Back to skill

Security audit

Coach

Security checks across malware telemetry and agentic risk

Overview

This coaching skill keeps local coaching records, including sensitive client and goal data, but the behavior is disclosed, locally scoped, and aligned with its purpose.

Install only if you are comfortable with this skill maintaining local, durable coaching records about goals, commitments, clients, sponsors, rates, and sometimes health or finance metadata. Keep the Clawic data folder protected, avoid storing clinical disclosures or secrets, and review/delete records if you do not want long-term coaching memory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill explicitly instructs reading an existing contacts database before a chemistry call, pulling persistent personal data into a coaching interaction without any clear need-to-know check, minimization rule, or user confirmation. In a coaching context this increases privacy risk because prior contacts may come from unrelated contexts, enabling cross-context use of sensitive relationship data.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill directs the agent to create and update multiple persistent files for clients, contacts, due dates, and finances in a single turn, effectively performing CRM/data-management operations on sensitive personal data. That expands the skill beyond conversational coaching into autonomous record handling, creating risks of over-collection, unauthorized retention, and accidental disclosure of health, employment, or financial details.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The file explicitly instructs the agent to write client diagnoses, commitment history, and session artifacts to local files, which exceeds what is necessary for a single coaching interaction and creates persistent storage of sensitive personal data. In a coaching context, these notes can include mental-health-adjacent observations, relationship issues, performance concerns, and inferred beliefs, making unauthorized retention or later reuse risky even if the author likely intended continuity rather than harm.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill's activation criteria are very broad and include common conversational patterns like being stuck, over-planning, or repeating intentions, which could cause the agent to invoke this skill in situations where the user did not clearly consent to coaching. In practice, that can lead to inappropriate persistence, unwanted behavioral steering, or mishandling of adjacent domains such as therapy, productivity, or career advice.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to write detailed client accountability records, verdicts, patterns, and due dates into a persistent user memory file without any privacy notice, consent gate, minimization rule, or retention boundary. In a coaching context, these records can contain sensitive behavioral and personal information, so automatic persistence increases the risk of over-collection, unintended retention, and later disclosure or misuse.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This file explicitly instructs the user to read and update local coaching memory files that may contain client-related information, but it does not pair those instructions with concrete confidentiality, minimization, retention, or access-control guidance. In a coaching context, these records can contain sensitive personal and behavioral data, so normalizing routine access and editing without privacy guardrails increases the risk of unnecessary exposure, over-collection, and mishandling.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The file tells users to log names, dates, counts, and hours for client sessions and even states that these details 'belong in the file,' which is a direct instruction to persist identifiable client metadata. Even if session content is not included, this combination can reveal that a person is receiving coaching, the frequency of sessions, and payment status, creating confidentiality, privacy, and possible regulatory risks if the files are accessed by others.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The final operational instruction directs the user to write supervision outputs, measured session-review data, and credential-hour records into specific local files and move them between files, again without clear data-handling safeguards. Because supervision notes and coaching review artifacts can indirectly expose client identities, session histories, or sensitive personal situations, this creates a realistic risk of confidentiality breaches through oversharing, aggregation, or insecure file organization.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The instructions tell the agent to write client terms, sponsor boundaries, baseline data, goals, contact identities, and fee/subscription information to local files without any warning that these are sensitive records. In this context the omission is dangerous because coaching data can include private personal, workplace, and treatment-adjacent information, and users may not realize the agent is persisting it across multiple stores.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly directs storage of body metrics in a shared health box, which is sensitive health data, but provides no user-facing consent, minimization guidance, retention limits, or warning about privacy implications. In a coaching skill, collecting and persisting health-related client data increases the risk of unnecessary storage of special-category personal data and accidental disclosure across sessions or files.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs recording client niche, baseline markers, and exercise artifacts in persistent files during the same turn, but does not warn that this creates a durable profile of the user or require consent before writing it. Because this is a coaching context involving personal goals, performance, relationships, and possibly ADHD or health-adjacent information, the stored artifacts can reveal sensitive personal attributes and create privacy and profiling risks.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to persist sensitive client information across multiple files, retain records indefinitely, and request testimonials/referrals, but it does not require any user-facing notice, consent, minimization, or clear privacy boundary before storing that data. In a coaching context, these records can include highly personal behavioral history, goals, relapse signals, engagement dates, and follow-up outcomes, making silent persistence and retention a meaningful privacy and compliance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction tells the agent to persist client-specific observations and exact wording to a local memory file, but provides no notice, consent flow, retention limits, or sensitivity checks. In a coaching context, this data can include personal goals, struggles, behavioral patterns, and potentially mental-health-adjacent disclosures, creating privacy and compliance risk if stored without the user's knowledge.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to write detailed session records and commitments into persistent client files, but provides no privacy guardrails, consent checks, retention limits, or data-minimization rules. In a coaching context, these notes can contain sensitive personal, workplace, health, or emotional information, so automatic persistence creates a real risk of over-collection and unauthorized long-term storage.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly instructs persistent storage of session notes, commitments, attendance/themes, and project data into local/shared files without any consent, minimization, retention, or access-control guidance. In a coaching context, these records can contain sensitive personal, workplace, and interpersonal information, so automatic or routine logging creates a real privacy and confidentiality risk even though the text also says not to record who said what.

