Back to skill

Security audit

Ecommerce

Security checks across malware telemetry and agentic risk

Overview

This ecommerce skill stores local operational notes and has privacy guardrails; the scanner concerns are real cautions but are mostly disclosed and purpose-aligned.

Before installing, be comfortable with the skill keeping local ecommerce memory under ~/Clawic/data, including business contacts, supplier/wholesale terms, metrics, deadlines, and incident summaries. Do not use its legal, tax, email, SMS, or consumer-law guidance without checking the current rules for your jurisdiction and ensuring marketing consent, opt-out handling, and retention practices are correct.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Defaulting legal and fiscal behavior from `profile.yaml` or assumptions creates a hidden trust boundary: shared profile data or unstated assumptions can drive compliance recommendations without the user's active approval in the current session. In a skill that covers taxes and consumer law, this increases the chance of incorrect registration, disclosure, or filing advice.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Defaulting legal and fiscal behavior from `profile.yaml` or assumptions creates a hidden trust boundary: shared profile data or unstated assumptions can drive compliance recommendations without the user's active approval in the current session. In a skill that covers taxes and consumer law, this increases the chance of incorrect registration, disclosure, or filing advice.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The skill explicitly instructs the agent to write account terms, named contacts, tax numbers, credit limits, and related business data into shared memory files without any user-facing consent prompt, minimization guidance, or data-handling boundary. While this appears operationally motivated rather than malicious, it can cause unnecessary propagation of sensitive commercial and personal data into shared stores, increasing privacy, confidentiality, and retention risk.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill gives operational guidance for abandoned-cart email and SMS sequences but omits any warning that these messages must be conditioned on lawful consent, jurisdictional marketing rules, and platform policies. In an ecommerce skill, this omission is more dangerous because users are likely to implement the workflow directly, creating risk of unlawful marketing outreach, complaints, spam filtering, or regulatory exposure.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The document tells operators to write support outcomes into metrics, pain points, and incident files, which creates a real risk that customer-specific details are copied into persistent markdown records outside controlled support systems. Although it earlier says transcripts and identities may not be stored, the later instruction is broad enough that staff or downstream agents could still record incident details containing personal data, increasing privacy, retention, and unauthorized disclosure risk.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:73