Back to skill

Security audit

CRM

Security checks for vulnerabilities and agentic risk

Overview

The skill maintains local CRM and contact records, including durable notes and controlled cleanup actions, and its sensitive behavior is disclosed and aligned with that purpose.

Install only if you want the agent to maintain CRM records in local Clawic files, including shared contacts. Before using it on real customer or prospect data, review the configured data paths, set a conservative safety_posture, require confirmation for deletions and bulk changes, and avoid storing credentials or unnecessary sensitive personal details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance explicitly tells users to 'Delete or archive the rest from view' during CRM revival, but it does not include safeguards such as backup, export, soft-delete, retention review, or recovery instructions. In a CRM context, deleting records can permanently remove customer history, contact data, consent status, or compliance-relevant records, so omission of loss-prevention steps creates a real operational and legal risk even if the intent is process simplification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file instructs the operator to delete people from a shared non-CRM contacts store as part of CRM hygiene, which crosses the declared boundary of this skill and can remove unrelated personal or operational data. Because this is a destructive action against a shared dataset, an agent following it could cause unintended data loss outside the CRM domain without clear user confirmation or scope checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown includes a deletion instruction for shared contacts but does not require an explicit warning, preview, or confirmation before destructive action. In an agent setting, this raises the risk of silent or overbroad deletion, especially since the target is a shared file outside the CRM and the surrounding text frames the step as routine hygiene.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guidance explicitly instructs copying imported CRM people into a separate shared contacts store, which broadens the data footprint beyond the CRM’s stated scope and creates a second repository for personal data. This increases the chance of unauthorized access, inconsistent deletion/unsubscribe handling, and privacy compliance failures because contact records may persist in one system after being removed or restricted in the other.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · memory-template.md (reported line 52)May include surrounding context.

md
Everything except interactions, closed deals, the suppression list, artifacts, `db/` and the shared boxes begins inside `memory.md`. Splitting is a procedure, not a suggestion:

1. Before appending to a section, count its entries.
2. If the append would take it past **~15 entries or ~40 lines of real content** — scaffolding, headings and comments do not count — then, in the same turn: create the new file in `~/Clawic/data/crm/`, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file.
3. Keep the headings identical on both sides of the move, so the split is a copy-paste and never a rewrite.
4. Never leave a copy behind. If the same data ever appears in both places, the extracted file wins and the `memory.md` copy is deleted.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction explicitly tells the agent to overwrite the current month's row in a user memory file and to split data into another file, which is a state-changing filesystem operation. Because it does not require confirmation, backup, or a dry-run summary before modifying CRM records, it creates a real risk of unintended data loss, duplication mistakes, or destructive edits to user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to store identifiable contact data and relationship metadata across shared files without an immediate, explicit warning about minimizing personal data, securing access, or handling consent-sensitive fields. In a CRM context this can lead to over-collection, inappropriate retention, or insecure storage of personal information, especially because the workflow is framed as a default operating procedure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guidance to log interviewer names, what they cared about, and promised follow-ups encourages storing potentially sensitive professional and interpersonal notes without a contemporaneous warning about discretion, minimization, or lawful handling. In job-search and networking contexts, subjective notes can become privacy-sensitive, reputationally harmful, or problematic if shared, retained too long, or stored insecurely.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · privacy.md (reported line 62)May include surrounding context.

md
6. **Confirm in writing**, listing what was done, what was retained and on what basis.
7. **Record the completion** in `do-not-contact.md` (the entry) and `## Data Health` (the pass), with dates.

An objection to marketing needs no verification debate and no delay: suppress on the same day.

## Every Copy

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · privacy.md (reported line 99)May include surrounding context.

md
## Purchased Lists And Enrichment

- **A purchased list has no consent and usually no defensible legitimate interest for personal addresses.** Under GDPR, contacting people on it is the highest-risk thing a small CRM does; a business role address at a business domain is the defensible end of the spectrum, a personal address is not.
- If a list is used, you still owe **notice at first contact**: who you are, where the data came from, and how to opt out. That is an obligation, not a courtesy.
- **Enrichment vendors** are a processing relationship: you need to know what they hold, and their data becomes yours to defend. Enriching company-level attributes (size, sector, tech) carries a fraction of the risk of enriching personal contact details.
- Scraping a platform that forbids it is a contract problem on top of a data-protection one. Do not.

Static analysis

No suspicious patterns detected.