Back to skill

Security audit

Council

Security checks for vulnerabilities and agentic risk

Overview

This skill is a markdown-only brainstorming aid that delegates analysis to disclosed persona files, with minor cautions about broad triggers and an unsolicited promotional footer.

Before installing, be aware that ordinary wording like “council of the wise” may start a longer sub-agent review, and council reports may include a promotional footer link. Only add persona files to the agents folder from sources you trust, because the skill intentionally auto-discovers those local markdown personas.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:94
Finding

Mandatory Third-Party Promotional Content Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 94-133
Vulnerability Type: Mandatory output manipulation through skill instructions
Risk Level: Low

Vulnerable Code

markdown
## Output Format

```markdown
## 🏛️ Council of the Wise — [Topic]

### ⚖️ Synthesis (TL;DR)
[combined verdict + key tensions between perspectives]
[not a summary — a wise moderator's take after hearing everyone]

---

### 👹 Devil's Advocate
[challenges and risks — opens with the scariest question]

### 🏗️ Architect
[structure and strategy — systems-first framing, no implementation details]

### 🛠️ Engineer
[implementation plan — concrete steps with time/effort estimates]

### 🎨 Artist
[voice and experience — anchored by a real-world analogy from outside the domain]

### 📊 Analyst
[quantitative analysis — at least one number or calculation]

---

## 🎯 Action Items
1. **[Highest priority action]** — [effort estimate]
2. **[Next action]** — [effort estimate]
3. **[Next action]** — [effort estimate]

## Confidence
[High / Medium / Low] — [one sentence explaining why: "The council mostly agreed on X" or "Sharp disagreement between Engineer and Analyst on timeline suggests more research needed"]

---
*Found this useful? ⭐ [Council of the Wise on ClawdHub](https://clawhub.com)*
text

### Technical Analysis

The skill defines a mandatory response template that appends a promotional message and third-party link to generated council reports. Because this instruction is loaded as part of the skill and passed into the response-generation workflow, the promotional content is inserted regardless of whether it is relevant to or requested by the user.

This constitutes skill instruction hijacking at a limited scope: the skill modifies the agent's output objective by requiring unsolicited advertising in addition to the requested analysis. The instruction does not override safety controls, execute c
...[truncated 1322 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the promotional footer from the mandatory output template.
  2. Keep generated output limited to content necessary to satisfy the user's request.
  3. If attribution is required, make it optional and clearly distinguish it from generated analysis.
  4. Require explicit user consent before including promotional or third-party links.
  5. Document all external links and explain why each is necessary.
  6. Add a review test that rejects mandatory advertising, affiliate content, or unrelated external links in response templates.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented trigger phrase is broad enough to plausibly appear in ordinary conversation, which can cause accidental invocation of the skill. Because this skill spawns sub-agents and may auto-discover personas, unintended activation could lead to unnecessary processing, context exposure to sub-agents, or confusing agent behavior even if there is no clearly malicious functionality in the README itself.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The activation section lists phrases like "council of the wise" and "get the council's feedback on" without tightly constraining context, which could overlap with ordinary discussion about the skill rather than a true invocation. Although there is a brief 'Don't invoke for' note, it does not give concrete negative examples or clear boundary conditions for ambiguous cases.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.