Back to skill

Security audit

Simple Claude Deep Research Agent

Security checks for vulnerabilities and agentic risk

Overview

The active skill is mainly a web research helper, but it bundles persistent permission settings and reference prompts that create review-worthy privacy and authority concerns.

Review before installing. Use it only in a constrained project, remove or narrow artifact/.claude/settings.local.json if you do not want broad Edit/Bash permissions, and do not reuse the bundled reference prompts with Slack, Gmail, Drive, Calendar, Asana, or similar integrations unless the user explicitly asks for that private data scope. Avoid putting secrets, confidential business data, internal URLs, or personal medical details into research prompts unless you accept the network and privacy exposure.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
research_lead_agent.md:131
Finding

Reference agent prompts mandate unnecessary access to private integrations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (49)

Bundled project settings declare a broad permission surface.

Critical
Category
Bundled Execution Surface
Confidence
99% confidence
Finding

Bundled project settings contain permission-related configuration; activation evidence distinguishes conditional grants from modes ignored on this surface.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CLAUDE.md (reported line 122)May include surrounding context.

md
### Testing Changes

1. Edit skill files
2. Test with: `deep-research <test query>`
3. Iterate based on results

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README_en.md (reported line 217)May include surrounding context.

md
### Testing Changes

1. Edit skill files
2. Test with: `deep-research <test query>`
3. Iterate based on results

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to use any additional internal read-only tools 'once or twice' even when they are not relevant to the user's request. That creates unnecessary access to private workspace data and violates data minimization, increasing the chance of unauthorized disclosure of Slack, Asana, Drive, or profile information unrelated to the task.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · skills.md (reported line 190)May include surrounding context.

ls .claude/skills/

View a specific Skill's content

cat ~/.claude/skills/my-skill/SKILL.md

text

## 测试 Skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills.md (reported line 322)May include surrounding context.

bash
# Personal
rm -rf ~/.claude/skills/my-skill

# Project
rm -rf .claude/skills/my-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills.md (reported line 322)May include surrounding context.

bash
# Personal
rm -rf ~/.claude/skills/my-skill

# Project
rm -rf .claude/skills/my-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skills.md (reported line 325)May include surrounding context.

rm -rf ~/.claude/skills/my-skill

Project

rm -rf .claude/skills/my-skill git commit -m "Remove unused Skill"

text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · skills.md (reported line 413)May include surrounding context.

bash
# View frontmatter
cat .claude/skills/my-skill/SKILL.md | head -n 15

# Check for common issues
# - Missing opening or closing ---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs users to submit arbitrary research queries to web-enabled agents without warning that prompts and embedded data may be sent to external services through web_search, web_fetch, or browser tooling. This creates a real privacy and data-handling risk if users include proprietary, personal, or regulated information in queries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file includes a medical example prompt about depression treatment but provides no caution that outputs are informational only and should not be used for diagnosis or urgent care. In a web-research skill, this increases the chance users submit sensitive health information or rely on generated summaries for medical decisions.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · CLAUDE.md (reported line 47)May include surrounding context.

md
- Receives tasks from lead agent
   - Uses web tools (web_search, web_fetch, Playwright MCP)
   - Reports findings in dense format
   - Limited to 20 tool calls

3. **Citations Agent** (`.claude/skills/citations.md`)
   - Adds citations to completed reports

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · IMPLEMENTATION_SUMMARY.md (reported line 11)May include surrounding context.

md
## 实现的功能

### ✅ 三个核心 Agent Skills

1. **Research Lead Agent** (`.claude/skills/deep-research.md`)
   - 查询分析和分类(3 种类型)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a natural-language locale constraint: '主要针对英语查询优化' ('primarily optimized for English queries'). Under the policy, forcing or preferring a specific language without user opt-in can be a language/locale policy violation, and the file does not present this as an optional user choice or a clearly justified regional requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and entire report are written in Chinese, and there is no indication that language selection is optional or that the file is intended only for a Chinese-speaking or region-specific context. The policy calls for flagging language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README documents automatic use of web_search, web_fetch, and Playwright for dynamic pages, but does not clearly warn users that their queries and possibly surrounding context may be transmitted to external services or remote websites. In a research skill that can automatically browse and fetch pages, lack of disclosure and consent increases privacy and data-handling risk, especially if users submit sensitive prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README describes web_search, web_fetch, and Playwright-based browsing but does not warn users that their prompts, search queries, and fetched page interactions may be transmitted to external services and third-party websites. This can lead to inadvertent disclosure of sensitive user data if users submit confidential research topics, credentials, internal URLs, or proprietary content.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_en.md (reported line 192)May include surrounding context.

md
### Skill Files

Skills are automatically loaded from `.claude/skills/`:
- `deep-research.md`: Main research coordination
- `research-subagent.md`: Subagent research logic
- `citations.md`: Citation addition

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions tell the agent to access integrations and even identify the user or inspect tasks/profile data without any user-facing disclosure or opt-in. This can lead to silent collection and use of personal or organizational data that the user did not realize would be touched during a research task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates use of additional internal tools whenever available, regardless of whether the user requested or needs them. A mandatory-use rule defeats least-privilege behavior and can cause the agent to over-collect sensitive internal data simply because the tools exist.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill broadly instructs the agent to access internal communications, tasks, profiles, and documents, including identifying the user, instead of limiting collection to narrowly scoped data. This broad authority materially raises privacy and confidentiality risk, especially in enterprise contexts where integrated systems contain sensitive employee, customer, and business information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The report gives extensive treatment guidance, medication options, and severity-based recommendations before presenting any crisis or emergency safety guidance. In a mental-health context, a reader in acute distress could rely on the document for self-management and miss the need for urgent help when experiencing suicidal thoughts, psychosis, or inability to stay safe.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs the agent to ALWAYS use internal tools such as Google Drive, Gmail, and Calendar whenever they are available and potentially relevant. That creates a privacy and data-minimization risk because it can cause unnecessary access to personal or non-public data without requiring explicit user consent for the specific task, narrowing scope, or warning about sensitive data handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents nearly all instructional content in Chinese, which constitutes a locale/language constraint in natural-language guidance. The document does not offer the user an explicit language choice or explain that the locale is intentionally region-specific, so it fits the policy-violation criteria for forced language without opt-in.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skills.md (reported line 35)May include surrounding context.

md
Skills 存储为包含 `SKILL.md` 文件的目录。

### 个人 Skills

个人 Skills 在您的所有项目中都可用。将它们存储在 `~/.claude/skills/` 中: