Back to skill

Security audit

Learn

Security checks across malware telemetry and agentic risk

Overview

This is a local learning-planner skill that persistently records study plans, reviews, sessions, and learning-related resources, with disclosed local bookkeeping for paid learning subscriptions.

Before installing, be comfortable with the skill keeping persistent local learning records and related project/contact/subscription notes under ~/Clawic/data/. Pay particular attention when retiring a topic: it may delete or update a local subscription row for a paid learning resource, and that bookkeeping does not by itself cancel external billing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The maintenance guidance instructs the skill to modify `~/Clawic/data/finances/subscriptions.md`, which is outside the stated scope of a learning-maintenance planner. Crossing into a personal finances file creates an unauthorized side effect on unrelated user data and could lead to incorrect cancellation tracking or financial account management actions being taken based on an educational workflow.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The summary section reinforces an unrelated capability by directing the agent to clear learning records and also cancel a subscription row in a personal finances file. Embedding this in the end-state instructions makes the cross-domain action more likely to be executed automatically, increasing the risk of unintended modification of sensitive financial data during routine learning maintenance.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to modify `~/Clawic/data/finances/subscriptions.md`, which is outside the declared scope of learning management and crosses into personal finance data. Even though the stated goal is to cancel learning-related subscriptions, this creates a scope-expansion path where an agent handling a learning task may access or alter unrelated sensitive records, increasing the risk of unintended data exposure or unauthorized financial actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:58