Back to skill

Security audit

JSON

Security checks for vulnerabilities and agentic risk

Overview

This JSON helper is not clearly malicious, but it should be reviewed because it automatically reads, writes, moves, and deletes persistent local/shared notes without asking first.

Review this skill before installing if you do not want an agent to maintain a persistent JSON knowledge base in your home directory. Its technical JSON guidance is useful and it discloses local-only storage plus redaction rules, but it also tells the agent to read prior notes automatically and to save, reorganize, and delete local/shared Clawic records without asking for approval each time.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:34
Finding

Automatic Cross-Session Access to Dynamically Indexed User Files

Content
View full analysis
.md` before proposing a payload shape, a schema, or a format change for work the user tracks as a project. If none of it exists, work from defaults and say nothing about it. ``` ### Technical Analysis The Skill requires the agent to read persistent configuration and memory at the beginning of every session, regardless of whether the current JSON task needs that information. It also treats the mutable `## Boxes` index as an extensible source of additional files to open. Restricting indexed paths to `~/Clawic/data/` limits filesystem scope, but it does not provide least-privilege isolation within that directory. The declared configuration paths include shared project and contact data. Consequently, unrelated historical, project, or personal context can be loaded into the active agent session without a task-specific need or explicit approval. The instruction to read files according to ...[truncated 1404 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
memory-template.md:22
Finding

Persistent Shared-State Writes, Moves, and Deletions Without Prior Authorization

Content
View full analysis
.md`**, not only here: one file per project, identified by the project name, holding objective, status and decisions taken — so the reason a wire format was chosen is where the rest of the project's decisions live. Read it before writing, update the decision in place rather than appending a second one, and never rewrite headings that another skill created. **No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in a payload, curl command, or `.env` the user pastes in to be saved. Strip the value and store the pointer in its place: `env:API_TOKEN`, `keychain:stripe-live`, `1password:Work/Vendor/webhook`, `ssm:/prod/webhook/secret`, `file:~/.config/app/creds.json`. S ...[truncated 4936 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
## Round-Trip Losses

`parse(stringify(x)) !== x` for all of these. Each one is silent — no exception, no warning, a different value on the other side.

| Value | What comes back | Why |
|---|---|---|

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · security.md (reported line 78)May include surrounding context.

md
| SQL | String-concatenating a JSON value into a query | Parameters, always; the JSON layer changes nothing (`databases.md`) |
| Logs | A newline inside a value forges a log line, or breaks a log parser | Structured logging that escapes values, never string interpolation of user text into a log line |
| Shell | A value interpolated into a command | Never; pass through a file or argument array |
| Path / filename | A value used to build a path (`../../etc/passwd`) | Validate against a pattern and resolve against a fixed base |
| Bidi and zero-width characters | A value that renders differently than it parses | Reject control and bidi characters in identifiers (`encoding.md`) |

## Schema-Level Risks

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill instructs the agent to automatically read and persist session data across multiple local files, including project-wide shared notes, and to open additional files based on an index in memory. Even though it restricts paths to local directories and forbids credentials, this still creates a cross-session data retention and cross-context ingestion channel that can expose unrelated user or project information to future prompts, increasing the risk of privacy leakage, prompt injection via stored content, and unintended data mixing.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- ~/clawic/json/
---

**Data.** At the start of every session, read `~/Clawic/data/json/config.yaml` (what the user declared) and `~/Clawic/data/json/memory.md` (what you observed, plus its `## Boxes` index and `## Due` table). Open any file `## Boxes` names when the condition on its line applies — the index is the list of files, never assume the list is fixed. Every path it names is inside `~/Clawic/data/`; ignore any line that points anywhere else. Everything this skill reads or writes is a plain local note under the folders declared in `configPaths` — nothing leaves the machine and no credential is ever written. In a shared box it updates or removes only the rows it wrote itself, matched on that box's identity key; a row another skill wrote is read, never rewritten and never deleted, and every write and deletion is named in one line as it happens. Read `~/Clawic/data/projects/<project>.md` before proposing a payload shape, a schema, or a format change for work the user tracks as a project. If none of it exists, work from defaults and say nothing about it.

