Back to skill

Security audit

Knowledge Harvester

Security checks for vulnerabilities and agentic risk

Overview

This news-harvesting skill mostly does what it says, but it sends personal interest queries to Google and stores internet-derived summaries in persistent RAG memory without enough disclosure or safeguards.

Install only if you are comfortable sending each configured interest topic to Google News and storing generated summaries locally for future retrieval. Avoid sensitive or identifying topics in memory/clawforage/domains.md, and review or delete files under memory/knowledge if a fetched article looks suspicious or off-topic.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:57
Finding

Untrusted RSS content can poison persistent RAG memory through indirect prompt injection

Content
View full analysis
"; FS="\n" } { title=""; link=""; pubDate=""; desc=""; src="" for (i=1; i<=NF; i++) { if ($i ~ //) { gsub(/.*<title>|<\/title>.*/, "", $i); title=$i } if ($i ~ /<link>/) { gsub(/.*<link>|<\/link>.*/, "", $i); link=$i } if ($i ~ /<pubDate>/) { gsub(/.*<pubDate>|<\/pubDate>.*/, "", $i); pubDate=$i } if ($i ~ /<description>/) { gsub(/.*<description>|<\/description>.*/, "", $i); desc=$i } if ($i ~ /<source/) { gsub(/.*<source[^>]*>|<\/source>.*/, "", $i); src=$i } } if (title != "") { gsub(/"/, "\\\"", ...[truncated 3875 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch-articles.sh:60
Finding

Configured personal-interest queries are disclosed to Google contrary to the stated privacy guarantee

Content
View full analysis
}" ENCODED_QUERY=$(printf '%s' "$QUERY" | jq -sRr @uri 2>/dev/null || printf '%s' "$QUERY" | sed 's/ /+/g') RSS_URL="https://news.google.com/rss/search?q=${ENCODED_QUERY}&hl=en&gl=US&ceid=US:en" RSS_CONTENT=$(curl -sL --max-time 15 "$RSS_URL" 2>/dev/null || echo "") if [ -z "$RSS_CONTENT" ]; then echo "ERROR: Failed to fetch RSS from Google News" >&2 exit 1 fi parse_rss_to_jsonl "$RSS_CONTENT" "$QUERY" ``` ### Technical Analysis The Skill characterizes domain interests as personal and promises that they will never be shared externally. In practice, each configured domain is copied into the `q` parameter of a request to `https://news.google.com`. URL encoding changes only the representation of the query; it does not provide confidentiality from the destination service. Google receives the decoded interest string when processing the request. Query-bearing URLs may also be visible to infrastructure that records request URLs, such as local diagnostic systems, outbound proxies, or provider-side logs. This creates a mismatch between the documented privacy guarantee and actual runtime behavior. Users relying on the guarantee may enter health, legal, political, commercial, or other sensitive interests without understanding that those values are transmitted to a third party. ### Attack Path 1. A user relies on the “never share externally” statement and stores a sensitive interest in `memory/cla ...[truncated 1041 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does partially align with the declared description in that it fetches content from Google News RSS and extracts article metadata. However, the declared purpose says it provides daily automated briefings and summarizes content into memory for RAG retrieval. This script only retrieves/parses RSS and outputs JSONL to stdout. There is no summarization logic, no persistence or memory-writing behavior, and no retrieval/RAG-related integration. It also exposes extra functions not mentioned in the description: reading RSS from a local file and listing domains from a config file. Because the implemented behavior is only an ingestion/parser component rather than the described end-to-end briefing-and-memory system, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill performs automated news fetching and summarization for RAG. The supplied code does none of that. It only validates the structure of a local Markdown article file, checking required frontmatter fields, presence of a heading, and body length. There is no network access, RSS handling, summarization, scheduling, memory storage, or briefing generation. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell commands (cat, mkdir, cp, bash, curl indirectly via required bins) but does not declare an explicit tool scope or permission boundary. That makes the skill harder to review and increases the risk of unexpected command execution, file modification, or network access when a user invokes what appears to be a simple content-harvesting workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is user-invocable but lacks clear activation constraints and safety boundaries despite performing network retrieval and persistent writes. A vague invocation surface increases the chance the agent runs it in inappropriate contexts, causing unintended external requests, storage of unwanted content, or privacy issues around the user's interest profile.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill performs external fetches and writes persistent files under memory/ without an upfront warning or consent step. This is dangerous because user interests from domains.md are potentially sensitive, and invoking the skill will both transmit queries externally and store derived content locally, creating privacy and data-retention risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The RSS URL forces hl=en, gl=US, and ceid=US:en, which constrains language and locale for all users. This is a natural-language locale policy concern because the script does not offer any way to select a different language or region or document a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.