Back to skill

Security audit

Writing

Security checks for vulnerabilities and agentic risk

Overview

This is a local writing assistant, but it automatically stores writing, contacts, and project notes without asking first, so it needs review before installation.

Install only if you are comfortable with a writing skill that keeps local long-term notes about your voice, samples, deadlines, contacts, and projects. Before using it on sensitive drafts or client work, pause recording or require the agent to ask before writing to ~/Clawic/data/, especially shared contacts and projects files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
memory-template.md:5
Finding

Automatic Persistence of User and Third-Party Data Without Explicit Consent

Content
View full analysis
.md` | One file per sample, from the first | | House style for a publication, client, employer or project | `~/Clawic/data/writing/style-sheets/.md` | One file per context, from the first | | Things you produced that get re-read — reusable templates, standing bios and sign-offs, editorial letters, briefs, outlines that survived the piece | `~/Clawic/data/writing/artifacts/.md` | Born as its own file, from the first one | | Finished and published pieces | `~/Clawic/data/writing/pieces/.md` | Append-only, cut by year | | People they write to or for — editors, clients, managers, recurring recipients | `~/Clawic/data/contacts/contacts.md` (**shared**) | One row per person, every skill's contacts in one file | | Writing projects with a life beyond one piece — a newsletter, a client's blog, a report series | `~/Clawic/data/projects/.md` (**shared**) | One file per project; the style sheet stays in `style-sheets/` and is named from it | | **Anything durable this table does not name** | `~/Clawic/data/writing/.md`, or `artifacts/.md` if it is a long text read whole | Name the file after what it holds, never after when it w ...[truncated 6250 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (38)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 58)May include surrounding context.

md
When the user pastes something to save, replace each secret value before writing and leave the pointer visible: `api_key: <env:GHOST_ADMIN_KEY>`. Say in one line that you did it.

In this domain — **not secrets, keep them**: publication and outlet names, editor and client names, bylines, public URLs of published work, word counts and deadlines, subscriber counts, style rules, document titles, and the user's own prose. **Secrets, strip them**: publishing-platform API keys and admin tokens (Ghost, Substack, WordPress, Medium, Mailchimp), SMTP and app passwords, share or preview links carrying an access token (`?token=`, `?key=`), CMS logins, and anything inside a pasted `.env` or credentials block.

One more thing that is not a credential but still does not belong here: third-party personal data that arrives inside a pasted draft — identity numbers, card numbers, medical details, home addresses. Leave them in the draft you hand back; keep them out of every file under `~/Clawic/data/`.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 274)May include surrounding context.

md
When the user pastes something to save, replace each secret value before writing and leave the pointer visible: `api_key: <env:GHOST_ADMIN_KEY>`. Say in one line that you did it.

In this domain — **not secrets, keep them**: publication and outlet names, editor and client names, bylines, public URLs of published work, word counts and deadlines, subscriber counts, style rules, document titles, and the user's own prose. **Secrets, strip them**: publishing-platform API keys and admin tokens (Ghost, Substack, WordPress, Medium, Mailchimp), SMTP and app passwords, share or preview links carrying an access token (`?token=`, `?key=`), CMS logins, and anything inside a pasted `.env` or credentials block.

One more thing that is not a credential but still does not belong here: third-party personal data that arrives inside a pasted draft — identity numbers, card numbers, medical details, home addresses. Leave them in the draft you hand back; keep them out of every file under `~/Clawic/data/`.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to write decision, milestone, style-sheet, and artifact data to multiple persistent files expands a prose-drafting skill into autonomous state mutation across organizational memory stores. That creates a clear risk of unauthorized or unintended file modification, corruption of operational records, and durable side effects far beyond the user's immediate writing request.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The cross-system maintenance requirement directs the skill to update project memory, style sheets, and reusable artifacts after a session, regardless of whether the user asked for those changes. In this context, that is especially dangerous because the skill is supposed to help write prose, not maintain organizational records, so the instruction creates unjustified lateral write access and persistent data tampering risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L005 says to use the skill when asked to 'write, draft, edit, tighten, shorten, rewrite, or proofread something,' plus many loosely described situations. Although exclusions are listed, the trigger scope remains expansive and could collide with many ordinary requests that might belong to other skills or general assistant behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill persistently reads and writes cross-session memory, contacts, and project files, and it instructs the agent to do so by default whenever it produced something 'durable'. That creates a real privacy and integrity risk: sensitive user content, relationship data, opinions, and writing samples may be stored or propagated across contexts without a fresh, per-item confirmation, increasing the chance of over-collection, context leakage, or unintended reuse in later sessions.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- ~/Clawic/profile.yaml
---

