Back to skill

Security audit

English

Security checks across malware telemetry and agentic risk

Overview

This English coaching skill keeps local learning and contact notes, but the behavior is disclosed, scoped to Clawic data folders, and aligned with its purpose.

Install this if you want an English assistant that remembers your preferences, recurring mistakes, reusable phrases, and how to write to specific people. Review or clear the local Clawic data files if you do not want long-term language or contact-context notes kept across sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The instruction to write user-specific dislikes and style reactions into `config.yaml` and `artifacts/style-sheet.md` introduces persistent state changes beyond simple English correction. That can create unnecessary retention of user preference data and expands the skill's authority from transient editing into cross-session profile building, which is risky if the user did not explicitly consent or if other skills can read those files.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to read user-local contacts and memory files before composing an email, which expands behavior from English editing into collection and use of persistent personal data. That creates unnecessary data access, potential privacy leakage, and hidden context injection from local files unrelated to the immediate editing request.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The skill tells the agent to persist approved phrases, templates, and person-specific communication details into memory and artifact files, which goes beyond the stated purpose of correcting or improving English. Persistent storage of user and third-party preferences increases privacy risk, creates a long-lived data trail, and can be repurposed by other skills or future prompts without clear consent.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to read user-specific memory and contact files before helping with a call or meeting, which exceeds the stated purpose of English correction and creates unnecessary access to personal data. Because the referenced files may contain sensitive relationship history, rehearsed phrases, and contact-specific notes, this expands data exposure and enables contextual profiling beyond what is needed for the immediate task.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill directs persistent recording of conversation outcomes, errors, scripts, and phrasebook entries into memory and session files, which goes beyond transient language assistance and creates a lasting behavioral record. Storing this material by default can capture sensitive workplace interactions, personal speaking patterns, and identifiable contact context without a narrowly defined retention need.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The file explicitly instructs the agent to read user-specific memory files before suggesting idioms, introducing persistent profiling and cross-session state that goes beyond simple English correction. Even if intended to personalize teaching, this creates unnecessary access to retained user preference/history data and increases privacy risk if the data is over-collected, reused outside user expectations, or exposed to other skills/processes.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The instruction to write every acquired or rejected expression into persistent files directs the agent to maintain a lasting user profile of language behavior and preferences. This expands the skill from editing text into ongoing behavioral tracking, which can accumulate sensitive preference/history data without clear necessity for the stated purpose.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs reading and updating persistent files such as memory.md, errors.md, and config.yaml to track user mistakes over time. For an English-correction skill, durable profiling and memory writes go beyond transient text correction and create unnecessary retention of user-derived data, which can expose sensitive personal information or behavioral profiles if misused or accessed by other components.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This section directs the agent to add recurring errors, dates, counts, and vocabulary chunks to persistent records, establishing ongoing user profiling across sessions. That persistence is not necessary for basic English editing and increases the risk of over-collection, unintended disclosure of personal writing content, and use of retained data outside the user's expectations.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The document explicitly instructs the agent to persist user-specific pronunciation targets, progress, due items, and session history into local memory files. For a pronunciation coaching skill, this expands behavior from transient assistance into durable profile building without clear necessity, consent, minimization, or retention limits. This is dangerous because it can accumulate sensitive behavioral data over time and create unauthorized state changes on the user's filesystem.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill directs reading `config.yaml` and user memory files before drilling pronunciation, even though a pronunciation guidance document can operate from the current conversation alone. This is unjustified local data access: it broadens the skill's reach into unrelated user state and may expose personal preferences or prior records beyond what is needed for the immediate task. In context, the English skill description does not establish a need to inspect local files, so the access is more suspicious, not less.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The instructions add session logging, progress tracking, and due-table management, which are broader learner-management features rather than core English correction or pronunciation assistance. This capability creep increases the amount of personal data stored and creates ongoing agent behavior outside the immediate user request. Because the skill's stated purpose is language correction, the extra tracking functionality is insufficiently justified and raises privacy and integrity concerns.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill explicitly instructs the agent to read user-specific contact and memory files before writing to a named person, pulling in persistent relationship history and prior reactions. For an English/register skill, that expands scope from text editing into personal profiling and stateful data access, creating unnecessary privacy and prompt-surface risk if those files contain sensitive notes or unrelated data.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The skill tells the agent to persist relationship-specific interaction notes, including greeting preferences, preferred structure, and pushback history, into local memory files. That is unjustified for a language-editing skill and creates durable storage of behavioral metadata about named individuals, which can later be exposed, misused, or silently influence outputs across sessions.

Ssd 3

Medium
Confidence
96% confidence
Finding
The instruction to read a named person's row in contacts plus phrasebook entries causes the agent to retrieve and use stored preferences and approved phrasings tied to identifiable individuals. This is dangerous because it enables profiling of contacts and cross-session personalization without clear necessity, transparency, or access control for an English-editing skill.

Ssd 3

Medium
Confidence
98% confidence
Finding
The file instructs the agent to save approved phrasings, templates, and named-person preferences into persistent memory and contacts stores, creating durable personal dossiers and reusable communication patterns. In context, this is more dangerous because the skill is presented as language assistance, so users may not expect ongoing surveillance-like retention of their relationships and communication habits.

Ssd 3

Medium
Confidence
98% confidence
Finding
Recording retained preferences and prior accepted/rejected phrases in persistent memory creates a user-specific profile that may reveal habits, communication style, regional identity, and interaction history across sessions. In the context of an English skill, this is more dangerous because the functionality is framed as language help, so users may not reasonably expect durable storage of granular preference data.

Ssd 3

Medium
Confidence
95% confidence
Finding
The file instructs persistent recording of mispronunciations, preferred pronunciations, practice targets, agreed cadence, and dated session entries. Even if not overtly malicious, this creates a durable behavioral record tied to the user, which can reveal language background, habits, and ongoing activity. The context makes it more dangerous because pronunciation coaching does not inherently require long-term storage, so the persistence is disproportionate to the feature's stated purpose.

Ssd 3

Medium
Confidence
96% confidence
Finding
Reading persistent personal interaction history about named individuals across sessions creates a data retention and leakage risk because the model may ingest past notes that are not necessary for the present editing task. In this skill context, the danger is heightened because the files are framed as normal prerequisites, encouraging routine access to accumulated personal context without clear necessity or consent.

Ssd 3

Medium
Confidence
98% confidence
Finding
The instruction to record what named people 'reacted badly to' and other relationship-specific preferences creates a persistent dossier of interpersonal behavior. Such notes are sensitive, easy to over-collect, and can leak through future outputs or unauthorized file access, especially since they are stored as free-form natural language rather than tightly scoped settings.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:63