Back to skill

Security audit

Fabrik Codek

Security checks for vulnerabilities and agentic risk

Overview

This instruction-only skill is purpose-aligned, but it recommends broad indexing of Claude session transcripts into persistent local knowledge stores and depends on an unpinned external source install.

Install only after auditing or pinning the external Fabrik-Codek source you will run. Before building the knowledge base, review `~/.claude/projects/` for secrets or private conversations, avoid broad transcript ingestion unless you need it, and keep the MCP transport on stdio or localhost-only. Treat the generated `./data/` indexes as sensitive because they may contain derived copies of transcript content.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:70
Finding

Sensitive Session Transcripts Are Included in the Recommended Knowledge-Base Build

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:162
Finding

Unpinned Installation of External Source and Development Dependencies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Setup

Configure as an MCP server in your openclaw.json or ~/.claude/settings.json:

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
### Session transcript privacy

The `fabrik learn` command reads Claude Code session transcripts, which may contain sensitive data (code, credentials, conversation history). This command is **opt-in** — you must run it manually. It does not run in the background or on a schedule unless you explicitly configure `fabrik learn watch`. Review what's in your `~/.claude/projects/` before indexing.

### Source verification

Static analysis

No suspicious patterns detected.