Back to skill

Security audit

Lawyer

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local legal-assistant skill, but it automatically reads and updates sensitive legal, contact, project, and finance records without asking each time.

Install only if you want a legal assistant that maintains local working records automatically. Before use, consider changing the workflow to require confirmation before writing or deleting files, segmenting records by client or matter, and limiting what gets saved into shared contacts, projects, and finances. Do not use it for privileged or highly confidential matters unless you are comfortable with durable local memory and cross-session reuse.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The instruction to update `~/Clawic/data/finances/subscriptions.md` extends the legal skill into modifying finance records, which is outside narrow legal-review scope and creates a cross-domain side effect. If the agent follows this automatically after contract execution, it could alter budgeting or subscription tracking data without explicit user approval, causing integrity issues in operational records.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The post-execution instruction tells the legal skill to maintain `memory.md`, `## Due`, templates, and shared finance records in the same turn, turning advisory work into autonomous operational bookkeeping. This broadens the skill's authority and write scope, increasing the risk of unintended or adversarially induced changes to contract systems, reminders, and financial tracking artifacts.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The file instructs the skill to read prior positions from shared local memory and reusable clause artifacts before proposing a position. In a legal-negotiation context, that creates cross-client data contamination risk: one customer's negotiated terms can influence another matter, and artifact contents may reveal confidential deal positions during later use or diligence preparation. Because the memory is explicitly positioned as reusable precedent, this is more dangerous here than ordinary note-taking.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
This instruction explicitly tells the skill to persist accepted clause language, acceptance history, rejected positions, and summaries into long-lived local memory/artifact files. That is a direct mechanism for storing sensitive client negotiation history and then reusing it across future matters, which can leak confidential strategy, pricing of legal risk, and customer-specific concessions. In a lawyer skill, this is especially sensitive because contract positions are privileged or commercially confidential and reuse can prejudice other clients.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to read persistent legal portfolio and filing records before answering, which expands behavior from document review into ongoing records management and cross-matter data access. In a legal skill, that creates a real risk of unnecessary access to prior client matters, confidentiality spillover, and use of retained data outside the immediate task.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The instruction to update filings, deadlines, legal context, and reusable artifacts after any IP action gives the skill a standing document-management and persistent memory role beyond legal analysis. In the legal context, this is more dangerous because it can silently write sensitive client data, deadlines, and work product into shared long-lived stores, causing confidentiality, integrity, and cross-client contamination risks.

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The file instructs the skill to write personal-matter rows, deadlines, correspondence artifacts, and even contract-register entries after personal matters, which extends a legal-advice skill into ongoing case-management and tracking behavior. In a legal context this creates operational scope creep: the agent may retain and act on sensitive matters beyond the immediate task, increasing privacy, accuracy, and unauthorized-recordkeeping risk.

