Back to skill

Security audit

the ediscovery claw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent e-discovery command guide with sensitive legal-data handling that is expected for its purpose, but users should apply normal legal review and data-protection controls.

Install only if you trust the external edisclaw Homebrew package and are authorized to process the matter data. Treat ~/.edisclaw/ as sensitive legal data, protect the host appropriately, verify privilege and redaction decisions before production, and review any Pro or Litigation features before allowing external API use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages ingestion, storage, and analysis of ESI collections, which commonly include privileged communications, personal data, and other highly sensitive legal materials, but it does not clearly warn users about those risks up front. In a legal-discovery context, missing privacy and handling warnings can lead users to process regulated or confidential data locally without appropriate safeguards, retention controls, or authorization.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The production and export commands can generate new production sets, redacted outputs, and load files that may disclose responsive, privileged, or insufficiently reviewed documents if used incorrectly, yet the skill presents them without a clear warning or verification step. In e-discovery, accidental overproduction is a serious legal and confidentiality risk because exported files are intended for disclosure and may be relied on as final productions.

Static analysis

No suspicious patterns detected.