Back to skill

Security audit

Emergency Financial Triage

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent financial-crisis advice guide, but it asks for calendar and filesystem access without explaining why.

Install only if you are comfortable with the declared calendar and filesystem access, or ask the publisher to remove those permissions and provide a pinned, reproducible install command. Treat the advice as US-focused unless you confirm local equivalents for your country.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Remote Installation Command Creates a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:11
Finding

Skill Requests Calendar and Filesystem Tools Without a Demonstrated Functional Need

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install command invokes npx clawhub without pinning an exact package version, which allows the latest published package to be fetched at install time. If the upstream package is compromised, typosquatted, or updated with malicious code, users installing the skill could execute untrusted code in their environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instructions state that programs and phone numbers are US-specific and tell the agent to adapt for other countries, but the skill otherwise presents a default US-centric workflow. This can create a locale-policy issue because users are funneled into a specific national context without an explicit choice or a clearly documented scope limitation such as 'for US users only'.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.