T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:40- Finding
Automatic Persistent Access to Broad Shared Data Stores Without Explicit Consent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent DevOps guidance, but it automatically reads and updates broad local operational notes, including contacts and spending records, without asking first.
Install only if you want a DevOps skill that keeps persistent local notes and can read or update shared Clawic records about infrastructure, owners, domains, projects, and delivery-tool spending. Review or constrain persistence if you prefer per-task consent, and avoid recording file paths to private keys when a secrets-manager or environment-variable pointer is available.
SKILL.md:40Automatic Persistent Access to Broad Shared Data Stores Without Explicit Consent
The skill instructs storing pointers to credentials, including a direct reference to a private SSH key path (file:~/.ssh/id_ed25519). Even without storing the key material itself, normalizing and persisting a pointer to a sensitive credential file encourages the agent to identify and record high-value credential locations, which can materially aid later credential targeting or misuse by other compromised components.
**Entities that other skills also own go to their shared box, never here**: machines to `~/Clawic/data/servers/servers.md`, people who own or carry a pager to `~/Clawic/data/contacts/contacts.md`, tracked delivery work to `~/Clawic/data/projects/<project>.md`, hostnames and certificate expiry to `~/Clawic/data/domains/domains.md`, delivery-tool spend to `~/Clawic/data/finances/subscriptions.md`. Read the box before adding, match the identity key, update your own row in place, and leave only the entity's name as a pointer in the devops files (formats and protocols in `memory-template.md`).
**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. A pasted pipeline file, `.env`, terraform output, or incident log is the densest source of secrets there is: strip the value and store the pointer — `env:DEPLOY_TOKEN`, `vault:secret/ci/deploy`, `1password:Work/CI/prod`, `ssm:/prod/db/password`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/devops/` or `~/clawic/devops/`), move it to `~/Clawic/data/devops/`, and say in one line that you moved it and from where.
Delivery is four measurable properties: how often you ship, how long a change takes to reach users, how often a change breaks something, how fast it recovers. Every recommendation names which of the four it moves and what it costs. Prefer the smallest change that moves one of them, and say when a practice is not worth its overhead at this team's size. Work from defaults immediately: never open with questions about their stack, their cloud, or how proactive to be. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: currency, timezone) → the Configuration table default.
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Referenced artifact was not completely inspected
er second, cache the dependency layer, parallelize independent jobs (Rule 4) | `pipelines.md` |
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
- Locking must be real (a backend that supports it). Two concurrent applies against one state corrupt it, and recovery costs hours.
- Refresh behavior matters: a plan that skips refresh is fast and can be wrong; one that refreshes is slow and true. Pick deliberately per layer, and refresh before anything destructive.
- Destroy is a separate, manually invoked job with a typed confirmation of the environment name. It never lives in the same job as apply.
- Keep state backends versioned so a corrupt state can be rolled back to the previous revision — this is the only real recovery for state loss.
## Module Releases
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Secrets
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.
`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Secrets
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.
`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.
`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`
In a text, the pointer goes where the value was: `DATABASE_URL: postgres://app:<ssm:/prod/db/password>@db.internal/app`. Say in one line that you did it.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted pipeline file, `.env`, terraform output, kubeconfig, or incident log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.
`env:DEPLOY_TOKEN` · `vault:secret/ci/deploy` · `ssm:/prod/db/password` · `secretsmanager:prod/api/key` · `gcp-sm:projects/acme/secrets/deploy` · `azure-kv:prod-vault/deploy` · `keychain:ci-runner` · `1password:Work/CI/prod` · `bitwarden:CI/registry` · `profile:prod` · `file:~/.ssh/id_ed25519`
In a text, the pointer goes where the value was: `DATABASE_URL: postgres://app:<ssm:/prod/db/password>@db.internal/app`. Say in one line that you did it.
The declared access includes contacts and financial subscription data, which are more sensitive than ordinary DevOps configuration and are not clearly necessary for many DevOps workflows. Even if intended for pager ownership or tooling spend tracking, this broad default access increases privacy exposure and the blast radius of misuse or prompt-injection-driven data harvesting.
The skill states that data stays in local DevOps notes, but it explicitly reads from and writes to several shared data domains such as servers, contacts, projects, domains, and finances. This creates a scope-expansion and data-minimization issue: a DevOps skill gains access to unrelated or more sensitive records than users may reasonably expect from the manifest language.
This file directs the operator to modify a GitOps repo and identifies rollback targets, which can affect live deployment state. While later sections discuss operational mechanics, the document does not provide an upfront warning that commits or reverts may trigger production changes and should be performed carefully.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Level | Impact | Response | Comms |
|---|---|---|---|
| Sev1 | Core journey broken or data at risk, for most users | Page immediately, all hands allowed, rollback authority without approval | Status page and stakeholder update on a fixed cadence |
| Sev2 | Degraded or partial: one journey, one region, one large customer | Page during hours the rotation covers; escalate if unresolved within a stated time | Internal channel plus affected-customer notice |
| Sev3 | Contained: workaround exists, no budget burn of consequence | Ticket, next business day | Ticket only |
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| What went well | Genuinely — the parts that worked are the parts to protect during the next reorganization |
| Action items | Owned, dated, tracked (below) |
- **Blameless means the system is the subject.** "Engineer ran the wrong command" is not a finding; "the command that drops the table is one character from the one that describes it, with no confirmation" is.
- Counterfactuals are not findings. "If we had noticed sooner" describes a wish; "the alert evaluates a 15-minute window, so detection could not have been faster than 15 minutes" describes a system.
- Time-to-detect, time-to-mitigate, and time-to-resolve are three separate numbers. Recording them separately is what tells you whether to invest in alerting, in runbooks, or in architecture.
- Small incidents deserve short postmortems. A four-page template for a 10-minute blip guarantees nobody writes them at all.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
One well-supported way to build, test, deploy, observe, and page for a new service — documented, templated, and actually used by the team that maintains it.
- The test is a stopwatch: **from `git init` to a running, monitored, deployable service in production**, how long? Teams with a real golden path measure this in hours; teams without measure it in weeks of copying an existing repo and inheriting its mistakes.
- A template is a starting point, not a cage. Every generated service must be editable by its owners without asking permission, or teams fork the template and the path dies.
- Templates rot. Whoever owns the path owns keeping it current with the practices in this skill, and a way to tell existing services what changed — a template with no update mechanism guarantees a fleet of divergent snowflakes.
- Adoption is voluntary but the path is subsidized: teams on the path get the pipeline, the dashboards, the alerts, and the runbook skeleton for free. Teams off it own all of it. Mandates produce compliance theater; a genuinely cheaper path produces adoption.
The manifest describes a skill for delivery execution concerns such as pipelines, deployments, rollback strategy, reliability, secrets hardening, and on-call practice, and explicitly says image builds belong elsewhere. This file is centered on artifact identity, provenance, signing, SBOMs, vulnerability triage, and dependency supply-chain controls, which is a materially different operational domain than the stated skill scope.
The manifest description lists many natural-language 'use when' conditions such as 'when builds are slow' or 'when alerts are noisy' without defining specific trigger phrases or activation boundaries. Although domain-focused, the activation guidance is expansive enough that the skill could be invoked in a wide range of routine software discussions, increasing the chance of unintended selection.
No suspicious patterns detected.