Back to skill

Security audit

Layoff 72 Hours

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent layoff triage guide, but it tells users to copy broad employer and third-party information and persist sensitive financial, health, and employment details without clear limits.

Before installing, treat this as sensitive crisis guidance: do not copy employer, client, vendor, CRM, address book, proprietary, or confidential records unless your employer policies and legal obligations clearly allow it. Prefer requesting employment, pay, benefits, and severance records through HR, and avoid storing exact financial and health-related details in agent memory unless you explicitly want that retained and can later delete it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:96
Finding

Overbroad Transfer of Employer and Third-Party Contact Information

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:286
Finding

Uncontrolled Cross-Session Retention of Sensitive Financial and Employment Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill includes an install command using npx clawhub without pinning a specific version, which creates a supply-chain risk because whatever version is current at execution time will be fetched and run. In a security-sensitive agent ecosystem, this can allow a compromised or malicious package update to affect users or agent environments unpredictably.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to forward workplace materials to personal email or cloud storage, including broad contact lists and accomplishment documentation, which can easily cause exfiltration of employer-controlled data, personal data of third parties, or confidential business information. Even though the text warns against taking trade secrets, the operational guidance is broad and given during a stressful moment, making over-collection and policy violations likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill defines persistent state and automations that retain extensive sensitive information about layoffs, finances, insurance, legal matters, and deadlines across sessions, increasing the privacy and breach impact if agent memory, logs, or connected systems are accessed improperly. Much of this data exceeds strict minimization for immediate task completion and could expose a user during an already vulnerable life event.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.