Back to skill

Security audit

Calorie Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent calorie tracker, but it should be reviewed because it stores sensitive diet and health details in local plaintext files without clear consent, retention, deletion, or permission controls.

Review this before installing if you are uncomfortable with a skill keeping local records of meals, weight trends, goals, restrictions, medications, pregnancy, conditions, or eating-disorder history. Prefer using it only when you understand where ~/Clawic/data/calories/ is stored and how you can remove or protect those files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
setup.md:20
Finding

Plaintext Persistence of Sensitive Health Data Without Privacy Controls

Content
View full analysis

Vulnerability Details

File Location: setup.md:20-25, with the stored fields defined in memory-template.md:15-19
Vulnerability Type: Plaintext storage of sensitive personal and health information
Risk Level: Medium

Vulnerable Code

markdown
Write to config or memory **only** when the user states something in the course of the work — never as a preflight.

- User names units, energy unit, summary cadence, or how they want ambiguity handled → update the matching key in `~/Clawic/data/calories/config.yaml`.
- User reveals a goal, stats, restrictions, staple foods, an external tracker, or a weigh-in habit → record under the relevant preference area in `~/Clawic/data/calories/memory.md`.
- User corrects an estimate ("that pasta was actually 700") → update the library entry; corrected entries outrank estimates forever.
- User discloses anything from the Red Flags table → record it in memory's Health Context section so the guardrail persists across sessions.

The corresponding memory template contains:

markdown
## Stats
<!-- weight (7-day avg), height, age, sex as given — only what was volunteered or needed for a target -->

## Health Context
<!-- Red Flags disclosures: meds, conditions, pregnancy, ED history — persists the guardrail (safety.md) -->

Technical Analysis

The skill directs the Agent to persist body measurements and highly sensitive health information—including medication use, medical conditions, pregnancy status, and eating-disorder history—in Markdown files under ~/Clawic/data/calories/.

Although persistence is limited to information disclosed during ordinary use, the project does not require explicit informed consent before storing health data. It also does not specify owner-only filesystem permissions, encryption, data minimization, retention periods, automatic expiration, redaction, or a process through which users can inspect and delete their records.

Consequently, the confidentiality of these records d ...[truncated 1699 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit, informed opt-in before persisting health information, separately from ordinary food-library storage.
  2. Default sensitive health context to session-only storage unless the user requests persistence.
  3. Minimize stored information. Persist a coarse safety state such as clinician_target_required: true instead of detailed diagnoses or medication names whenever possible.
  4. Create the data directory and files with owner-only permissions, such as directory mode 0700 and file mode 0600, where the platform supports permission management.
  5. Use encrypted storage or an operating-system credential/privacy store for medical context.
  6. Define a retention policy with automatic expiration for stale health and tracking records.
  7. Provide documented commands or workflows to view, correct, export, selectively redact, and permanently delete stored data.
  8. Warn users when their home directory is synchronized or backed up to third-party services.
  9. Separate low-sensitivity preferences and food-library data from health context so access and retention policies can be applied independently.
  10. Add tests or output gates that prevent sensitive data from being written before consent and verify secure permissions after file creation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 15)May include surrounding context.

md
last: YYYY-MM-DD

## Goal & Targets
<!-- goal: cut | bulk | maintain | recomp; current target kcal + protein g; date set -->
<!-- measured TDEE: value, window it came from (calibration.md) -->

## Stats

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 16)May include surrounding context.

md
## Goal & Targets
<!-- goal: cut | bulk | maintain | recomp; current target kcal + protein g; date set -->
<!-- measured TDEE: value, window it came from (calibration.md) -->

## Stats
<!-- weight (7-day avg), height, age, sex as given — only what was volunteered or needed for a target -->

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises a very wide set of trigger conditions across calorie counting, weight trends, TDEE, macros, plateaus, medications, GLP-1s, and eating-disorder-adjacent situations, while only narrowly excluding meal planning and recipes. In an agent-routing context, this can cause the skill to activate on sensitive health questions that may be better handled by a clinician-oriented or safer specialist workflow, increasing the chance of overconfident calorie or weight advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The fallback instruction 'Anything else | Log it with a range, save to memory, zero commentary on whether the number is good or bad' is effectively catch-all routing language. That broad fallback can pull in ambiguous or out-of-scope requests and encourage the skill to persist potentially sensitive health data even when the user did not clearly ask for calorie tracking or the situation should have been declined.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · exercise.md (reported line 30)May include surrounding context.

md
## NEAT — the Invisible Half

Non-exercise activity (walking, fidgeting, standing) often exceeds workout burn, and it silently DROPS in a deficit — the body economizes without asking. Practical countermeasure: a daily step floor (e.g. hold whatever the user's normal is) so adaptation can't hollow out expenditure unnoticed. A falling step count during a stall is evidence for the audit in `trend.md`.

## Framing Guardrails

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This setup instructs the skill to persist sensitive health-related information, goals, restrictions, weigh-in habits, and eating-disorder red flags to local files without any user-facing notice or explicit consent step in this file. In a nutrition and calorie-tracking context, that data is especially sensitive because it can reveal medical conditions, mental-health risk factors, and long-term behavioral patterns, increasing privacy and misuse risk if the files are accessed by other components or users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.