Back to skill

Security audit

Journal

Security checks for vulnerabilities and agentic risk

Overview

This is a local journaling skill that stores sensitive personal notes and metadata, but its file access is disclosed, bounded to named local folders, and aligned with its purpose.

Install only if you are comfortable with a skill creating and maintaining a plaintext local journal corpus, including entries, prompt history, no-go topics, mood ratings, reviews, and some neutral shared records. Check `agent_read_scope`, `no_go_file`, backup/sync choices, and shared health/finance/contact paths before using it with highly sensitive material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (40)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
**Neutral fields leave the journal folder; content never does.** A mood rating goes to the shared series `~/Clawic/data/health/mood.md` so sleep, fitness, and health skills read the same numbers. A person becomes a row in `~/Clawic/data/contacts/contacts.md` only when the user asks for it, and the row carries their name and channel, never a line of what was written about them. A decision that belongs to a tracked project leaves a one-sentence summary in `~/Clawic/data/projects/<project>.md`, and a salary or subscription figure the user asks to track goes to `~/Clawic/data/finances/`. Formats, identity keys, and the write protocol for all four: `memory-template.md`.

**No credential is ever written anywhere under `~/Clawic/data/`** — not in an entry, not in a file you create, not in text the user pastes in to be saved. People vent about work with a token still in the log they copied. Strip the value and leave the pointer where it was: `env:API_KEY`, `keychain:work-vpn`, `1password:Personal/Bank`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/journal/` or `~/clawic/journal/`), move it to `~/Clawic/data/journal/`, and say in one line that you moved it and from where.

Journaling fails for one of three reasons: the page is blank, the practice lapsed, or nobody ever reads it back. Everything here serves one of those three. Default posture is scribe, not editor and not therapist: capture first, respond short, interpret only when asked. Work from defaults immediately — never open with questions about their method, their schedule, or how much you should read. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, timezone) → the Configuration table default.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 69)May include surrounding context.

md
**Neutral fields leave the journal folder; content never does.** A mood rating goes to the shared series `~/Clawic/data/health/mood.md` so sleep, fitness, and health skills read the same numbers. A person becomes a row in `~/Clawic/data/contacts/contacts.md` only when the user asks for it, and the row carries their name and channel, never a line of what was written about them. A decision that belongs to a tracked project leaves a one-sentence summary in `~/Clawic/data/projects/<project>.md`, and a salary or subscription figure the user asks to track goes to `~/Clawic/data/finances/`. Formats, identity keys, and the write protocol for all four: `memory-template.md`.

**No credential is ever written anywhere under `~/Clawic/data/`** — not in an entry, not in a file you create, not in text the user pastes in to be saved. People vent about work with a token still in the log they copied. Strip the value and leave the pointer where it was: `env:API_KEY`, `keychain:work-vpn`, `1password:Personal/Bank`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/journal/` or `~/clawic/journal/`), move it to `~/Clawic/data/journal/`, and say in one line that you moved it and from where.

Journaling fails for one of three reasons: the page is blank, the practice lapsed, or nobody ever reads it back. Everything here serves one of those three. Default posture is scribe, not editor and not therapist: capture first, respond short, interpret only when asked. Work from defaults immediately — never open with questions about their method, their schedule, or how much you should read. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, timezone) → the Configuration table default.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
- Streaks work until the first break, then they invert: the counter that motivated on day 20 is the reason someone does not come back on day 21. This is the mechanism behind most abandoned journals, and it is why `nudge` defaults to false.
- If the user wants a streak, use two counters, not one: **current run** and **entries in the last 30 days**. The second one survives a break, which is exactly what the first one cannot do.
- Never display a broken streak unprompted. The number is stored in `## Practice`; showing it after a lapse is a punishment with no upside.
- A "streak" that is being maintained with one-word entries is worth naming once, without judgment: the floor is doing its job, and it is also hiding that the practice has become a checkbox.

## Nudging

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · consistency.md (reported line 62)May include surrounding context.

md
- Streaks work until the first break, then they invert: the counter that motivated on day 20 is the reason someone does not come back on day 21. This is the mechanism behind most abandoned journals, and it is why `nudge` defaults to false.
- If the user wants a streak, use two counters, not one: **current run** and **entries in the last 30 days**. The second one survives a break, which is exactly what the first one cannot do.
- Never display a broken streak unprompted. The number is stored in `## Practice`; showing it after a lapse is a punishment with no upside.
- A "streak" that is being maintained with one-word entries is worth naming once, without judgment: the floor is doing its job, and it is also hiding that the practice has become a checkbox.

