Back to skill

Security audit

Freelance

Security checks across malware telemetry and agentic risk

Overview

This skill is a local freelance-business assistant that stores business notes on the user's machine, with no evidence of credential theft, network exfiltration, or hidden execution.

Install this only if you are comfortable with the assistant keeping local freelance business records under ~/Clawic/data, including contacts, terms, quote history, dispute notes, and financial references. Review those files periodically and avoid pasting secrets or client-confidential material unless it can be stripped to a pointer as the skill instructs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file explicitly instructs the agent to persistently modify config, memory, and artifact files based on user statements and inferred conventions. That exceeds a passive reference role and creates state-changing behavior that can be triggered by ordinary conversation, risking unauthorized persistence, prompt-injection propagation into memory, and unintended cross-session effects.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The instruction to create reusable artifact documents on disk introduces a file-generation capability not necessary for a trade-norms guidance document. If acted on automatically, user-provided content could be turned into persistent templates or scope wording, enabling storage of poisoned instructions or unauthorized document creation that influences later workflows.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to write conclusions into fixed local files under ~/Clawic/data/freelance/ without any explicit confirmation step or warning that user data will be modified. Even though this appears intended as normal state/memory management for the skill, it creates a real risk of unintended persistent changes, especially if the assessment is wrong, premature, or triggered in the wrong context.

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill explicitly instructs writing negotiated terms and clause sets into persistent local files, but it does not require an explicit user confirmation or warning before modifying stored data. In an agent setting, this can lead to unintended persistence, overwriting prior records, or silent accumulation of sensitive contractual metadata in local memory.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to create and store dispute artifacts containing dates, amounts, and client-specific dispute history in persistent records, but it does not clearly warn about privacy, confidentiality, retention, or access control. In a freelance context, those records can contain personal data, commercially sensitive facts, or allegations that may later be inaccurate, creating unnecessary disclosure, compliance, and reputational risk if stored in shared locations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file advises marking shared contact records with adverse client history, which can propagate sensitive allegations across a team without a strong privacy, confidentiality, or defamation safeguard. Although it says to avoid slurs and keep notes factual, it still encourages persistent adverse labeling in a shared system, which can expose the operator to legal or contractual disputes if the record is inaccurate, overbroad, or visible to people who do not need it.

Missing User Warnings

Low
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to write a decision file and update memory data under ~/Clawic/data without requiring user confirmation or warning that local files will be modified. In an agent setting, this can cause unintended persistent state changes, overwrite prior notes, or create privacy/integrity issues if the user did not intend the skill to perform file writes.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The template authorizes writes and deletions with "No permission needed" and permits in-place rewrites of durable user data. In an agent setting, allowing destructive file operations without an explicit confirmation step increases the risk of accidental data loss, corruption, or unauthorized modification triggered by ambiguous prompts or model mistakes.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The split procedure instructs the agent to move content and then delete the original section from memory.md in the same turn, with no confirmation or rollback safeguard. If the agent miscounts entries, chooses the wrong section, or partially fails the move, it can orphan or destroy data while appearing to follow the template correctly.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill directs the agent to add any newly met person to a shared contacts file with identifying details, but provides no data-minimization, consent, retention, or sensitivity guardrails. In a freelancing workflow this can lead to unnecessary collection and persistence of personal data about prospects or third parties, creating privacy, compliance, and leakage risk if the shared file is broadly accessible or later reused for unrelated outreach.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs persistent logging of quote data in a long-lived memory file, including client identity, pricing, outcome, reasons, and potentially competitor pricing, but gives no minimization, consent, retention, or sensitivity guidance. In an agent context, this can cause accumulation of commercially sensitive or personal data that may later be exposed, misused, or retained longer than necessary.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill tells the agent to write to config and memory files without any user-facing disclosure or consent mechanism in the content itself. Silent persistence is dangerous because users may believe they are only receiving advice while the agent is actually altering long-lived state, which can affect future decisions, privacy, and system behavior.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.