Back to skill

Security audit

Emergency Fund Builder

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent emergency-fund coaching workflow, but it asks to store sensitive financial details across sessions and has an unpinned installer plus unexplained filesystem access.

Install only if you are comfortable with the agent retaining financial profile details between sessions. Do not provide account numbers, passwords, or banking login information. Prefer session-only use or clear deletion controls if available, verify the installer source before running npx, and question why filesystem access is needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:321
Finding

Persistent Retention of Sensitive Financial Profile Data Without Defined Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
**Agent action**: Run the user through each category and ask about current spending. Do not moralize. Record identified savings in state. Calculate total available monthly savings.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command uses npx clawhub install ... without pinning a specific version of the tool. This creates a supply-chain risk because future or compromised releases of clawhub could execute unexpected code during installation, and users would implicitly trust whatever latest version resolves at install time.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
- Never recommend specific financial products or banks by name — provide the framework and comparison criteria instead
- Never suggest stopping minimum debt payments in favor of saving — that triggers fees and credit damage that cost more than the savings gain
- Always acknowledge when the income/expense gap is structural — don't imply that budgeting harder will fix a situation where income is genuinely below survival cost
- Crypto, stocks, and investments are not emergency funds — never suggest them as substitutes

## Tips

Static analysis

No suspicious patterns detected.