Back to skill

Security audit

Interviewer-Claw

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only interviewing skill that asks structured planning questions and can create project-spec files after user confirmation.

Before installing, expect the skill to drive a persistent, one-question-at-a-time planning interview. Only point it at documents you want reviewed, and confirm generated spec-kit files before allowing writes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 344)May include surrounding context.

md
- "Understood. I'm parking [topic] as an open question. We'll need to resolve it before [dependent decision]. Let's continue with [next branch]."

### Contradictory answers surface
Flag immediately without judgment:
- "Earlier you said [X], but just now you mentioned [Y]. These seem to be in tension. Which takes priority, or is there a way both can be true?"

### Interview is going in circles

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Because this is a markdown file, vague-trigger review applies. The example trigger "Help me think through this" is broad and could match many ordinary conversations, making unintended invocation more likely compared with the slash commands or more specific interview-oriented phrases.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description lists "help me think through this" as a trigger phrase, which is common everyday speech and not specific to this skill's structured interviewing behavior. This could cause unintended invocation when a user is simply asking for general assistance rather than requesting a rigorous stress-test interview.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The start function says to run when the user says "grill me", "stress-test my plan", "interview me about my design", "etc.", which leaves the trigger set undefined. The lack of explicit boundaries or exclusion examples makes it unclear when the skill should activate versus when normal conversation should continue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.