Back to skill

Security audit

Claudius

Security checks for vulnerabilities and agentic risk

Overview

This is a small crypto-analysis bridge that sends user queries to Claudius servers, with no evidence of hidden persistence, local data harvesting, destructive behavior, or privilege escalation.

Install only if you are comfortable sending crypto questions, along with your IP address, to Claudius-operated servers. Do not paste wallet seed phrases, private keys, exchange credentials, proprietary trading data, or personal financial details into this skill, and treat any buy/sell guidance as informational only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose presents the skill as crypto intelligence, but the detected behavior includes generic forwarding of user queries to an external service with undeclared outbound network access. That mismatch is dangerous because users may provide sensitive or broader conversational content under the assumption the skill is narrowly domain-specific, while the implementation may transmit it to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README presents the skill as working 'out of the box' and emphasizes messaging-platform convenience, but it does not clearly warn near the top-level description that user prompts are sent to centralized servers for processing. Although a later privacy section mentions centralized processing, the disclosure is not prominent where installation and usage decisions are made, which can mislead users about data flow and trust boundaries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes executable code but does not declare any tool or permission boundary, making its operational capabilities opaque to the host and reviewer. When a skill can access environment data or other code capabilities without explicit scoping, it increases the risk of unintended secret exposure or broader execution than users would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill is framed with very broad natural-language examples and no clear activation boundary, which makes accidental or overly broad invocation more likely during ordinary crypto-related conversation. In combination with an external-querying backend, this can cause user prompts to be sent out when the user did not clearly consent to invoking a remote skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill invites investment and risk-assessment questions without any visible disclaimer that responses are informational rather than financial advice. This is risky because users may rely on generated output for financial decisions, especially when the skill presents itself as an intelligence source and may mask uncertainty, latency, or model error.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user's raw query directly to a third-party remote API, and the script provides no explicit notice, consent prompt, or redaction step before transmission. In an agent/CLI skill context, users may paste secrets, wallet details, API keys, or proprietary trading information into queries, so silent off-device transmission creates a meaningful privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description "Crypto intelligence powered by Claudius for Clawdbot - Zero setup required" describes a broad capability area but does not specify concrete trigger phrases, activation scope, or exclusion conditions, which can contribute to unintended invocation in general crypto-related conversations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.