## Nudging

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · consistency.md (reported line 71)May include surrounding context.

md
- **Nudge with an opening, not a reminder.** "You mentioned the interview was Thursday — want to write about it?" works; "you haven't journaled in 5 days" is a guilt notification and produces avoidance.
- One nudge per lapse, ever. A second one for the same gap converts the tool into a nag and the practice into an obligation.
- Never nudge during a period the user has described as hard, and never nudge from a Red Flags context — that is a check-in, not a streak reminder (SKILL.md Red Flags).
- On-this-day resurfacing ("a year ago you wrote about the move") is a separate opt-in from streak nudges, because it can surface grief material without warning. Off unless asked, and never for entries in `## Read Scope`.

## Diagnosing A Lapse

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · difficult-entries.md (reported line 115)May include surrounding context.

md
1. **Stop the protocol.** No prompt, no analysis, no streak, no review, no interpretation.
2. **Say what you read, plainly, in one or two sentences.** Not a diagnosis: the observable thing, and that you noticed it.
3. **Ask who they can talk to now** — a person, a clinician, or a crisis line. Their local emergency number and crisis line, if you can identify the country from `~/Clawic/profile.yaml`; otherwise ask.
4. **Keep capturing if they want to keep writing.** Do not refuse the entry. Removing the outlet mid-crisis helps nobody.
5. **Do not write your risk assessment into the entry file** (Rule 9 and `privacy.md`). One dated line in `## Escalations` of `memory.md`: date, what was observed, what was said, nothing quoted.
6. **Do not surface it later unprompted.** If the user returns to it, the record exists.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file directs the agent to log rejected prompts and topics the user never wants prompted again, which are highly sensitive preference and boundary signals, without any warning that this data will be persistently recorded. In a journal skill, these records can expose avoided subjects, emotional triggers, or personal history, making undisclosed storage especially dangerous.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · prompts.md (reported line 98)May include surrounding context.

md
- After ~10 entries, the situation table matters less than the record: which prompts produced long entries for this person and which produced two lines.
- A prompt "landed" if it produced an entry the user did not stop early. A prompt "flopped" if they changed the subject, wrote under two lines, or said no.
- Prompt families are personal and stable: some people never answer emotion prompts and always answer description prompts. Once three prompts in a family have flopped, stop offering that family and say nothing about it.

**Write in the same turn:** every prompt offered, with landed/flopped and the date, to `## Prompts That Land` in `memory.md` (or `prompt-log.md` once it has split); a topic the user asks never to be prompted about, to `no_go_file`; a prompt the user invents and likes, to the same log marked `own`. Formats: `memory-template.md`.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to write prompt outcomes, dates, user-invented prompts, and no-go topics in the same turn mandates immediate capture of sensitive journaling metadata without any visible notice or confirmation. Same-turn persistence reduces the chance for informed user choice and can silently accumulate a detailed behavioral profile over time.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The same-turn write requirement explicitly requires persistent storage of prompt outcomes, dates, no-go topics, and user-created prompts, creating a structured and sensitive record of journaling behavior. Because journaling often involves intimate personal material, this persistence can materially increase harm from misuse, over-collection, or unauthorized access.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · review.md (reported line 15)May include surrounding context.

md
2. **Count before you conclude.** Every claim carries its numbers: entries in the window, days covered, how many mention the theme. Rule 7's bar decides whether a count becomes a pattern.
3. **The output is short and it is written down.** A review that lives only in the chat is a review that never gets referenced, which means the next one repeats it. It goes to `reviews/<year>.md`.
4. **One carry-forward, maximum three.** A review that produces nine intentions produces zero. The carry-forward goes to `## Open Threads` and gets checked at the next review by name.
5. **Do not moralize the numbers.** "Three entries this week" is a fact. Whether that is a problem is the user's call, and a nudge in a review is still a nudge (`consistency.md`).
6. **Excluded material stays excluded.** Morning pages, expressive-writing days, grief entries, and anything in `## Read Scope` are not review inputs unless the user says otherwise, and their absence is stated in one line so a partial review is never presented as a complete one.

## Weekly

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · review.md (reported line 99)May include surrounding context.

md
Resurfacing an entry from one, three, or five years ago on the same date.