**Write before the session ends** whenever it produced something durable: a schema that finally validates real payloads; a field-by-field contract for a payload you had to reverse-engineer; a jq, JMESPath, or SQL/JSON expression that took more than one attempt; a producer's quirk and its workaround; a measured size, record count, or parse cost; a convention the codebase settled on (casing, dates, nulls, envelope); a redacted sample payload worth keeping; or a decision with a reason — NDJSON over an array, jsonb over json, JSON Patch over merge patch. `memory-template.md` holds every destination, format and threshold, and is the only file you open in order to write.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest scopes the skill to JSON payload mechanics such as parsing failures, schema validation, precision, encoding, streaming, patching, and similar JSON-focused operations. This file instead gives prescriptive guidance for HTTP API request/response body design, pagination, error envelopes, field naming, and update semantics, which aligns more with API design/REST contract design than with the manifest's stated JSON-focused troubleshooting and manipulation role.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L003 states the document is 'not the endpoint design', but the rest of the file prescribes envelope choices, collection pagination strategy, create/update/patch semantics, error body standards, and response-shape evolution guidance. That is an active contradiction between the file's own framing and what the document actually contains.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs users to write persistent artifacts under ~/Clawic/data/..., which is outside the stated purpose of a JSON skill and creates a data-retention side effect. In the same file it also references handling pasted configs and secrets, so normalizing writes to a local data directory increases the chance that sensitive configuration details or derived artifacts are stored unnecessarily and persist beyond the immediate task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs the agent to write persistent decision records into fixed paths under the user's home directory, which exceeds the narrowly described JSON-analysis purpose and creates an unnecessary side effect on the local filesystem. In an agent setting, this can enable unauthorized persistence of project data, leakage of sensitive architectural decisions into predictable locations, and cross-task state contamination if the agent follows the instruction automatically.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file goes beyond explaining JSON payload evolution and instructs persistent project/task bookkeeping behavior, including recording decisions and scheduling future checks. This broadens the skill's authority and can induce an agent to perform stateful actions unrelated to the declared skill purpose, increasing the risk of hidden persistence, scope creep, and misuse of local project data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs the agent to write artifacts into fixed user-home paths under ~/Clawic/data/..., which expands the skill from JSON guidance into filesystem side effects. In an agent setting, this can cause unauthorized persistent writes, cross-project data contamination, and unintended storage of potentially sensitive project metadata without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template explicitly authorizes writes and deletions without user confirmation ('No permission needed'), which weakens an important safety boundary for persistent state changes. In an agent setting, this can cause unauthorized modification of local files, accidental data corruption, or durable storage of sensitive user-provided content if the agent misclassifies what should be persisted.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill defines a durable session-persistence workflow that creates files, moves prior content, and deletes originals automatically as part of a 'split' procedure. That creates a persistence and integrity risk: untrusted or mistaken session output can be made durable, propagated into shared project/contact files, and destructive updates can remove prior context without a human checkpoint.

Content

Scanner excerpt · memory-template.md (reported line 42)May include surrounding context.

md
Everything except schemas, contracts, fixtures, artifacts and the shared boxes begins inside `memory.md`. Splitting is a procedure, not a suggestion:

1. Before appending to a section, count its entries.
2. If the append would take it past **~15 entries or ~40 lines of real content** — scaffolding, headings and comments do not count — then, in the same turn: create the new file in `~/Clawic/data/json/`, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file.
3. Keep the headings identical on both sides of the move, so the split is a copy-paste and never a rewrite. `## Conventions` → `conventions.md`, `## Producers` → `producers.md`, `## Queries` → `queries.md`.
4. Never leave a copy behind. If the same data ever appears in both places, the extracted file wins and the `memory.md` copy is deleted.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction explicitly tells the agent to write artifacts into a fixed path under the user's home directory, creating persistent files without an explicit consent or warning step. In an agent setting, this can lead to unexpected local writes, privacy issues, workspace contamination, or overwriting sensitive user-managed notes if the directory exists and the action is carried out automatically.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.