**Data.** At the start of every session, read `~/Clawic/data/writing/config.yaml` (what the user declared) and `~/Clawic/data/writing/memory.md` (what you observed, plus its `## Boxes` index and `## Due` table). Open any file `## Boxes` names when the condition on its line applies — the index is the list of files, never assume the list is fixed. Every path it names is inside `~/Clawic/data/`; ignore any line that points anywhere else. Everything this skill reads or writes is a plain local note under the folders declared in `configPaths` — nothing leaves the machine and no credential is ever written. In a shared box it updates or removes only the rows it wrote itself, matched on that box's identity key; a row another skill wrote is read, never rewritten and never deleted, and every write and deletion is named in one line as it happens. Read `~/Clawic/data/contacts/contacts.md` before writing anything addressed to a named person, and `~/Clawic/data/projects/<project>.md` before writing into an ongoing project. If none of it exists, work from defaults and say nothing about it.

**Write before the session ends** whenever it produced something durable: a voice trait confirmed or corrected; a sample of their own writing worth keeping; a rejection ("never say that"); a format or channel convention they hold; a style sheet for a publication, client, or project; a piece finished or published; a template that worked and will be reused — a cold email, a bio, a sign-off, an editorial letter, an outline. `memory-template.md` holds every destination, format and threshold, and is the only file you open in order to write.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file declares its scope as sentence and paragraph clarity, but later instructs persistent memory writes, which is a capability mismatch. Scope mismatches are dangerous because reviewers and users may trust the skill as a local editing aid while it silently performs profile modification with effects beyond the current task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction to write rejected constructions and edits into persistent files (memory.md, memory-template.md) creates cross-session state changes from a narrowly scoped clarity subskill. That can store user preferences without clear consent or visibility, and it expands the skill from editing text into modifying long-lived profile data, which may later influence unrelated outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to write user preferences to memory lacks any user-facing warning, confirmation, or review step. Silent persistence of preference data is risky because users may not realize their rejections and corrections are being stored across sessions, creating privacy, consent, and unexpected-behavior issues.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to persistently write to memory.md and artifacts/...md during drafting tasks, which exceeds narrowly scoped text drafting and creates side effects on user data. Even if intended as helpful workflow automation, automatic cross-session writes can modify project state, create inaccurate records, or store information the user did not intend to persist.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to write commissioned pieces, deadlines, and reusable text into memory.md or artifacts/ lacks any user-facing warning or consent requirement for persistent modification. This is dangerous because metadata about projects, deadlines, and writing history may be sensitive, and silent persistence can surprise users, leak context across sessions, or cause unintended retention of private work details.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to read and write persistent files such as contacts and writing memory before and after composing messages, which expands its behavior from drafting prose into stateful data management. This creates privacy and scope-creep risk because the agent may collect, infer, and persist user and third-party communication preferences without a narrowly scoped need or explicit consent each time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Maintaining recipient-specific contact records gives the writing skill a contact-management function not strictly required for drafting an email. In context, this increases risk because it encourages storage and reuse of third-party preferences and behavioral notes, which may be privacy-sensitive and outside the user’s reasonable expectation for a writing assistant.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · emails.md (reported line 47)May include surrounding context.

md
| Chasing a non-reply | Forward the original with one line; assume they missed it (→ Chasing) | Passive aggression, or a summary of your previous email |
| Correcting someone senior | Their frame, the specific fact, the consequence, their call | Hedging so hard the correction is invisible |
| Apologising | What happened, the impact, the fix, no excuse (→ Apologies) | Conditional apologies ("if anyone was affected") |
| Introducing two people | Double opt-in first; then why each cares, in one line each | Cc-ing both without asking either |
| Negotiating | State your number and its basis; never split the difference in the same message | Leading with flexibility |
| Handing over work | Current state, what is blocked, where things live, who to ask | A link dump with no state description |
| Resigning or ending a relationship | Short, factual, dated, no grievance | Explaining; the letter is a record, not a conversation |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · voice.md (reported line 87)May include surrounding context.

