Back to skill

Security audit

Multi-viewpoint Debates

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible decision-debate helper, but it needs review because its copy-paste shell workflow can run unintended commands and it encourages storing sensitive decision data without privacy safeguards.

Review the helper script before using it. Do not run generated commands from untrusted or shared debate topics, and avoid putting secrets, customer data, regulated data, or full private session transcripts into the debate archive unless you redact and protect them. Publishers should also pin any CLI install instructions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-debate.sh:7
Finding

Shell Command Injection in Generated Debate Commands

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
PUBLISH.md:29
Finding

Unpinned Global npm Package Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · PUBLISH.md (reported line 88)May include surrounding context.

To update the skill for future versions:

  1. Update VERSION file
  2. Update SKILL.md or reference materials as needed
  3. Publish with new version number:
bash

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is related to the declared purpose in that it supports multi-viewpoint analysis using the named personas. However, the description overstates the implementation. The script does not directly execute the three sub-agent spawns; it echoes commands for the user to copy and run. It also does not automatically collect, save, or archive any outputs, despite the description stating that debate outputs are automatically captured for future reference and pattern analysis. This is a material description-behavior mismatch because the claimed automation and archival capabilities are absent from the supplied code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tips section encourages use of 'actual context,' including 'specific metrics' and 'real user data,' without any privacy or security guardrails. In this skill's context, that is more dangerous because the same document also recommends saving full persona responses and metadata to an archive, increasing the chance that personal data, customer information, or confidential operational details are disclosed to sub-agents and then retained long-term.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to archive full debate outputs, metadata, context, and later use the archive for search and pattern analysis, but it provides no warning about storing sensitive prompts, personal business decisions, or third-party data. This creates a real privacy and data-governance risk because users may persist confidential material indefinitely in markdown files and indexes without considering minimization, retention, or access controls.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · START_HERE.md (reported line 11)May include surrounding context.

1. Review the Skill (2 minutes)

bash
cat /home/nick/clawd/skills/multi-viewpoint-debates/SKILL.md | head -100

This is what ClawdBot will show to users when they search for "debate" or "decision-making."

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template hard-codes persona labels, including 'Monkey', which is a culturally loaded term that can be interpreted as demeaning or discriminatory depending on context and audience. Because the skill is designed for repeated use and archival, this language can normalize offensive framing, create hostile outputs, and propagate harmful content into stored records or downstream analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example response explicitly pressures the user toward a major life and career decision using absolutist, emotionally manipulative framing ('you already know the answer is yes', 'unremarkable life') without any safety caveats or uncertainty handling. In the context of a decision-support skill designed to influence user choices through strong personas, this can unduly steer vulnerable users into high-risk actions without balanced consideration of finances, obligations, mental health, or downside scenarios.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file instructs users to copy full session transcripts from a local JSONL path into an archive without warning that those transcripts may include secrets, personal data, prompts, or other sensitive context. That creates a realistic risk of unnecessary data exposure, especially if the archive is later shared, indexed, synced, or committed to a repository.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comment says the script will read persona references and inline them for the spawn command, and lines L020-L022 do read the three reference files into variables. However, those variables are never used; the generated commands embed separate hardcoded persona definitions instead. This creates a mismatch between the documented behavior and the actual implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The comment at L019 explicitly states that persona references are read to be inlined into the spawn command. In reality, the variables populated at L020-L022 are unused, and the heredoc below contains hardcoded frameworks. This is an active contradiction between code documentation and actual behavior, not just incomplete documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.