Back to skill

Security audit

founder-wisdom

Security checks for vulnerabilities and agentic risk

Overview

This is a startup-advice reference skill with optional maintenance and evaluation utilities; I found no hidden execution, persistence, exfiltration, or destructive behavior.

Install it as an opinionated startup-advice reference, not as professional counsel. Treat legal, tax, finance, hiring, and shutdown guidance as prompts for discussions with qualified advisors, and pin dependencies in an isolated environment if you choose to run the optional eval harness.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
evals/README.md:75
Finding

Unpinned Third-Party SDK Installation

Content
View full analysis

Vulnerability Details

File Location: evals/README.md:75
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

text
(`pip install anthropic`) and set `ANTHROPIC_API_KEY`. `--dry-run` needs neither and
prints the plan, which is enough to catch a broken runner in CI.

Technical Analysis

The evaluation documentation instructs users to install the anthropic package directly from the package index without a version constraint, lockfile, integrity hash, or isolated-environment requirement. Consequently, installation is not reproducible and automatically resolves whichever release is current when the command is run.

The package name is legitimate and no evidence shows that its current releases are malicious. The risk is conditional: if the upstream package, its distribution account, or its dependency chain were compromised, following the documented command could install attacker-controlled code. An unexpected incompatible release could also alter evaluation behavior.

Python packages and their transitive dependencies execute with the privileges of the invoking user during installation or subsequent import. evals/run_scenarios.py imports this dependency and creates an API client, making installed package code part of the trusted execution path.

Attack Path

  1. An attacker compromises the upstream package publication account, release infrastructure, or a transitive dependency.
  2. The attacker publishes a malicious release under a version accepted by the unrestricted installation command.
  3. A user follows the documented pip install anthropic instruction.
  4. Pip resolves and installs the malicious or compromised release.
  5. Attacker-controlled code executes during package installation or when evals/run_scenarios.py imports the package.
  6. That code operates with the permissions of the user running pip or the evaluation harness.

...[truncated 684 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the reviewed direct dependency to an exact version in a dedicated evaluation requirements file.
  2. Include hashes for the package and all transitive dependencies, then install with hash enforcement:
    bash
    python3 -m pip install --require-hashes -r requirements-evals.txt
    
  3. Generate and review a lockfile using a dependency-locking tool, and update it through controlled dependency-review changes.
  4. Recommend installation in a dedicated virtual environment:
    bash
    python3 -m venv .venv
    .venv/bin/python -m pip install --require-hashes -r requirements-evals.txt
    
  5. Run dependency vulnerability and provenance checks in CI.
  6. Avoid running installation or evaluation under an administrator account.
  7. Limit the API key used for evaluations where provider-side controls permit, and keep unrelated secrets out of the evaluation environment.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (33)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a substantive startup advisory/routing skill that should provide founder guidance and trigger on startup decision questions. The supplied code does nothing related to startup advice, founder canon, or answering user questions. Instead, it is an internal repository utility for validating eval scenario data and displaying scenarios. This is a materially different primary purpose and includes undeclared file-validation and CLI behavior unrelated to the description. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for an end-user advisory skill about startup decisions and founder wisdom. The supplied code does not provide startup advice or surface founder axioms to users as its primary function. Instead, it is an internal eval runner that tests such a skill by orchestrating model calls, tool calls, file reads, validation logic, judging, reporting, and CLI behavior. This is a materially different purpose and includes undeclared capabilities such as filesystem access, API-based scenario execution, grading, and JSON reporting. While the code is related to the founder-wisdom skill, it evaluates the skill rather than implementing the described advisory behavior, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an advisory skill for answering startup/founder questions. The supplied code does not implement founder guidance behavior, routing, response generation, or user-triggered advice logic. Instead, it is a repository maintenance/build utility that transforms markdown sources into bundled documentation and a system-prompt stub, with validation and check/write modes. This is a materially different primary purpose and introduces undeclared file-processing and artifact-generation capabilities. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- `references/finance-ops.md` — Cash, burn, close cycles, CFO timing, forecasting — including the ruin test that overrides expected value (a bet you cannot surv

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
- `references/finance-ops.md` — Cash, burn, close cycles, CFO timing, forecasting — including the ruin test that overrides expected value (a bet you cannot surv

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · dist/founder-wisdom-full.md (reported line 2)May include surrounding context.

md
<!-- Generated by scripts/build_bundle.py — do not edit by hand.
     Edit SKILL.md and references/*.md in the source repository instead,
     then rerun: python3 scripts/build_bundle.py -->

# Founder Wisdom — system prompt for retrieval-based deployments

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · dist/system-prompt.md (reported line 2)May include surrounding context.

md
<!-- Generated by scripts/build_bundle.py — do not edit by hand.
     Edit SKILL.md and references/*.md in the source repository instead,
     then rerun: python3 scripts/build_bundle.py -->

# Founder Wisdom — system prompt for retrieval-based deployments

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/build_bundle.py (reported line 35)May include surrounding context.

python
<!-- Generated by scripts/build_bundle.py — do not edit by hand.
     Edit SKILL.md and references/*.md in the source repository instead,
     then rerun: python3 scripts/build_bundle.py -->

# Founder Wisdom — system prompt for retrieval-based deployments

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- Pull 3–7 axioms maximum per response, in **bolded axiom + explanation**
  format. The axiom itself should be quotable in one sentence.
- Don't over-hedge; founders need conviction. When something genuinely is
  contextual, say so plainly and explain the dependency. Don't moralize.
- When relevant, name the limit of the axiom ("fire fast — except never in
  anger, never on a Friday").
- Stage-match: a pre-seed founder needs different axioms than a Series C CEO.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · dist/founder-wisdom-full.md (reported line 112)May include surrounding context.

md
- Pull 3–7 axioms maximum per response, in **bolded axiom + explanation**
  format. The axiom itself should be quotable in one sentence.
- Don't over-hedge; founders need conviction. When something genuinely is
  contextual, say so plainly and explain the dependency. Don't moralize.
- When relevant, name the limit of the axiom ("fire fast — except never in
  anger, never on a Friday").
- Stage-match: a pre-seed founder needs different axioms than a Series C CEO.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · dist/system-prompt.md (reported line 80)May include surrounding context.

md
- Pull 3–7 axioms maximum per response, in **bolded axiom + explanation**
  format. The axiom itself should be quotable in one sentence.
- Don't over-hedge; founders need conviction. When something genuinely is
  contextual, say so plainly and explain the dependency. Don't moralize.
- When relevant, name the limit of the axiom ("fire fast — except never in
  anger, never on a Friday").
- Stage-match: a pre-seed founder needs different axioms than a Series C CEO.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/build_bundle.py (reported line 308)May include surrounding context.

python
- Pull 3–7 axioms maximum per response, in **bolded axiom + explanation**
  format. The axiom itself should be quotable in one sentence.
- Don't over-hedge; founders need conviction. When something genuinely is
  contextual, say so plainly and explain the dependency. Don't moralize.
- When relevant, name the limit of the axiom ("fire fast — except never in
  anger, never on a Friday").
- Stage-match: a pre-seed founder needs different axioms than a Series C CEO.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · evals/README.md (reported line 238)May include surrounding context.

md
These are recorded so they aren't rediscovered every time:

- **"Reassurance" is an output rule, not a trigger rule.** `SKILL.md`'s
  "What this skill is not for" lists reassurance, but the entry itself says the
  skill "should still surface the axiom that pushes back." `reassurance-still-triggers`
  encodes the trigger as **true**.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This README says the skill activates 'when you ask Claude a founder-stage question' across a very wide set of domains and 'surrounding territory,' but it does not define clear boundaries or exclusions. That kind of broad natural-language trigger can cause unintended invocation for general business or career questions that happen to resemble startup topics.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance is intentionally broad and includes many common founder-adjacent phrasings, plus directions to trigger without an explicit advice request. That can cause unintended invocation in ordinary conversations, leading the assistant to over-apply this skill, shape responses too aggressively, or read unnecessary reference material that the user did not ask for.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger guidance is intentionally broad and includes common phrases like 'should I…' and 'we're thinking about…', which can cause the skill to activate in many ordinary conversations. This is dangerous because it can override narrower, more appropriate skills or inject unsolicited domain-specific advice when the user did not actually ask for founder guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt explicitly instructs invocation for a very wide range of founder-related phrasing, including implicit advice-seeking and adjacent roles like advisors, coaches, mentors, and investors. That can cause the skill to activate in conversations where the user did not clearly request this specialized guidance, increasing the chance of irrelevant or intrusive behavior and unintended reliance on opinionated startup advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scenario explicitly codifies activation on broad phrasings like 'should I...' without requiring stronger startup-specific qualifiers at trigger time. In an agent system, this can cause the skill to over-trigger on ordinary conversational text and route unrelated prompts into founder-advice behavior, increasing the chance of irrelevant or misleading guidance. The surrounding corpus does include scope constraints, which lowers severity somewhat, but the trigger examples themselves are permissive enough to create accidental activation risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase 'is it normal that...' is highly generic and appears in many non-founder conversations, so treating it as a trigger anchor creates collision risk. If the router keys too heavily on this wording, unrelated prompts may activate the skill and surface authoritative startup axioms in contexts where they do not apply. The startup-focused skill description reduces impact compared with a dangerous-action skill, but misrouting remains a real safety and quality problem.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The bare phrase 'we're thinking about...' is too open-ended to safely imply founder-advice intent, because it commonly appears in ordinary planning, family, legal, medical, and enterprise contexts. Encoding a scenario that requires triggering on that phrase even without a question mark encourages aggressive activation heuristics and increases false-positive routing into this skill. Because the skill gives strategic advice rather than executing code, the impact is not critical, but it can still mislead users and crowd out more appropriate skills or safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text states that the section reflects U.S. federal law and Delaware framing, which is a locale-specific policy constraint. While it includes a vintage disclaimer, the document does not clearly present itself as a U.S.-only guide in the title or offer a jurisdiction choice, so users could apply it outside the intended locale.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · dist/founder-wisdom-full.md (reported line 176)May include surrounding context.

md
**A smaller team moves the failure mode from coordination cost to key-person concentration.** AI-native companies reach meaningful revenue with a fraction of the headcount the same business needed a decade ago, and the org-design consequence is not "the same company, cheaper." At twelve people, there is no bench, no redundancy, and no slack: one person owns billing, one person owns the inference pipeline, one person owns every enterprise relationship, and the departure of any of them is a quarter of lost velocity. The disciplines that follow are unglamorous and specific — written runbooks for anything only one person can do, a named second for every critical system, deliberate cross-exposure even when it's inefficient, and retention attention on the three or four people whose exit would actually hurt. Founders who celebrate revenue-per-employee without auditing bus factor are optimizing a metric that hides their largest single risk.

**When you only make eight hires, the law of large numbers stops protecting your hiring bar.** A 200-person company absorbs a bad hire as a rounding error; a 15-person company just gave 7% of its capacity and a large share of its culture to someone who doesn't clear the bar, and the "fire fast" clock is the only correction available. Small headcount means the variance of each decision dominates, which argues for *more* process, not less — real work samples, back-channel references on every hire including the junior ones (late-stage only, and never into a current employer without consent), and a hard no on the candidate you're talking yourself into. Two related traps in the current market: screening signal has degraded because the tools a candidate uses in a take-home are the tools they'd use on the job, so test judgment and debugging under observation rather than output; and "we'll stay small" is a strategy that only survives if the bar is genuinely higher, not merely asserted to be.

**Hire systems thinkers over narrow specialists — sp
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/hiring.md (reported line 43)May include surrounding context.

md
**A smaller team moves the failure mode from coordination cost to key-person concentration.** AI-native companies reach meaningful revenue with a fraction of the headcount the same business needed a decade ago, and the org-design consequence is not "the same company, cheaper." At twelve people, there is no bench, no redundancy, and no slack: one person owns billing, one person owns the inference pipeline, one person owns every enterprise relationship, and the departure of any of them is a quarter of lost velocity. The disciplines that follow are unglamorous and specific — written runbooks for anything only one person can do, a named second for every critical system, deliberate cross-exposure even when it's inefficient, and retention attention on the three or four people whose exit would actually hurt. Founders who celebrate revenue-per-employee without auditing bus factor are optimizing a metric that hides their largest single risk.

**When you only make eight hires, the law of large numbers stops protecting your hiring bar.** A 200-person company absorbs a bad hire as a rounding error; a 15-person company just gave 7% of its capacity and a large share of its culture to someone who doesn't clear the bar, and the "fire fast" clock is the only correction available. Small headcount means the variance of each decision dominates, which argues for *more* process, not less — real work samples, back-channel references on every hire including the junior ones (late-stage only, and never into a current employer without consent), and a hard no on the candidate you're talking yourself into. Two related traps in the current market: screening signal has degraded because the tools a candidate uses in a take-home are the tools they'd use on the job, so test judgment and debugging under observation rather than output; and "we'll stay small" is a strategy that only survives if the bar is genuinely higher, not merely asserted to be.

**Hire systems thinkers over narrow specialists — sp
...[truncated 25 chars]

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · dist/founder-wisdom-full.md (reported line 202)May include surrounding context.

md
- Hiring senior people too early to "give the company credibility" — they need a working machine to manage, not a blank canvas to invent.
- Making counter-offers to retain people who've already given notice — almost always a mistake. The reasons they looked don't change, the trust is already dented, and most counter-offer accepts are gone within a year anyway.
- Promoting top individual contributors into management without asking whether they want to manage. Many don't, and you lose your best IC and gain a mediocre manager.
- Negotiating equity individually rather than from bands — you'll regret it the day employee #15 finds out what employee #4 in the same role got.

Static analysis

No suspicious patterns detected.