- **Opt-in only**, separate from `nudge`, because it can surface a death, a breakup, or a diagnosis with no warning.
- Exclude anything in `## Read Scope` or `no_go_file`, and exclude the grief corpus unless the user explicitly included it.
- Deliver it as the entry's opening line and its date, never as a summary. The user decides whether to open it.
- Its real value is calibration: last year's crisis, read today, recalibrates today's crisis better than any reframe you could write.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · storage.md (reported line 112)May include surrounding context.

md
Resurfacing an entry from one, three, or five years ago on the same date.

- **Opt-in only**, separate from `nudge`, because it can surface a death, a breakup, or a diagnosis with no warning.
- Exclude anything in `## Read Scope` or `no_go_file`, and exclude the grief corpus unless the user explicitly included it.
- Deliver it as the entry's opening line and its date, never as a summary. The user decides whether to open it.
- Its real value is calibration: last year's crisis, read today, recalibrates today's crisis better than any reframe you could write.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s description repeatedly frames journaling as confined to a journal-local corpus, but its actual config paths and instructions authorize reading and writing across health, contacts, projects, finances, and profile data. That broadens the accessible sensitive-data surface and can mislead users and downstream policy engines about what the skill may touch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to keep photographed handwritten pages as copied image files alongside entries, but does not require notifying the user that media will be retained as separate artifacts. Retaining copied images can preserve more sensitive information than the transcription alone, including metadata or visible incidental content, and may surprise users who only expected text capture.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to write mood information from a journaling interaction into a separate health record file, which expands data use beyond the primary journal entry without an explicit per-action consent step. Because mood data is sensitive health-adjacent information, this creates a privacy and scope-creep risk if users do not clearly understand that journaling disclosures will populate another dossier.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Writing to a separate health tracking file is not necessary to save a journal entry and creates an additional sensitive-data sink. This increases the chance of overcollection, unexpected profiling, and later reuse of emotional-state data outside the narrow purpose the user likely intended when asking to journal.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions direct writes to several files in one turn: the entry itself, memory.md sections, read-scope metadata, and possibly a health file, without requiring a user-facing warning or confirmation. Hidden multi-file side effects are dangerous because users may believe they are creating a single journal entry while the agent is also updating behavioral memory and privacy-related metadata elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This instruction tells the agent to write to memory.md, config.yaml, and ## Due as part of the same turn, but the file provides no explicit requirement to obtain fresh user confirmation before modifying persistent files or settings. In a journaling skill, these writes may store sensitive behavioral and emotional metadata, so silent persistence increases privacy and integrity risk even if the feature is intended.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to write the entry itself verbatim in the same turn, alongside escalation metadata and other artifacts, creates a data-retention and cross-surface disclosure risk for highly sensitive crisis content. In this skill, the material explicitly includes trauma, abuse, shame, and crisis situations, so preserving exact text increases the chance that sensitive content is stored, indexed, surfaced in later reviews, or exposed through adjacent features.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template explicitly directs the journal skill to write durable user data into shared health, contacts, projects, and finances stores, which expands data collection and propagation beyond core journaling. Even if framed as user-requested, cross-skill persistence increases privacy risk, broadens access by other skills, and can cause sensitive personal data to surface in unrelated contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Directing a journaling skill to store compensation and subscription figures in shared finance storage is a data-scope expansion into financial records. This creates unnecessary aggregation of sensitive financial information and raises the chance of secondary use, exposure to other skills, or incorrect assumptions that the journal is authorized to manage finance data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example config includes a concrete default entry_language value ('german'), which can cause the agent to apply a language preference the user never declared. In a journaling context, silently imposing language affects data integrity, usability, and may alter how sensitive reflections are captured or interpreted.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · memory-template.md (reported line 150)May include surrounding context.

md
| Annual review | year, mid-January | 2026-01-14 | 2027-01-14 |

## Practice
Started 2021-03. Daily entries, evening slot, dictated on the walk home; typed at weekends.
Current run 12 days, longest 96, 22 entries in the last 30 days. Floor: one sentence.
Morning pages tried 2024, dropped after 3 weeks — "felt like homework". Do not re-recommend.
2025-11: migrated from Day One (JSON export kept). 2019-2020 entries lost their times, dates intact.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file instructs the agent to write derived analysis, mood data, and exclusions directly into user files in the same turn, but it does not require an explicit confirmation or user-facing notice before modifying persistent data. In a journaling context, these writes can alter sensitive personal records, create new health-related data, and persist inferred labels that may later be treated as authoritative, so silent modification is risky even if operationally convenient.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.