Back to skill

Security audit

Productivity

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local productivity-memory skill, but it merits review because it can automatically read and modify persistent health, contact, project, and behavioral notes without explicit confirmation.

Install only if you are comfortable with a productivity skill keeping persistent local memory about your work patterns, projects, contacts, commitments, and limited user-stated health facts. Review the Clawic data folders periodically, and avoid using this skill for sensitive health, HR, financial, or credential material unless you intentionally want those notes stored locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (23)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 65)May include surrounding context.

md
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. Store the pointer in its place, in this shape: `<kind>:<locator>`.

`env:TODOIST_TOKEN` · `keychain:work-mail` · `1password:Personal/Calendar` · `bitwarden:Work/VPN` · `file:~/.ssh/id_ed25519` · `profile:work`

When the user pastes something to save — an automation recipe, an exported list, a login note, a meeting dial-in — replace each secret value before writing and leave the pointer visible: `api_token: <env:TODOIST_TOKEN>`. Say in one line that you did it.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The skill explicitly authorizes autonomous file creation and updates 'without asking', which reduces user oversight over persistent state changes. In this context the writes are local and scoped to productivity data paths, but the skill can still persist sensitive or incorrect information about the user or third parties, creating privacy and integrity risks if the agent misclassifies, over-collects, or writes unintended content.

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
**Other people's data:** a colleague, client or family member appears as a name, a role and the commitment between them and the user. Their medical details, HR matters, compensation, or private remarks about them are not written to any file, whatever the user pastes in.

**Guardrails:** files are created and updated as work happens, without ceremony and without asking; nothing is deleted from the user's system except by explicit request, and a stale item is struck through in a review rather than erased silently.

## Related Skills
More Clawic skills, get them at https://clawic.com/skills/productivity (install if the user confirms):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs writing ADHD-related diagnosis or medication timing into a shared health profile file, which is sensitive health information. Even though it says to record only user-stated facts and not infer diagnoses, it provides no privacy warning, consent check, retention rule, or access-control guidance, so it can normalize unnecessary persistence of medical data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file instructs the agent to persist diagnosis, medication, and clinician-set restrictions into a shared health profile from within a productivity skill. That expands the skill beyond productivity planning into handling sensitive health data, creating unnecessary collection and cross-context propagation of medical information that may later be exposed or reused by unrelated workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance explicitly tells the agent to record diagnosis, medication, and clinician-imposed restrictions without any accompanying privacy notice, minimization rule beyond a narrow wording constraint, or explicit consent checkpoint. This is dangerous because highly sensitive medical data may be stored by default in a shared location, increasing the chance of privacy violations, over-retention, and unintended access by other skills or users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs writing to and moving content within user files such as ~/Clawic/data/projects/, triage-policy.md, config.yaml, and archival files, but it does not include any user-facing warning, confirmation, or safeguard before modifying persistent data. In a productivity skill, these edits are contextually expected, but unattended or implicit file changes can still overwrite user preferences, alter task state, or create data-loss scenarios if the guidance is followed automatically by an agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

These instructions explicitly direct the agent to persist user-specific behavioral and emotional observations such as what 'lands,' what 'irritates,' dread patterns, and guilt after rest. Storing inferred emotional or psychological profiling in shared memory creates privacy risk, can exceed user expectations for a productivity skill, and may enable sensitive longitudinal profiling without clear necessity or consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to read from a specific local memory file before advising, which expands behavior from general productivity coaching into filesystem data access. That creates a real risk of unnecessary access to sensitive personal data in local notes and memory stores, especially because the referenced file may contain unrelated or confidential information beyond what is needed for the immediate task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

