T09 · Insecure Skill Coding Practices
- Location
scripts/run-debate.sh:7- Finding
Shell Command Injection in Generated Debate Commands
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plausible decision-debate helper, but it needs review because its copy-paste shell workflow can run unintended commands and it encourages storing sensitive decision data without privacy safeguards.
Review the helper script before using it. Do not run generated commands from untrusted or shared debate topics, and avoid putting secrets, customer data, regulated data, or full private session transcripts into the debate archive unless you redact and protect them. Publishers should also pin any CLI install instructions.
scripts/run-debate.sh:7Shell Command Injection in Generated Debate Commands
PUBLISH.md:29Unpinned Global npm Package Installation
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
To update the skill for future versions:
The code is related to the declared purpose in that it supports multi-viewpoint analysis using the named personas. However, the description overstates the implementation. The script does not directly execute the three sub-agent spawns; it echoes commands for the user to copy and run. It also does not automatically collect, save, or archive any outputs, despite the description stating that debate outputs are automatically captured for future reference and pattern analysis. This is a material description-behavior mismatch because the claimed automation and archival capabilities are absent from the supplied code.
The tips section encourages use of 'actual context,' including 'specific metrics' and 'real user data,' without any privacy or security guardrails. In this skill's context, that is more dangerous because the same document also recommends saving full persona responses and metadata to an archive, increasing the chance that personal data, customer information, or confidential operational details are disclosed to sub-agents and then retained long-term.
The skill explicitly instructs users to archive full debate outputs, metadata, context, and later use the archive for search and pattern analysis, but it provides no warning about storing sensitive prompts, personal business decisions, or third-party data. This creates a real privacy and data-governance risk because users may persist confidential material indefinitely in markdown files and indexes without considering minimization, retention, or access controls.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
cat /home/nick/clawd/skills/multi-viewpoint-debates/SKILL.md | head -100
This is what ClawdBot will show to users when they search for "debate" or "decision-making."
The template hard-codes persona labels, including 'Monkey', which is a culturally loaded term that can be interpreted as demeaning or discriminatory depending on context and audience. Because the skill is designed for repeated use and archival, this language can normalize offensive framing, create hostile outputs, and propagate harmful content into stored records or downstream analysis.
The example response explicitly pressures the user toward a major life and career decision using absolutist, emotionally manipulative framing ('you already know the answer is yes', 'unremarkable life') without any safety caveats or uncertainty handling. In the context of a decision-support skill designed to influence user choices through strong personas, this can unduly steer vulnerable users into high-risk actions without balanced consideration of finances, obligations, mental health, or downside scenarios.
The file instructs users to copy full session transcripts from a local JSONL path into an archive without warning that those transcripts may include secrets, personal data, prompts, or other sensitive context. That creates a realistic risk of unnecessary data exposure, especially if the archive is later shared, indexed, synced, or committed to a repository.
The comment says the script will read persona references and inline them for the spawn command, and lines L020-L022 do read the three reference files into variables. However, those variables are never used; the generated commands embed separate hardcoded persona definitions instead. This creates a mismatch between the documented behavior and the actual implementation.
The comment at L019 explicitly states that persona references are read to be inlined into the spawn command. In reality, the variables populated at L020-L022 are unused, and the heredoc below contains hardcoded frameworks. This is an active contradiction between code documentation and actual behavior, not just incomplete documentation.
No suspicious patterns detected.