T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:13- Finding
Unrestricted Sensitive-Data Access and Autonomous External Actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Review case because it advertises autonomous access to email, messaging, social posting, and attachments without enough scope, approval, or privacy detail.
Before installing, require draft-only defaults or per-action approval for every send, post, outreach message, job application, and attachment. Ask for exact OAuth scopes, token storage and revocation details, recipient and attachment allowlists, audit logging, rate limits, a kill switch, and a clear explanation of what data stays local versus what Base44 or other third-party services process.
SKILL.md:13Unrestricted Sensitive-Data Access and Autonomous External Actions
SKILL.md:101Contradictory Local-Only Privacy and Hosted-Backend Claims
The marketing copy promotes autonomous Gmail monitoring, reply drafting/sending, lead outreach, and WhatsApp auto-replies without any disclosure of data access, consent requirements, or safeguards for outbound communications. In the context of an agent skill, this can normalize deployment of automated messaging features that access sensitive personal data and send external communications without clear user review, increasing privacy, compliance, and reputational risk.
The README explicitly promotes autonomous email monitoring, drafting, and sending, including sending a CV, but provides no warning about privacy exposure, consent, account access scope, or unintended outbound communications. In an agent skill context, this can lead users to enable broad email automation without understanding that sensitive inbox data may be processed and messages may be sent externally on their behalf.
The README advertises automatic lead prospecting and auto-replies, which are autonomous external actions that can contact third parties or act on user accounts without adequate disclosure of risks. Without warnings or constraints, users may deploy behavior that causes spam, privacy issues, reputational damage, or policy violations across messaging and social platforms.
The skill advertises fully autonomous emailing, messaging, job applications, and social posting without prominent warnings about unsupervised external actions. This is dangerous because it can cause unauthorized communications, privacy breaches, reputational damage, spam, or accidental disclosure of sensitive documents such as CVs and business data if users enable autonomy without understanding the risks.
The security/privacy section claims data never leaves the user's machine and presents strong privacy assurances, but the skill explicitly relies on Gmail, WhatsApp, Telegram, Discord, and other third-party services. This creates misleading privacy expectations because user content, metadata, tokens, and outbound communications necessarily transit or reside with external providers, increasing compliance and data-handling risk.
The description advertises an 'autonomous business agent' that handles prospecting, email, marketing, and lead qualification 'on autopilot' without describing approval gates, scope limits, or trigger constraints. In a skill that can manage communications and job applications across multiple channels, this ambiguity can enable unsolicited outreach, unintended actions, or abuse if the agent is invoked with insufficient oversight.
The config sets the agent language to "nl", which imposes a specific language choice in natural-language behavior. There is no indication in this file that users can select another language or that the locale restriction is justified by a region-specific requirement.
The document presents the skill as "Badman" and says to publish "badman-clawhub" (L12), but the install command advertises badman-agent-rental (L33, L45). This is an intent/documentation inconsistency that could mislead users about what is actually being published or installed.
The skill description implies autonomous outreach and communication handling but does not state any user-configurable language, locale, or audience controls. This increases the risk of sending inappropriate, noncompliant, or misleading messages to recipients in the wrong language or region, especially across WhatsApp, Telegram, and Discord.
No suspicious patterns detected.