Back to skill

Security audit

Recipes

Security checks for vulnerabilities and agentic risk

Overview

The skill is recipe-focused and local-only, but it can save health and guest information to shared files without prior approval.

Install only if you are comfortable with the skill automatically maintaining a local recipe collection and also saving allergies, diet-relevant conditions, guest restrictions, kitchen facts, prices, and related project notes into shared local files. Review those files periodically, and avoid giving health or third-party guest details unless you want them retained. No credential storage, collection upload, or remote code execution was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
memory-template.md:28
Finding

Automatic Persistence of Sensitive Health and Contact Data Without Explicit Consent

Content
View full analysis
.md` **and** its row in `index.md` | | A recipe was retired or found unmakeable | Move its row to `## Retired` in `index.md` with the reason; keep or delete the file as the user says | | A dish was cooked | A row in `made/.md`; bump `Made` and `Rating` in `index.md` | | A change was cooked twice and worked both times | Promote it into the recipe's `## Ingredients`/`## Method`, move the old line to `## Variations` (`testing.md`) | | A scaled or substituted version was produced but not yet cooked | `## Variations` in the recipe file, marked `untested` | | A week or an event was planned | A section in `plans/.md` | | An ingredient price was read off a receipt, a shelf, or an order | `## Prices` | | A kitchen fact changed a number — oven offset, tin sizes, hob type, altitude, salt brand, mixer capacity | `## Kitchen` | | A source proved reliable, or wasted a cook | `## Sources` | | The user stated an allergy, intolerance, or a condition that constrains food | `~/Clawic/data/health/profile.md` (**shared**) | | Someone was cooked for, or their restriction was learned | Their row in `~/Clawic/data/contacts/contacts.md` (**shared**) | ``` Related instructions in `SKILL.md:40` require these health and contact records to be shared across multiple skills: ```markdown **Allergies, intolerances, and diet-relevant conditions go to th ...[truncated 2816 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (26)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · vetting.md (reported line 51)May include surrounding context.

md
| Whole-muscle beef and lamb | 52-63 °C / 125-145 °F by preference | Surface-only contamination; a seared exterior is the control |
| Pork, whole cuts | 63 °C / 145 °F plus 3 min rest | The old 71 °C figure was retired; a recipe still using it will be dry |
| Fish | 52-63 °C / 125-145 °F | Raw service depends on the supply chain and freezing history, not on the recipe |
| Eggs, dishes with runny yolk | 71 °C / 160 °F for the safe version | Pasteurized eggs are the escape hatch for a raw preparation |
| Leftovers, reheated | 74 °C / 165 °F throughout | Cooked rice held warm is the classic *Bacillus cereus* case: cool fast, refrigerate within 1 hour, reheat once |
| Home canning, low-acid foods | Pressure canning only | A boiling-water bath cannot reach the temperature botulinum spores need. A recipe that says otherwise is discarded, not adapted |

Anything in this table suspends the recipe: fix the recipe to meet the floor, or do not cook it. If the user reports an illness after a meal, that is a clinician's question, not a recipe question.

## Verdicts

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · migration.md (reported line 68)May include surrounding context.

md
Then, per match: the existing file wins on every field it already has. The import adds its source under `## Original`, its differing quantities as a dated `## Variations` entry, and nothing else. The one exception is `made`/`last_made`/`rating` — take the higher count and the later date, because the import is usually the app the user actually cooked from.

- **Never delete a file during an import.** A wrong merge that only added lines is recoverable; a deletion is not.
- **Stop and ask exactly once**, at the end, and only about the pile the fingerprint rule surfaced as maybes. Everything else is decided by the ladder.
- **Report in one line**: imported, merged, skipped, and the maybes. `"312 in: 268 new, 31 merged, 9 skipped as exact duplicates, 4 for you to look at."`