Description-Behavior Mismatch

Medium
Confidence
76% confidence
Finding
This file broadens the Lawyer skill from its manifest’s commercial/contract focus into consumer and personal legal matters such as renting, debt collectors, traffic fines, and employee-side disputes. That mismatch can cause the agent to operate outside declared scope, making routing, user expectations, and safety guardrails weaker for higher-risk personal legal scenarios.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown directs the agent to write to specific local files in the same turn, without an explicit confirmation or warning that local data will be modified. That creates an unsafe side effect: the agent may alter user files or knowledge stores automatically, potentially overwriting or appending sensitive legal content without informed consent or review. In this skill, silent writes are more dangerous because the content involves legal positions and client negotiation records.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to write updates into persistent local files such as memory.md and artifacts under ~/Clawic/data/lawyer/artifacts/ without requiring confirmation, preview, or a clear boundary on when file modifications are allowed. In an agent setting, this creates an unauthorized state-modification risk: merely using the skill can silently alter durable records, which could overwrite valid data, introduce inaccurate compliance entries, or poison future legal/compliance workflows that rely on those files.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs storing legal matter metadata, spending details, advice summaries, and lawyer contact information in shared files without any guardrails for minimization, access control, redaction, consent, or jurisdiction-specific confidentiality handling. In a legal workflow, those records can contain privileged, highly sensitive, and strategically damaging information, so centralizing them in broadly shared plaintext knowledge stores materially increases the risk of privilege waiver, internal overexposure, and downstream data leakage.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to record dispute matter details, deadlines, counterparties, settlement terms, contacts, and legal spend into shared files without any sensitivity gating, minimization, or access-control warning. In a legal-disputes context, these records can contain highly sensitive confidential, privileged, personal, and litigation-related information, so writing them into broadly shared repositories creates a real risk of privacy breach, privilege waiver, and strategic exposure.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs the agent to read from local memory and artifact files in a home-directory path without any user disclosure or consent boundary. In a legal workflow, those files may contain prior client matters, negotiation history, playbooks, or sensitive clauses, creating a risk of unintended cross-client data access and prompt-context leakage.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill directs persistent storage of reusable documents and drafting reasoning after a draft ships, again without warning the user that their contract text and legal reasoning will be retained. In this legal context, persisted drafts and strategy notes can contain privileged, confidential, or client-identifying information, and could later be surfaced into unrelated matters.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The instruction explicitly tells the agent to write user- and task-derived jurisdictional context into persistent local files (`memory.md` and jurisdiction-specific artifact memos) in the same turn, without requiring explicit user consent or a warning that local data will be modified. In a legal skill, this can persist sensitive business, employment, customer-territory, or counsel-derived information across future tasks, creating privacy, data-minimization, and cross-task leakage risks.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The template authorizes autonomous writes and deletions to persistent storage with only a minimal announcement, which creates a real risk of unintended data modification or loss without meaningful user confirmation. In a legal workflow, that is especially sensitive because records, deadlines, and shared files may be changed based on model interpretation rather than explicit user approval.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to write negotiation outcomes into local memory files (`memory.md` and related sections) after the negotiation closes, but gives no user-facing notice or consent check before modifying persistent local data. In an agent environment, silent writes can create privacy, integrity, and auditability risks by storing sensitive legal positions, contract terms, counterparty behavior, and dates without the user's explicit approval.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The instructions tell the agent to store matter details, amounts at stake, deadlines, and reusable correspondence for personal legal issues without any warning, consent flow, or minimization guidance. Because personal legal disputes often contain financial, housing, employment, and other sensitive data, indiscriminate persistence materially raises privacy and confidentiality risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to write contract metadata, deadlines, positions, and potentially new counterparty contact records into persistent local files without any user confirmation or warning. This creates a cross-session data persistence channel that can store sensitive legal and business information, and it may modify shared data stores in ways the user did not request or expect.

Ssd 3

Medium
Confidence
96% confidence
Finding
The file directs the agent to persist broad categories of legal context and work product—entities, employing jurisdictions, customer territories, governing-law defaults, local counsel advice, clause enforceability, and formality requirements—into shared memory/artifact stores without clear minimization or scoping boundaries. Because this is a lawyer skill, the stored data may include especially sensitive commercial and employment information, increasing the chance of unnecessary retention and later disclosure to unrelated tasks.

Ssd 3

Medium
Confidence
91% confidence
Finding
The skill directs the agent to read prior matters, due items, and legal-context memory before answering every request, which can expose unrelated sensitive information across sessions and encourage over-collection beyond need-to-know. In a legal-assistance setting, cross-matter reuse of prior personal data is especially risky because users may disclose highly confidential facts and expect compartmentalization.

Ssd 3

High
Confidence
95% confidence
Finding
The file mandates persisting detailed personal legal matter data, deadlines, and reusable correspondence into long-term memory and artifact stores after every interaction. In the context of legal and consumer disputes, this can create a durable repository of sensitive personal information that may later be surfaced, reused incorrectly, or accessed by unrelated workflows, magnifying confidentiality and compliance risks.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.