Back to skill

Security audit

Summarizer

Security checks for vulnerabilities and agentic risk

Overview

This summarizer is not malicious, but it automatically keeps local memory and updates shared contact/project notes, so it needs review before installation.

Install only if you want a stateful local summarizer that can remember sources, deadlines, templates, audience preferences, contacts, and project context. For confidential transcripts, contracts, reports, or personal data, prefer disabling storage where possible and reviewing proposed writes to shared contacts or project files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:34
Finding

Default persistent storage and shared-data access exceed least-privilege requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
Findings (57)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
**People go to the shared inventory `~/Clawic/data/contacts/contacts.md`**, not here: the recipient of a brief is the same person `clients` or `crm` already knows. One row per person, keyed by lowercase email → handle → `<kebab-name>` — read the file and update that row in place, never append a second one. What is summarizer-specific (their length ceiling, their jargon tolerance, what they always ask for) stays in `## Audiences` in `memory.md`, referencing them by key only.

**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, and above all not in the source the user pastes in. Transcripts, logs, tickets, and `.env` snippets carry live secrets more often than any other input in this catalog: strip the value and leave the pointer before writing anything to disk — `env:STRIPE_API_KEY`, `keychain:vpn`, `1password:Work/DB/prod`, `file:~/.ssh/id_ed25519` — and say in one line that you did it. If data sits at an old location (`~/summarizer/` or `~/clawic/summarizer/`), move it to `~/Clawic/data/summarizer/`, and say in one line that you moved it and from where.

A summary is a lossy compression with a contract: everything it says is in the source, and everything the reader needs to act is in the summary. Both halves fail silently, so decide the target length before writing and name what you cut. Work from defaults immediately: never open with questions about audience, length, or format — infer from the request, state the assumption in the output header, and correct on feedback. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, language) → the Configuration table default.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 62)May include surrounding context.

md
**People go to the shared inventory `~/Clawic/data/contacts/contacts.md`**, not here: the recipient of a brief is the same person `clients` or `crm` already knows. One row per person, keyed by lowercase email → handle → `<kebab-name>` — read the file and update that row in place, never append a second one. What is summarizer-specific (their length ceiling, their jargon tolerance, what they always ask for) stays in `## Audiences` in `memory.md`, referencing them by key only.

**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, and above all not in the source the user pastes in. Transcripts, logs, tickets, and `.env` snippets carry live secrets more often than any other input in this catalog: strip the value and leave the pointer before writing anything to disk — `env:STRIPE_API_KEY`, `keychain:vpn`, `1password:Work/DB/prod`, `file:~/.ssh/id_ed25519` — and say in one line that you did it. If data sits at an old location (`~/summarizer/` or `~/clawic/summarizer/`), move it to `~/Clawic/data/summarizer/`, and say in one line that you moved it and from where.

A summary is a lossy compression with a contract: everything it says is in the source, and everything the reader needs to act is in the summary. Both halves fail silently, so decide the target length before writing and name what you cut. Work from defaults immediately: never open with questions about audience, length, or format — infer from the request, state the assumption in the output header, and correct on feedback. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, language) → the Configuration table default.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · data.md (reported line 64)May include surrounding context.

md
| MD&A / commentary | Management narrative | The explanations given for the numbers, attributed as management's |

- **Adjusted figures are attributed, always.** "Adjusted EBITDA" is a company-defined metric; the summary says whose definition it is and, when the source states it, what was adjusted out.
- **Non-recurring items that recur** every quarter are recurring; if the source shows three consecutive quarters of "one-off" charges, the summary can note the count without judging it.
- **Segment redefinition breaks comparability.** When segments were re-cut, prior-period comparisons in the summary carry a note.
- Forward-looking statements keep their modal: "expects", "targets", "guides to" — never "will".

