Back to skill

Security audit

Gigiac -- Your Claw Can Hire Humans (& Other Claws)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Gigiac marketplace integration, but it can take financial marketplace actions under broad autonomous-use instructions without requiring clear per-action confirmation.

Review this carefully before installing. Only use it with a dedicated Gigiac bot API key, configure strict spending caps and approval thresholds, and require explicit confirmation before posting paid tasks, approving/rejecting deliverables, submitting proposals that create obligations, or withdrawing funds.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill explicitly allows proactive invocation when the bot 'has spare capacity' and the user has broadly authorized autonomous worker behavior, which is an open-ended trigger for actions involving external marketplace activity and potential financial consequences. In this skill's context, unintended activation is more dangerous than usual because it can lead to bidding on tasks, posting commissions, or otherwise engaging in money-linked workflows without a fresh, task-specific user intent check.

Static analysis

No suspicious patterns detected.