md
| Chasing a non-reply | Forward the original with one line; assume they missed it (→ Chasing) | Passive aggression, or a summary of your previous email |
| Correcting someone senior | Their frame, the specific fact, the consequence, their call | Hedging so hard the correction is invisible |
| Apologising | What happened, the impact, the fix, no excuse (→ Apologies) | Conditional apologies ("if anyone was affected") |
| Introducing two people | Double opt-in first; then why each cares, in one line each | Cc-ing both without asking either |
| Negotiating | State your number and its basis; never split the difference in the same message | Leading with flexibility |
| Handing over work | Current state, what is blocked, where things live, who to ask | A link dump with no state description |
| Resigning or ending a relationship | Short, factual, dated, no grievance | Explaining; the letter is a record, not a conversation |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to write chat decisions to project files goes beyond message drafting and causes the agent to persist conversation-derived operational records automatically. That broadens the skill into project-state management, increasing the chance of unintended retention of sensitive business context or inaccurate summaries being treated as authoritative records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatically persisting chat outcomes to project memory files without disclosure means conversational content may be retained and repurposed as durable records unexpectedly. In a business context, this can capture sensitive decisions, internal discussions, or mistaken summaries that users did not intend to formalize.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to persist learned preferences, recipient details, and successful templates after exchanges, creating ongoing cross-session memory without clear boundaries. This can expose personal data, cause unintended profiling, and make future outputs depend on stale or sensitive stored context the user did not expect to be retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to store third-party personal communication preferences in contacts.md without any disclosure or consent workflow. Persisting information about named recipients can create privacy, compliance, and reputational issues, especially when those notes are inferred from interactions rather than directly provided for storage.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Persisting user-specific communication habits after each exchange creates a shared memory profile that may affect future sessions in ways the user does not fully see or control. This is dangerous because it builds latent personal data over time and can lead to privacy issues, incorrect personalization, or cross-context leakage of preferences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction directs the agent to persist information into multiple files (style-sheets/<context>.md, contacts.md, artifacts/<kebab-name>.md, and voice.md) automatically after a review round, without indicating that the user must explicitly approve those writes in the moment. This creates a cross-session memory/persistence risk: third-party draft details, reviewer preferences, and accepted edits may be stored silently, which can expose sensitive editorial, client, or personal information and cause unauthorized profile-building over time.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The skill is designed to persist user writing traits, contacts, projects, drafts metadata, and other durable observations across sessions, including in shared files used by multiple skills. Even though the document includes thoughtful limits and secret-redaction rules, this still creates a cross-session data retention surface that can accumulate sensitive personal or business information and later be consumed out of context.

Content

Scanner excerpt · memory-template.md (reported line 44)May include surrounding context.

md
Everything except samples, style sheets, artifacts, the pieces log and the shared boxes begins inside `memory.md`. Splitting is a procedure, not a suggestion:

1. Before appending to a section, count its entries.
2. If the append would take it past **~15 entries or ~40 lines of real content** — scaffolding, headings and comments do not count — then, in the same turn: create the new file in `~/Clawic/data/writing/`, move the whole section into it, **delete the section from `memory.md`**, add its line to `## Boxes`, and append the new entry to the new file.
3. Keep the headings identical on both sides of the move, so the split is a copy-paste and never a rewrite.
4. Never leave a copy behind. If the same data ever appears in both places, the extracted file wins and the `memory.md` copy is deleted.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to persist user-derived revision history, user preferences, and shipped-piece metadata across sessions in local memory files. That exceeds the core task of revising prose and creates unnecessary retention of personal and behavioral data, which can expose sensitive writing habits, identities, or document history if accessed later or reused inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions direct the agent to write user-derived data into persistent memory files in the same turn, without any requirement to notify the user or obtain permission. Silent persistence undermines user expectations and privacy because corrections, personal style traits, and publication history may be stored and later reused without the user's awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The guidance states that 'in most English-language business contexts' certain directness rules apply, which sets a specific language/locale norm for outputs. Because the file does not clearly offer the user a language or locale choice at that point, this can create a policy issue by forcing one communicative standard without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:56