Back to skill

Security audit

DocuClaw

Security checks for vulnerabilities and agentic risk

Overview

DocuClaw is a document-processing skill with no executable payload, but its privacy promises conflict with documented remote and third-party data flows.

Review this skill carefully before installing. It appears non-executable, but do not rely on its '100% local' claim unless you configure only local models and disable external sync. Treat OpenAI Vision and calendar/accounting integrations as outbound data sharing paths for potentially sensitive documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill makes a strong privacy and deployment claim ('100% local' and 'zero cloud dependency') while simultaneously advertising OpenAI Vision support, which normally requires sending document contents to a remote service. For a document-processing skill handling invoices, receipts, contracts, and mail, this mismatch can mislead users into exposing sensitive personal or business data to third parties under a false assumption of local-only processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Claiming '100% local' while listing OpenAI Vision support without clarifying that it is a remote service creates a security-relevant transparency failure. Because this skill is marketed for private document intelligence and archival, users may rely on the local-only claim when processing highly sensitive records, increasing the risk of inadvertent disclosure to external providers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow states that extracted document data may be synced to a calendar or accounting tool, but it does not warn that this can transfer sensitive financial, contractual, or personal information outside the local archive. In the context of a 'sovereign' document system, omission of outbound data-flow warnings can cause users to unintentionally propagate confidential data into third-party systems with different security and retention properties.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.