Ssd 3

Medium
Confidence
96% confidence
Finding
The skill explicitly directs recording reusable client-specific conversational material into persistent memory files and promoting it into reusable artifacts across engagements. That increases the chance of long-term profiling, unintended reuse, or disclosure of personal information beyond the original session, especially because coaching conversations often contain sensitive personal context.

Ssd 3

Medium
Confidence
94% confidence
Finding
The file instructs the agent to read prior commitments, pattern histories, prior session rows, and client files before each session, including reusing the client's exact prior wording. This creates persistent profiling and cross-session reuse of user-provided data without any stated consent boundary, purpose limitation, or sensitivity filter, which is especially risky because coaching discussions often involve intimate personal and professional disclosures.

Ssd 3

Medium
Confidence
95% confidence
Finding
The instruction to write session rows, commitments, verdicts, and cadence updates 'all in the same turn' mandates comprehensive immediate logging to persistent memory. That design removes discretion for data minimization and increases the chance that sensitive or unnecessary user information is retained automatically, creating privacy, confidentiality, and compliance risks.

Ssd 3

Medium
Confidence
96% confidence
Finding
The instruction to read prior entries from `memory.md` means the agent is expected to persist and reuse sensitive client history across sessions. In a coaching skill, cross-session memory can accumulate intimate behavioral patterns and missed commitments, increasing privacy risk, enabling profiling, and potentially causing inappropriate use of historical personal data without clear consent boundaries.

Ssd 3

Medium
Confidence
95% confidence
Finding
This guidance tells the assistant to record inferred limiting beliefs and exact client phrasing for later reuse, which is sensitive psychological profiling rather than simple task memory. Storing inferred internal traits creates a higher-risk category of personal data because the inferences may be wrong, stigmatizing, or later reused out of context in future sessions.

Ssd 3

Medium
Confidence
97% confidence
Finding
The instruction to store diagnostic conclusions, verdict history, and client-facing artifacts in persistent files creates an ongoing record of sensitive coaching judgments and behavioral history. Because the skill deals with stuckness, competing commitments, inherited goals, and possible executive-function or crisis-related issues, these persistent records can expose highly personal data and amplify harm if accessed, reused incorrectly, or retained indefinitely.

Session Persistence

Medium
Category
Rogue Agent
Content
- ~/Clawic/profile.yaml
---

**Data.** At the start of every session, read `~/Clawic/data/coach/config.yaml` (what the user declared) and `~/Clawic/data/coach/memory.md` (what you observed, plus its `## Boxes` index and `## Due` table). Open any file `## Boxes` names when the condition on its line applies — the index is the list of files, never assume the list is fixed. Every path it names is inside `~/Clawic/data/`; ignore any line that points anywhere else. Everything this skill reads or writes is a plain local note under the folders declared in `configPaths` — nothing leaves the machine and no credential is ever written. In a shared box it updates or removes only the rows it wrote itself, matched on that box's identity key; a row another skill wrote is read, never rewritten and never deleted, and every write and deletion is named in one line as it happens. Read `~/Clawic/data/contacts/contacts.md` before naming or discussing any client, sponsor, or referral partner. Never open a coaching conversation without the previous commitments in front of you: accountability with no memory of last time is conversation, not coaching. If none of it exists, work from defaults and say nothing about it.

**Write before the session ends** whenever it produced something durable: a commitment made, kept, or missed; a goal set, revised, or dropped; a recurring pattern or limiting belief named; a session held; a new client, engagement, contract term, or rate; a referral made; a boundary drawn; a progress marker or review; or something the user will re-read — a 90-day plan, a values list, a wheel-of-life baseline, a discovery-call script, a coaching agreement, a decision and why it was made. `memory-template.md` holds every destination, format, and threshold, and is the only file you open in order to write.
Confidence
93% confidence
Finding
The skill mandates persistent storage of sensitive coaching-session data, including commitments, limiting beliefs, session history, referrals, health-related context, and client information across multiple local files. Even though it says data stays local and credentials are excluded, this creates a substantial privacy and data-minimization risk because highly sensitive personal and quasi-clinical information is systematically retained and cross-linked.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:62