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This instruction mandates writing summary outputs and updating memory files after summarization, creating undisclosed side effects beyond the requested task. Because it can write multiple files automatically, it raises the risk of unauthorized workspace modification, unintended data retention, and leakage of sensitive report contents into long-lived storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Updating a shared contacts database from meeting transcripts is outside the core function of summarization and causes the agent to persist personal data derived from potentially sensitive conversations. Because diarization and transcript identity mapping are acknowledged as unreliable in the same skill, this can also introduce inaccurate or misattributed contact records into a shared system.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to perform persistent writes to multiple files outside the requested summary output, including memory, glossary, contacts, project, and summary stores. This expands the skill from summarization into cross-file state mutation, creating a clear risk of unintended data retention, privacy leakage, and corruption of shared knowledge stores from unverified meeting content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file materially expands the Summarizer skill into recurring digest production, despite the manifest explicitly excluding recurring external feeds and directing those to a separate digest skill. Scope drift is dangerous because it can cause the agent to apply the wrong trust boundaries, memory behavior, and workflow to ongoing streams, increasing the chance of unauthorized persistence, missed safeguards, or processing sources under a less appropriate policy set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to read person-specific audience memory and contacts files before writing for a named person encourages use of stored personal preferences and contact metadata without any privacy notice, consent check, or data-minimization boundary. This can expose unnecessary personal data to the skill and normalize hidden profile-based processing beyond the immediate summarization request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to consult audience memory and contacts files before drafting for a named person causes the skill to ingest person-specific preferences and channels from shared storage. In the context of a summarizer, this is more dangerous because it is unrelated to core summarization and broadens data access to personal metadata that may not be necessary for the task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These lines instruct the agent to add or update named recipients' contact records, preferences, and reusable templates in persistent files, but provide no warning about privacy, retention, or consent. Persisting personal data and inferred preferences from interactions can create unauthorized profiling and long-term data exposure if those shared files are later accessed by other tasks or users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file directs the agent to maintain and update external contact and audience-profile files after completing a summarization task. That extends the skill's behavior from summarization into persistent data collection and modification, creating unnecessary privacy, integrity, and scope-expansion risk if the agent stores personal information without explicit user consent or validation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs storing recipient profiles, preferences, and contact details in shared memory files beyond the current task. Persistent shared storage of person-specific data increases the chance of cross-task leakage, unauthorized reuse, and inaccurate or stale profile data influencing future outputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to persist outputs and update multiple project-memory artifacts outside the core act of summarization, including release files, memory indexes, templates, glossary entries, and project tracking files. This creates unintended side effects on local state and can let a simple summarization request silently modify or poison future workflows, especially because no explicit user confirmation or scope check is required.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions go beyond summarization by directing updates to due-item records and project tracking artifacts, which can alter operational planning data and create task entries the user did not request. In skill context, this is more dangerous because users invoking a summarizer would not reasonably expect it to mutate project-management state, making hidden persistence and workflow contamination more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown explicitly directs the agent to write summaries and update several local files without any warning, consent step, or indication that local data will be modified. This is dangerous because it violates user expectations for a read/transform task, increases the chance of silent local data modification, and enables persistence of potentially incorrect or attacker-influenced content into future summaries and release workflows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Maintaining recurring-report history and user-specific metric definitions introduces cross-session state that is broader than a generic summarizer's core function. This can silently accumulate sensitive business context and influence later outputs in ways the user may not expect or be able to audit easily.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file instructs the agent to read and update persistent local files as part of normal operation, but it does not warn the user that local memory and glossary data may be modified. Hidden file writes are risky because they can alter user data, create privacy issues, and establish durable state without informed consent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction expands the skill from pure summarization into persistent state management by requiring updates to memory, glossary, and stored summary files. That creates unintended write side effects, increases data retention, and can modify user workspace contents without an explicit user request or consent flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file broadens the skill from summarization into maintaining recurring-job memory, template lookup, and configuration updates. This scope expansion is risky because it introduces persistent state and behavior changes that are not necessary to summarize content, increasing the chance of unintended data retention or unauthorized local modifications.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · formats.md (reported line 101)May include surrounding context.

md
| Slide | ~6 lines, ~8 words per line | One claim per slide; the rest goes to speaker notes |
| Social post | Fixed character count | Write to the count, not to a length band |
| Voice / audio | No visual structure at all | Prose, short sentences, numbers rounded and spoken, no symbols |
| Anything else | Assume markdown, no truncation | Use the ladder default |

## Markers and Formatting

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · formats.md (reported line 118)May include surrounding context.

md
1. **Cut branches first** (SKILL.md Rule 2) until the point count fits `target ÷ 25`.
2. **Then cut the connective tissue**: "it is worth noting that", "in order to", "the fact that". This is the only genuinely free compression and it typically recovers 10-15% of a first draft.
3. **Then cut adjectives and adverbs**, which carry almost no claim.
4. **Never cut**: negations, hedges, quantifiers, units, attributions, dates. If the count cannot be met without cutting one of these, the count is wrong for this content — say so and give the shortest honest version.
5. **Count before delivering.** "Under 100 words" delivered at 140 is a failed instruction, and it is the most common one.

## Templates

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly tell the skill to persist user-derived templates, style guides, and preferences into local files and config state. For a summarization skill, this creates unnecessary statefulness and local data modification, which can retain sensitive user content or organizational conventions beyond the immediate task without clear consent or bounds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation directs the agent to write template and style files locally and update configuration without any warning, confirmation, or disclosure to the user. Silent persistence is dangerous because users may provide confidential text assuming it is transient, while the skill stores it for future reuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to perform persistent writes to multiple user data stores after summarizing an agreement, including deadlines, sources, summaries, glossary entries, contacts, and project notes. That expands the skill from summarization into state mutation without clear user consent, creating a risk of unintended data retention, privacy leakage, and corruption of trusted records from potentially sensitive contract contents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs modification of shared contact and project files, which are broader organizational records not necessary for summarization. Because contract text may contain sensitive identities, engagement details, and inferred relationships, automatic propagation into shared files can leak information across contexts and poison data used by other skills or future tasks.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:64