Back to skill

Security audit

Badman — AI Agent Rental

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review case because it advertises autonomous access to email, messaging, social posting, and attachments without enough scope, approval, or privacy detail.

Before installing, require draft-only defaults or per-action approval for every send, post, outreach message, job application, and attachment. Ask for exact OAuth scopes, token storage and revocation details, recipient and attachment allowlists, audit logging, rate limits, a kill switch, and a clear explanation of what data stays local versus what Base44 or other third-party services process.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:13
Finding

Unrestricted Sensitive-Data Access and Autonomous External Actions

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:101
Finding

Contradictory Local-Only Privacy and Hosted-Backend Claims

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The marketing copy promotes autonomous Gmail monitoring, reply drafting/sending, lead outreach, and WhatsApp auto-replies without any disclosure of data access, consent requirements, or safeguards for outbound communications. In the context of an agent skill, this can normalize deployment of automated messaging features that access sensitive personal data and send external communications without clear user review, increasing privacy, compliance, and reputational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly promotes autonomous email monitoring, drafting, and sending, including sending a CV, but provides no warning about privacy exposure, consent, account access scope, or unintended outbound communications. In an agent skill context, this can lead users to enable broad email automation without understanding that sensitive inbox data may be processed and messages may be sent externally on their behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises automatic lead prospecting and auto-replies, which are autonomous external actions that can contact third parties or act on user accounts without adequate disclosure of risks. Without warnings or constraints, users may deploy behavior that causes spam, privacy issues, reputational damage, or policy violations across messaging and social platforms.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises fully autonomous emailing, messaging, job applications, and social posting without prominent warnings about unsupervised external actions. This is dangerous because it can cause unauthorized communications, privacy breaches, reputational damage, spam, or accidental disclosure of sensitive documents such as CVs and business data if users enable autonomy without understanding the risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The security/privacy section claims data never leaves the user's machine and presents strong privacy assurances, but the skill explicitly relies on Gmail, WhatsApp, Telegram, Discord, and other third-party services. This creates misleading privacy expectations because user content, metadata, tokens, and outbound communications necessarily transit or reside with external providers, increasing compliance and data-handling risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description advertises an 'autonomous business agent' that handles prospecting, email, marketing, and lead qualification 'on autopilot' without describing approval gates, scope limits, or trigger constraints. In a skill that can manage communications and job applications across multiple channels, this ambiguity can enable unsolicited outreach, unintended actions, or abuse if the agent is invoked with insufficient oversight.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The config sets the agent language to "nl", which imposes a specific language choice in natural-language behavior. There is no indication in this file that users can select another language or that the locale restriction is justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document presents the skill as "Badman" and says to publish "badman-clawhub" (L12), but the install command advertises badman-agent-rental (L33, L45). This is an intent/documentation inconsistency that could mislead users about what is actually being published or installed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The skill description implies autonomous outreach and communication handling but does not state any user-configurable language, locale, or audience controls. This increases the risk of sending inappropriate, noncompliant, or misleading messages to recipients in the wrong language or region, especially across WhatsApp, Telegram, and Discord.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.