These instructions direct the agent to write or maintain data in shared project, contacts, and artifact repositories, which broadens the skill into persistent data management and handling of personal/contact information. If followed without strict scoping and authorization, the skill could store sensitive information in inappropriate locations, modify unrelated records, or create privacy and integrity issues across the user's local knowledge base.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to persist durable health facts such as diagnoses, medications, and sleep disorders into a shared profile file, but it does so without an explicit consent, minimization, retention, or access-control warning. Because this is health data and the file is shared across contexts, the instruction increases the risk of unnecessary collection, over-retention, and unintended disclosure of sensitive personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to read from shared local memory and project files before advising, which can pull in sensitive personal or organizational data without any user awareness, consent, or data-minimization guardrails. In this executive context, those files likely contain commitments, constraints, projects, and contact details, making over-collection and unintended disclosure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to write user-specific behavioral data to config.yaml for future sessions without any user-facing disclosure or consent step. Because this file is persistent local state, the agent could store sensitive mental-health-adjacent information and silently shape later interactions based on it, creating a privacy and transparency risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section directs persistent recording of personal observations, triggers, and rest behavior into memory/review files without warning the user that their personal information will be stored. In this skill’s context, the notes concern guilt, self-worth, depletion, and possible therapy-related issues, which makes the stored data more sensitive and increases privacy harm if retained unexpectedly or later exposed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This instruction directs the agent to store habit-related information in a shared health profile file, which crosses a domain boundary from productivity into health data handling. Even though the example mentions legitimate health facts like medication timing or physiotherapy, placing them via a productivity skill into a health record increases the risk of collecting, propagating, or retaining sensitive medical data outside the skill's declared scope and user expectations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template states that writes and deletions remain within the skill's declared configPaths, but it also directs writes into shared paths such as ~/Clawic/data/projects/, ~/Clawic/data/contacts/, and ~/Clawic/data/health/. This inconsistency can cause the agent to modify files outside its expected sandbox, increasing the chance of cross-skill data corruption or unauthorized persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template authorizes autonomous file creation, rewriting, deletion, and migration with 'No permission needed,' including changes to persistent memory. Without a confirmation gate for destructive or structural operations, an agent can overwrite or remove user data based on misinterpretation, prompt injection, or malformed inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The split procedure instructs the agent to move sections, delete them from memory.md, and remove duplicate copies in the same turn, but it provides no user-visible safeguard or rollback requirement. If the agent makes an error during counting, parsing, or file creation, data can be lost or silently fragmented across files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest says this skill is not for 'running the day-to-day list' and distinguishes that role from a separate task-list skill. Yet the template maintains a live ## Tasks list, says to read tasks.md before planning, prioritizing, or deciding 'what should I do now', and records task lifecycle changes throughout. That behavior materially overlaps with day-to-day list operation rather than only higher-level productivity diagnosis/repair.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs the agent to write updates into user-local state files under ~/Clawic/data without any requirement for user confirmation or a visible warning that persistent data will be modified. In an agent setting, silent writes to memory and project files can corrupt user planning state, create unwanted durable changes, or be abused by adjacent instructions to overwrite trusted records.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest describes a productivity-diagnosis and coaching skill, but this file explicitly directs the agent to read from a persistent memory file before choosing a coaching register. While personalization can support coaching, accessing stored user memory is an additional capability not clearly declared in the stated purpose itself.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · energy.md (reported line 57)May include surrounding context.

md
| Tired every morning despite 8 hours in bed | Sleep quality, not quantity, or something medical | Clinician, not technique |
| Energy fine for hobbies, gone for work only | Motivation, meaning or resentment, not energy | `procrastination.md`, and the honest conversation about the job |
| Exhaustion plus cynicism plus feeling ineffective, for weeks | Burnout as ICD-11 frames it | Stop optimizing; `burnout.md` and SKILL.md Red Flags |
| Everything is flat, including things that used to be fun | Beyond the scope of this skill | Say so plainly and suggest a clinician |
| Crashes at the same hour daily | Circadian trough, or food and hydration timing | Schedule around it before treating it |

## The Levers That Are Not Sleep

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs creating and updating persistent user files such as sessions logs, configuration, and artifacts without any warning, confirmation, or guardrails. In a productivity skill this is functionally expected behavior, but it still creates a real risk of unintended state changes, overwriting user data, or silently persisting sensitive behavioral information if the agent follows the instructions automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to read several user data files, including memory, projects, and contacts, before advising, but provides no data-minimization, consent, or sensitivity guidance. This can cause overcollection of personal or confidential information unrelated to the immediate task, especially because contacts and project files may contain third-party data and sensitive business details.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:67