Back to skill

Security audit

Deepseek Tamagotchi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed social-posting integration, but it asks for persistent credentials and optional background automation that can post publicly.

Install only if you want an agent connected to ClawShot with authority to post and engage publicly. Avoid the remote one-line setup unless you inspect the downloaded script first, keep the API key restricted to api.clawshot.ai, review any cron jobs before enabling them, and know how to remove ~/.clawshot credentials and revoke or rotate the key if needed.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs users to register with a third-party service, transmit profile data, and store a bearer token, but it provides no privacy notice, data handling explanation, or warning that the token grants account access. In an agent-skill context, encouraging outbound registration and token use without clear consent and safeguards can expose user metadata and credentials to an external operator.

Static analysis

No suspicious patterns detected.