## Export Out To An App

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill explicitly allows allergen substitution 'without asking first' as a configurable safety posture. In a recipe skill that reads shared health data and may save modified recipes for later reuse, autonomous substitution of allergens can create unsafe outputs, hide material recipe changes, and introduce cross-session risk if the saved version is later treated as authoritative.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
- **Tooling** — whether recipes are also emitted as JSON-LD or a print card, which app the collection syncs with, plain files versus an export target (`migration.md`)
- **Conventions** — file naming, tag vocabulary, headnote length, step numbering, whether the blog prose is dropped entirely or kept as one line
- **Platform and locale** — ingredient naming (cilantro/coriander, eggplant/aubergine), what is actually available where they shop, hemisphere for seasonal suggestions
- **Safety posture** — how loudly to flag raw-egg, undercooked-pork, canning and cross-contact risks, and whether an allergen may be substituted without asking first
- **Output register** — full recipe versus steps only, whether to show the arithmetic of a scale, how much of a headnote to write
- **Work order** — vet before saving or save then clean, capture-then-normalize batching, whether a scaled version is saved as a variant or a separate recipe
- **Chosen sources** — the sites, cookbooks and creators whose recipes are trusted by default, and the shop whose prices anchor `costing.md`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to write to ~/Clawic/data/recipe/recipes/<kebab-title>.md and ~/Clawic/data/recipe/index.md in the same turn, but does not require explicit user confirmation at the point of modification. This creates a real integrity risk: a user may think they are only asking for extraction or preview, while the agent performs persistent local file writes and index updates automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs persisting user- or environment-specific facts into a local memory file, but it does not require clear user awareness or consent at the time of the write. Even though the data seems operationally useful and low sensitivity, silent persistence can create privacy, integrity, and surprise-modification risks because durable state is changed outside the immediate conversion task.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · equipment.md (reported line 34)May include surrounding context.

md
## Slow Cookers

- Low and High reach the same final temperature (~93-100 °C); High just gets there faster. Low is not gentler, it is slower.
- Almost no evaporation: a recipe transferred without cutting the liquid produces a thin, pale sauce. Cut ⅓-½, and reduce on the hob at the end if needed.
- Lifting the lid costs ~20-30 minutes of recovery. Resist it.
- Dried kidney beans must be boiled hard for 10 minutes before they go in — slow-cooker temperatures are inside the range where their lectin is most concentrated. Tinned beans are fine.
- What it is good at: tough collagen-rich cuts, pulses, stocks. What it is bad at: anything that wants texture contrast, and anything under 2 hours.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly instructs the agent to write durable state into ~/Clawic/data/recipe/memory.md and config.yaml without any guardrails such as user confirmation, scope limits, or validation of what may be persisted. In an agent setting, silent modification of memory and configuration can cause unauthorized persistent changes, preference poisoning, or long-lived behavior changes beyond the current recipe task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template explicitly directs the skill to read and write a shared health profile containing allergies, intolerances, and medical conditions. Even if intended for legitimate personalization, this expands the skill's authority into highly sensitive cross-skill medical data and creates unnecessary propagation and persistence risk if the Recipes skill is compromised or over-collects information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is instructed to maintain shared contacts records, including dietary notes, in a cross-domain contacts file. This broadens data handling beyond recipes into personal relationship data, increasing privacy risk and the chance of unintended modification of shared records used by other skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The template grants the Recipes skill responsibility for updating shared project files, which creates cross-skill write capability outside its core function. That increases the blast radius of prompt mistakes or malicious input by allowing recipe workflows to alter broader project-tracking state relied on elsewhere.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · memory-template.md (reported line 53)May include surrounding context.

md
Recipes, plans, make logs and artifacts are born as their own files. Everything else begins inside `memory.md`. Splitting is a procedure, not a suggestion:

1. Before appending to a section, count its entries.
2. If the append would take it past **~15 entries or ~40 lines of real content** — scaffolding, headings and comments do not count — then, in the same turn: create the new file in `~/Clawic/data/recipe/`, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file.
3. Keep the headings identical on both sides of the move, so the split is a copy-paste and never a rewrite. `## Prices` in `memory.md` becomes `## Prices` in `prices.md`; `## Sources` becomes `## Sources` in `sources.md`.
4. Never leave a copy behind. If the same data ever appears in both places, the extracted file wins and the `memory.md` copy is deleted.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to write multiple files in the user's recipe tree, including index and memory metadata, without requiring an explicit user confirmation at the point of modification. In an agent setting, this creates a real integrity risk: a mistaken import, bad dedup decision, or malformed source file can silently alter the user's collection and propagate changes across multiple files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to read and write guest restrictions in a contacts file, which expands the skill from recipe planning into personal contact-memory management. That creates unnecessary handling of personal data and a cross-domain data flow, increasing privacy risk and the chance of modifying unrelated records without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions direct the agent to access and update contact records containing guest restrictions, which are personal and potentially sensitive preference/health-related data, without any explicit notice, consent check, or minimization guidance. In a recipe skill, silently propagating such data into long-term memory is more dangerous because users may not expect meal planning to alter personal contact profiles.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L09 explicitly states that ## Original is transcribed verbatim and 'never edited afterwards'. L62 later instructs that each derived measure is written back into ## Original as derived <date>, which is a direct contradiction in the file's documented procedure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · preservation.md (reported line 56)May include surrounding context.

md
- Do not clean up the original text. The misspelling and the crossed-out line are evidence.
- Do not merge two family versions into one "correct" file. Two files, two names, each with its provenance, and a note in each pointing at the other — the disagreement between them is the family history.
- Do not discard the physical card after digitising. Photograph it and say so; whether the paper is kept is the family's decision, not a filing decision.
- Do not publish a family recipe outside the family without asking (`authoring.md`).

## The Family Cookbook

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to read ~/Clawic/data/health/profile.md and dietary configuration causes the skill to access sensitive health information to perform recipe substitutions, but there is no visible privacy notice, consent gate, or data-minimization limit in this file. Health data is especially sensitive, so silent reads can expose more information than needed and normalize unauthorized access by the agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to write user health restrictions into a persistent health profile and guest restrictions into contacts data, which expands behavior from recipe substitution advice into sensitive profile and contact record management. Even if intended to improve future substitutions, this broadens data handling scope and creates a privacy and safety risk if the write occurs without explicit, informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file directs persistent writes to recipe variations, health profiles, and contacts context, but the skill description does not clearly warn users that using the skill can modify long-lived personal records. This creates a transparency and consent failure: users may provide dietary or allergy information expecting a one-time response, not durable storage across multiple files.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to persist newly stated allergies, intolerances, and conditions into ~/Clawic/data/health/profile.md creates a durable natural-language repository of sensitive medical-style information. That increases the blast radius of accidental disclosure, over-retention, or later misuse, especially because freeform notes can capture more detail than is necessary for recipe adaptation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to write changes into recipe files and update a shared memory file, including source trust metadata, without requiring user confirmation or a user-visible warning. In an agent setting, silent persistence can modify personal data and future behavior, creating integrity and privacy risks even though the operational intent appears helpful rather than malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to write collected pricing data into a persistent user file after any costing pass, but it provides no guardrail to confirm the write, distinguish transient analysis from durable memory updates, or limit when persistence is appropriate. In an agent setting, this can cause unintended modification of personal data stores, stale or incorrect data accumulation, and privacy issues if receipt or shop data is persisted automatically from untrusted inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example configuration includes locale.ingredient_names: en-GB with a comment enforcing British ingredient vocabulary. This natural-language locale choice is presented as part of the template without offering alternatives or requiring user opt-in, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest includes building a week from the collection and one combined shopping list, but does not describe event-management outputs such as artifacts/menu-<name>.md with countdown run-sheets. Producing service-timed event artifacts is adjacent to cooking/hosting workflow management rather than clearly part of recipe filing and collection planning as described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs writing scaled results into recipe files, which is a persistent local data modification, but it does not require a user-facing confirmation or warning before doing so. In an agent setting, silent writes can violate user expectations, overwrite curated notes, or create unwanted persistent state even if the content is otherwise harmless.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:65