Back to skill

Security audit

Sleep

Security checks for vulnerabilities and agentic risk

Overview

The sleep coaching skill matches its stated purpose, but it persistently stores sensitive sleep, health-adjacent, substance, household, and travel details without clear consent, privacy, or deletion controls.

Review before installing if you are not comfortable with a local sleep diary and memory files being kept under ~/Clawic/data/sleep/. Those files may include sleep patterns, red-flag screening context, substance habits, prescriptions context, household routines, and travel plans; consider deleting or protecting that directory if you use the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Plaintext Persistence of Sensitive Health and Behavioral Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 13)May include surrounding context.

md
last: YYYY-MM-DD

## Context
<!-- Schedule reality: work pattern, commitments, observed chronotype -->
<!-- Household: partner schedule, kids, pets, room situation -->

## Protocol State

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · performance.md (reported line 48)May include surrounding context.

md
## Driving (the hard lines)

- Microsleeps arrive without warning at the wheel; yawning, drifting lanes, missing exits are late-stage signals, not early ones.
- The only countermeasures that work: stop, caffeine, 20-min parked nap (the coffee nap, above), or a different driver. Windows down and loud music measurably do not.
- Veto lines, stated flat: no driving past 17-19 h awake (the ~0.05% line, above), after a night under 5 h, or during week 1-2 of a restriction protocol (`insomnia.md` warns the same).

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · setup.md (reported line 7)May include surrounding context.

md
## Your Attitude

Sleep is where advice inflation does damage: one measured intervention beats five tips. Triage first, protocol second, referral without hesitation when the Red Flags table says so. Be calm and concrete; never moralize about the user's schedule.

## How To Load Preferences

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section gives specific medical-style intervention guidance, including timed bright-light exposure and melatonin dosing, without a clear warning that these are not personalized medical instructions and may carry health risks. In context, the advice can affect circadian rhythm, mood, and underlying conditions; the file itself even notes bipolar activation risk, which makes omission of an upfront safety warning materially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the user to record sensitive sleep and health-related data in a specific local path (~/Clawic/data/sleep/diary.md) without warning about privacy, retention, or who can access that file. Because this is health-adjacent personal data, hardcoding storage behavior can lead to unintended persistence, exposure to other local users, backups, sync services, or later reuse by other tools without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template directs storage of sensitive health-related and household information in a predictable local path without any warning, consent language, or privacy guidance. In a sleep-coaching context, this may capture medical-adjacent data, family/household details, substance habits, and red-flag screening notes, increasing privacy and confidentiality risk if the file is exposed or synced insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to read from and write to persistent user-specific files containing preferences, schedule details, substance habits, and protocol state, but it does not require notifying the user or obtaining consent for this storage/access. This creates a privacy and transparency risk because sensitive behavioral and health-adjacent information may be persisted or reused across sessions without the user's awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to write a trip plan into a specific local file path without telling the user or obtaining consent. Even though the content is benign sleep-planning data, silent filesystem writes can create privacy, transparency, and unwanted-persistence issues, especially if the destination contains health-related travel or sleep information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.