Back to skill

Security audit

DevOps

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent DevOps guidance, but it automatically reads and updates broad local operational notes, including contacts and spending records, without asking first.

Install only if you want a DevOps skill that keeps persistent local notes and can read or update shared Clawic records about infrastructure, owners, domains, projects, and delivery-tool spending. Review or constrain persistence if you prefer per-task consent, and avoid recording file paths to private keys when a secrets-manager or environment-variable pointer is available.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:40
Finding

Automatic Persistent Access to Broad Shared Data Stores Without Explicit Consent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs storing pointers to credentials, including a direct reference to a private SSH key path (file:~/.ssh/id_ed25519). Even without storing the key material itself, normalizing and persisting a pointer to a sensitive credential file encourages the agent to identify and record high-value credential locations, which can materially aid later credential targeting or misuse by other compromised components.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
**Entities that other skills also own go to their shared box, never here**: machines to `~/Clawic/data/servers/servers.md`, people who own or carry a pager to `~/Clawic/data/contacts/contacts.md`, tracked delivery work to `~/Clawic/data/projects/<project>.md`, hostnames and certificate expiry to `~/Clawic/data/domains/domains.md`, delivery-tool spend to `~/Clawic/data/finances/subscriptions.md`. Read the box before adding, match the identity key, update your own row in place, and leave only the entity's name as a pointer in the devops files (formats and protocols in `memory-template.md`).

**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted pipeline file, `.env`, terraform output, or incident log is the densest source of secrets there is: strip the value and store the pointer — `env:DEPLOY_TOKEN`, `vault:secret/ci/deploy`, `1password:Work/CI/prod`, `ssm:/prod/db/password`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/devops/` or `~/clawic/devops/`), move it to `~/Clawic/data/devops/`, and say in one line that you moved it and from where.

Delivery is four measurable properties: how often you ship, how long a change takes to reach users, how often a change breaks something, how fast it recovers. Every recommendation names which of the four it moves and what it costs. Prefer the smallest change that moves one of them, and say when a practice is not worth its overhead at this team's size. Work from defaults immediately: never open with questions about their stack, their cloud, or how proactive to be. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: currency, timezone) → the Configuration table default.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |

Memory Manipulation

High
Category
Memory Poisoning
Confidence
90% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · iac-workflow.md (reported line 72)May include surrounding context.

md
- Locking must be real (a backend that supports it). Two concurrent applies against one state corrupt it, and recovery costs hours.
- Refresh behavior matters: a plan that skips refresh is fast and can be wrong; one that refreshes is slow and true. Pick deliberately per layer, and refresh before anything destructive.
- Destroy is a separate, manually invoked job with a typed confirmation of the environment name. It never lives in the same job as apply.
- Keep state backends versioned so a corrupt state can be rolled back to the previous revision — this is the only real recovery for state loss.

## Module Releases

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 67)May include surrounding context.

md
## Secrets

Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 75)May include surrounding context.

md
## Secrets

Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 69)May include surrounding context.

md
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`

In a text, the pointer goes where the value was: `DATABASE_URL: postgres://app:<ssm:/prod/db/password>@db.internal/app`. Say in one line that you did it.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 307)May include surrounding context.

md
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`

In a text, the pointer goes where the value was: `DATABASE_URL: postgres://app:<ssm:/prod/db/password>@db.internal/app`. Say in one line that you did it.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The declared access includes contacts and financial subscription data, which are more sensitive than ordinary DevOps configuration and are not clearly necessary for many DevOps workflows. Even if intended for pager ownership or tooling spend tracking, this broad default access increases privacy exposure and the blast radius of misuse or prompt-injection-driven data harvesting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that data stays in local DevOps notes, but it explicitly reads from and writes to several shared data domains such as servers, contacts, projects, domains, and finances. This creates a scope-expansion and data-minimization issue: a DevOps skill gains access to unrelated or more sensitive records than users may reasonably expect from the manifest language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

This file directs the operator to modify a GitOps repo and identifies rollback targets, which can affect live deployment state. While later sections discuss operational mechanics, the document does not provide an upfront warning that commits or reverts may trigger production changes and should be performed carefully.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · incidents.md (reported line 15)May include surrounding context.

md
| Level | Impact | Response | Comms |
|---|---|---|---|
| Sev1 | Core journey broken or data at risk, for most users | Page immediately, all hands allowed, rollback authority without approval | Status page and stakeholder update on a fixed cadence |
| Sev2 | Degraded or partial: one journey, one region, one large customer | Page during hours the rotation covers; escalate if unresolved within a stated time | Internal channel plus affected-customer notice |
| Sev3 | Contained: workaround exists, no budget burn of consequence | Ticket, next business day | Ticket only |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · incidents.md (reported line 83)May include surrounding context.

md
| What went well | Genuinely — the parts that worked are the parts to protect during the next reorganization |
| Action items | Owned, dated, tracked (below) |

- **Blameless means the system is the subject.** "Engineer ran the wrong command" is not a finding; "the command that drops the table is one character from the one that describes it, with no confirmation" is.
- Counterfactuals are not findings. "If we had noticed sooner" describes a wish; "the alert evaluates a 15-minute window, so detection could not have been faster than 15 minutes" describes a system.
- Time-to-detect, time-to-mitigate, and time-to-resolve are three separate numbers. Recording them separately is what tells you whether to invest in alerting, in runbooks, or in architecture.
- Small incidents deserve short postmortems. A four-page template for a 10-minute blip guarantees nobody writes them at all.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · platform.md (reported line 30)May include surrounding context.

md
One well-supported way to build, test, deploy, observe, and page for a new service — documented, templated, and actually used by the team that maintains it.

- The test is a stopwatch: **from `git init` to a running, monitored, deployable service in production**, how long? Teams with a real golden path measure this in hours; teams without measure it in weeks of copying an existing repo and inheriting its mistakes.
- A template is a starting point, not a cage. Every generated service must be editable by its owners without asking permission, or teams fork the template and the path dies.
- Templates rot. Whoever owns the path owns keeping it current with the practices in this skill, and a way to tell existing services what changed — a template with no update mechanism guarantees a fleet of divergent snowflakes.
- Adoption is voluntary but the path is subsidized: teams on the path get the pipeline, the dashboards, the alerts, and the runbook skeleton for free. Teams off it own all of it. Mandates produce compliance theater; a genuinely cheaper path produces adoption.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for delivery execution concerns such as pipelines, deployments, rollback strategy, reliability, secrets hardening, and on-call practice, and explicitly says image builds belong elsewhere. This file is centered on artifact identity, provenance, signing, SBOMs, vulnerability triage, and dependency supply-chain controls, which is a materially different operational domain than the stated skill scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description lists many natural-language 'use when' conditions such as 'when builds are slow' or 'when alerts are noisy' without defining specific trigger phrases or activation boundaries. Although domain-focused, the activation guidance is expansive enough that the skill could be invoked in a wide range of routine software discussions, increasing the chance of unintended selection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.