skill, the file instructs the agent to perform pre-action skill discovery and mandatory invocation logic instead of task execution. That makes the skill function as a control-plane policy override, which can distort agent behavior and bypass intended selection logic for other tools or skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The red-flag guidance reframes nearly all questions and preliminary actions as tasks requiring a skill check first, which broadens activation to virtually everything. In context, this makes the skill especially dangerous because it pressures the agent to prefer procedural compliance over context-appropriate behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · doing-tasks/SKILL.md (reported line 72)May include surrounding context.

md
### Don't:
- Skip skills because "it's simple"
- Add unplanned scope without approval
- Work silently for long periods
- Guess when unclear
- Let blockers sit unreported

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill 'MUST use after completing any multi-step task or project,' which is an overly broad activation condition for a verification skill. This can cause the agent to invoke the skill in many loosely related situations, creating unnecessary workflow branching and increasing the chance of unintended file writes or disclosure of project state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases 'is it done?' and 'did it work?' are common conversational queries that overlap with ordinary speech and may activate the skill when the user only wants a quick status update. In an agent system, generic triggers like this can cause unintended execution paths, including unnecessary verification steps and downstream persistence of task details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs saving a completion report to a persistent memory/plans/ path without warning that project goals, blockers, and lessons learned may contain sensitive or proprietary information. While this is framed as documentation, silent persistence increases the risk of retaining data longer than intended and exposing it to later retrieval by other workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs writing a plan to memory/plans/<filename>.md without first telling the user that persistent data will be created. While the content being saved is only a plan, undisclosed persistence can surprise users, retain sensitive project details, and normalize silent file writes by agent skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.