Back to skill

Security audit

Save Money

Security checks for vulnerabilities and agentic risk

Overview

This skill is a cost-saving model router, but it automatically forwards broad categories of user requests to a hard-coded Sonnet session without clear user confirmation or visible disclosure.

Review this skill carefully before installing. It may save money on simple tasks, but it can automatically send full prompts, including sensitive business or personal content, to a spawned Sonnet session without first asking and without mentioning the switch unless you ask.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Global Agent Behavior and Session-Routing Hijack

Content
View full analysis
- Auto-detect task complexity for Claude models (Haiku + Sonnet). Route simple tasks to Haiku, escalate complex ones to Sonnet. Save 50%+ on API costs. | 適用 Claude 模型(Haiku + Sonnet),自動偵測任務難度,簡單用 Haiku,複雜升級 Sonnet,輕鬆省下 50% 以上的費用。— RULES: Before responding, classify the task. If it matches an escalation trigger, call sessions_spawn with the full task and model anthropic/claude-sonnet-4-20250514 IMMEDIATELY. Do NOT answer complex tasks yourself. ESCALATE: analysis, comparisons, planning, strategy, code >10 lines, reports, proposals, multi-step reasoning, tables, outlines, charts, long writing >3 paragraphs, summarization, long translation. NEVER on Haiku: comparison tables, code >10 lines, multi-step analysis, reports, complex reasoning. STAY on Haiku: factual Q&A, definitions, greetings, reminders, short lookups, casual chat, 1-2 sentence tasks. When in doubt, escalate. Keep Haiku replies concise. ``` The same mandatory behavior is reinforced in `SKILL.md`, lines 25–31: ```markdown Before generating ANY response, you MUST: 1. Check: does this task match ANY escalation trigger below? 2. If YES → call `sessions_spawn()` IMMEDIATELY. Do NOT attempt to answer yourself. 3. If NO → respond directly on the current model. ``` The document explicitly states the mechanism used to ensure these instructions affect the Agent when the Skill is loaded in `SKILL.md`, lines 150–159: ```markdown The Clawdbot skill system only injects the frontmatter `description` field into the system prompt — the body of SKILL.md is **not** automatically included. The model may optionally `read` the full file, but it is not guaranteed. Because this is a **behavioral skill** (changing how the model routes every message) rather than a tool skill (teaching CLI com ...[truncated 3496 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The rule of thumb to escalate anything requiring more than 30 seconds of focused thinking is highly subjective and effectively acts as a catch-all trigger. In practice, this can redirect many ordinary requests and makes behavior unpredictable, while also increasing the frequency with which full user prompts are sent to another model.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The escalation examples use broad everyday phrases such as requests to think, compare, summarize, or plan, which are common in normal chat and can cause routine prompts to be forwarded unnecessarily. Because the skill instructs immediate spawning with the full task, this broad matching increases the chance of excessive delegation and unintended disclosure of user content to another model/session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The file hard-codes routing behavior based on example trigger phrases in English, Traditional Chinese, Japanese, Korean, and German, but does not state that language handling is user-selectable or optional. This is a natural-language policy concern because the skill imposes predefined locale behavior rather than explicitly offering a language/locale choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Using prompt length greater than 200 characters as a complexity signal is too unspecific, since many harmless prompts exceed that size without needing delegation. This can lead to unnecessary spawning and additional exposure of user input, though the impact is lower because length alone is only one of several listed signals.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.