Back to skill

Security audit

Studying

Security checks for vulnerabilities and agentic risk

Overview

This is a study-coaching skill with disclosed, narrow local study-memory files and no executable code or evidence of hidden unsafe behavior.

Before installing, expect this skill to keep study preferences, session logs, and exam notes under ~/Clawic/data/studying/ and to use any existing study data in the old listed paths. Review or back up those folders if you do not want automatic study-history migration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · memory-template.md (reported line 13)May include surrounding context.

md
last: YYYY-MM-DD

## Techniques
<!-- what worked / failed, with evidence level: observed (1 signal) or confirmed (2+) -->
<!-- e.g. confirmed: mind-maps help in conceptual courses (worked in bio and psych) -->
<!-- e.g. observed: group comparison rounds helped once in stats -->

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares very broad activation triggers such as general requests about focus, procrastination, learning, memorization, or exam preparation, which can cause it to activate for ambiguous everyday conversations outside its intended scope. Overbroad routing increases the chance that this skill will capture requests better handled by other skills, persist user data unnecessarily, and expose users to unintended behavioral guidance or memory writes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup instructions direct the agent to read persistent user files and to migrate data from old locations, including moving files, without any explicit user notice or consent at the time of access. This creates a privacy and integrity risk because the skill can access and modify local study-history data as a side effect of first use, even when the user only asked for study help.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The template instructs creation of a persistent file under the user's home directory, but it does not state when this write is allowed or what user action should trigger it. In an agent setting, ambiguous persistence instructions can cause unexpected collection or retention of user study data outside clearly scoped consent or activation boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.