Back to skill

Security audit

Chinese

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent Chinese-writing assistant, but it automatically builds long-lived local records about people, documents, business communications, outcomes, and mistakes without requiring explicit user consent before writes.

Install only if you are comfortable with the skill maintaining local Chinese-writing memory about contacts, channels, documents, templates, outcomes, and mistakes. Avoid using it with sensitive HR, medical, legal, financial, client-confidential, or personal relationship content unless you are prepared to review and prune the files under ~/Clawic/data/.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs reading from and writing to local memory/artifact files containing prior user documents and accepted templates. That creates persistent retention of potentially sensitive employment, leave, and administrative content beyond the narrow need to draft Chinese text, increasing privacy and data-minimization risk if those files are exposed or reused inappropriately.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
These instructions direct the system to store accepted document skeletons, employer conventions, rejection history, and a log of each delivered document with recipient and outcome. This is sensitive behavioral and institutional metadata that can reveal employment relationships, internal processes, and user history, and it is not necessary for a basic Chinese-writing skill.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill covers handling of certifications, applications, IDs, employment, income, and residence documents, all of which commonly contain highly sensitive personal data. Even though one line says ID numbers should not be written to a template store, the broader guidance still normalizes collecting and templating sensitive records, creating unnecessary exposure and secondary-use risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to read recipient rows from a memory file and related artifacts before drafting business communications, which can expose stored personal or client-specific data without any minimization, consent, or sensitivity checks. In a workplace/client context, that increases the chance of unnecessary access to contact metadata, prior correspondence patterns, or business relationship details beyond what is needed for the current task.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs persistence of client/colleague titles, address forms, internal vocabulary, accepted templates, and even badly received emails or reports, creating a structured store of sensitive business and interpersonal information. Without retention limits, access controls, or sensitivity guidance, this can leak confidential workflow details, performance signals, client preferences, or reputationally damaging communication history.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs storing named persons' address forms, particle use, laughter length, group conventions, and socially sensitive mistakes in persistent memory files. This creates a real privacy and retention risk because behavioral profiles and embarrassing interaction history can be retained without consent, minimization, or deletion rules, and later exposed to unrelated tasks or users.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Recording each delivered document together with recipient and outcome creates a persistent audit trail of user activities without any privacy warning, consent flow, or minimization. Such metadata can be sensitive even without full document text because it reveals who the user is dealing with and what administrative or employment actions occurred.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The file explicitly instructs users to record named individuals' sensitivities in a persistent notes field without any warning about consent, minimization, access control, or retention. That creates a privacy risk because it encourages collection of personal preference and behavioral-profile data tied to identifiable people, which can be misused, exposed, or retained longer than necessary.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to persist data into memory and artifact files automatically whenever certain conditions are met, but it does not require explicit user confirmation before modifying stored data. This can cause unintended retention of user content, reviewer notes, or behavioral profiling data, creating privacy and integrity risks if sensitive text is written to long-lived storage without the user's awareness.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
The line instructs the agent to make a variant/script decision before producing any text and to state it out loud when `variant` is unset, which can override or preempt user preference. In a language-writing skill this is not directly security-sensitive, but it is still a real policy/control issue because it forces a language behavior without explicit user opt-in and may cause the agent to impose defaults the user did not request.

Ssd 3

Medium
Confidence
94% confidence
Finding
These instructions operationalize long-term retention of user-specific communication patterns and failures in natural-language memory files, which are easy to over-collect, hard to sanitize, and prone to later leakage through prompts, summaries, or cross-context reuse. In a messaging-style skill, such records can reveal interpersonal dynamics, hierarchy, and past social errors, making the context more sensitive rather than less.

Ssd 3

Medium
Confidence
97% confidence
Finding
The file gives plain-language retention instructions for storing sensitive user and institutional data in memory/artifact files, effectively defining a persistent data collection policy without safeguards. This is dangerous because it encourages accumulation of sensitive content and metadata that may be accessible to other components, future sessions, or anyone with file access.

Session Persistence

Medium
Category
Rogue Agent
Content
Everything except style guides, the pieces log, artifacts and the shared boxes begins inside `memory.md`. Splitting is a procedure, not a suggestion:

1. Before appending to a section, count its entries.
2. If the append would take it past **~15 entries or ~40 lines of real content** — scaffolding, headings and comments do not count — then, in the same turn: create the new file, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file.
3. Keep the headings identical on both sides of the move, promoted one level (`### Terms` inside `memory.md` becomes `## Terms` in `glossary.md`), so the split is a copy-paste and never a rewrite.
4. Never leave a copy behind. If the same data ever appears in both places, the extracted file wins and the `memory.md` copy is deleted.
Confidence
74% confidence
Finding
create the new file, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file. 3. Keep the headings identical on bo

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.