T09 · Insecure Skill Coding Practices
- Location
docs/brain-sync-architecture.md:37- Finding
Live CouchDB Administrator Credentials Committed to Repository Documentation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This package looks like a personal workspace rather than a scoped skill and exposes sensitive credentials while enabling broad automation and persistence.
Do not install or publish this package as-is. Treat the exposed database and remote-access credentials as compromised, rotate them, remove personal workspace docs and secrets, split the contents into separately scoped skills, and add explicit consent, authentication, confirmation, and disablement controls for automation, location tracking, sync, and auto-update behavior.
docs/brain-sync-architecture.md:37Live CouchDB Administrator Credentials Committed to Repository Documentation
skills/lastfm/SKILL.md:12Last.fm API Key Is Transmitted over Plain HTTP
docs/hammerspoon-setup.md:36Unauthenticated Hammerspoon HTTP API Provides GUI Click and Keystroke Control
skills/findmy-location/findmy-location.py:47Location Skill Ignores the Configured Target and Captures the Entire Screen to an Unprotected Temporary Path
skills/auto-updater/SKILL.md:29Unattended Daily Updates Install Mutable Remote Code Without Version Pinning or Review
skills/self-improving-agent/SKILL.md:160User-Controlled Corrections Can Be Promoted into Persistent Agent Instructions
skills/whatisxlistening-to/lastfm_cli.py:109Last.fm API Credential Is Stored in a Plaintext Configuration File Without Permission Hardening
skills/whatisxlistening-to/server.py:420Dashboard Exposes Listening History on All Interfaces Without Authentication
This document exposes live remote-access credentials for VNC, including a weak password and username/password pair, which materially lowers the barrier to unauthorized access if the file is readable by others or synced to additional devices. In the context of an automation agent with screen-control capabilities, compromise could lead to full interactive control of the host, access to synced notes, and abuse of other local tools.
This section proposes collecting or accessing highly sensitive mobile-device data and sensors, including location and camera access. The markdown description should explicitly warn that these capabilities have major privacy implications and require clear user consent and controls.
This documentation exposes live administrative CouchDB credentials alongside the reachable service URL and example commands for using them. Anyone who can access this file can authenticate to the database, inspect or modify synchronized notes, and potentially destroy data or pivot further into the environment; the surrounding operational detail makes exploitation straightforward rather than theoretical.
The iOS setup section repeats plaintext admin credentials and the remote endpoint, giving complete instructions for connecting a client to the production database. This increases exposure because it enables immediate reuse of the same privileged credentials on another device, broadening the attack surface and making credential theft or unauthorized synchronization trivial.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**Account:** clawdbot org on ensue.network
- Email: poileclawdbot@icloud.com
- API Key: Stored in Keychain as "ensue-api-key"
**Obsidian → Ensue Push:**
Add frontmatter to any note:
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
API_BASE="https://api.ensue-network.ai/v1"
if [[ -z "$API_KEY" ]]; then
# Try to get from keychain
API_KEY=$(security find-generic-password -a "clawdbot" -s "ensue-api-key" -w 2>/dev/null || true)
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
API_BASE="https://api.ensue-network.ai/v1"
if [[ -z "$API_KEY" ]]; then
# Try to get from keychain
API_KEY=$(security find-generic-password -a "clawdbot" -s "ensue-api-key" -w 2>/dev/null || true)
fi
This skill is explicitly designed to track a shared contact's live location with street-level accuracy, capture screenshots, and infer context such as home/work, yet it provides no prominent warning about the sensitivity of that data or the risks of storing or exposing it. In this context, omission of privacy/safety guidance materially increases the chance of misuse, overcollection, or accidental disclosure of highly sensitive location information.
This is a true tool-parameter abuse issue because shell invocation is used as a generic transport layer for multiple external tools. The skill interacts with GUI automation, screenshots, and local binaries, so a compromised path or crafted value can escalate from input manipulation to arbitrary command execution and broader system/data compromise.
}
def run(cmd):
return subprocess.run(cmd, shell=True, capture_output=True, text=True).stdout.strip()
def load_config():
if os.path.exists(CONFIG_PATH):
The script captures a full screen image and returns its path without any notice, consent, or scoping to only the Find My window. Screenshots can contain unrelated secrets such as messages, tokens, emails, or other personal data, making this a substantial privacy and data-exposure risk.
The error template asks for raw error messages, command inputs, and environment details, which commonly contain secrets such as access tokens, connection strings, file paths, hostnames, internal endpoints, and customer data. Without redaction guidance, users or agents are likely to copy sensitive material verbatim into persistent files, creating a straightforward disclosure path.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- deployment.yaml
- service.yaml
- ingress.yaml
# Note: secret.yaml excluded - create manually or via external-secrets
# Override these values in your overlay or via `kustomize edit set image`
images:
The next-steps section proposes proactive monitoring of calendar and email, which would involve ongoing access to sensitive personal data. For markdown files, behaviors that could affect user privacy should be accompanied by an explicit warning or disclosure about the scope of access and consent expectations.
The instructions recommend removing the app quarantine attribute with xattr -cr, which bypasses normal macOS Gatekeeper checks and suppresses a security control designed to warn about untrusted software. Documenting this without a warning encourages users to disable a platform protection and could normalize unsafe installation practices for software that will later receive powerful Accessibility permissions.
The configuration starts an HTTP server that accepts unauthenticated automation commands capable of clicking, typing, and pressing keys while Hammerspoon has Accessibility access. Even if intended for localhost use, exposing this without authentication or safety guidance is dangerous because any local malware, untrusted script, browser exploit, or user session process could drive the desktop and interact with security dialogs or sensitive apps.
The documented interface exposes arbitrary text entry and keypress injection through /type and /key, which goes beyond simple coordinate clicking and grants the caller the ability to drive sensitive UI flows, approve prompts, or enter commands into any focused application. Because the service is unauthenticated and paired with Accessibility privileges, any local process that can reach localhost can potentially abuse it for broader UI control.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Click
curl -X POST localhost:9090/click -d '{"x":500,"y":400}'
# Double-click
curl -X POST localhost:9090/doubleclick -d '{"x":500,"y":400}'
With no manifest available, this skill has no declared purpose that would justify reading secrets from the environment and the system keychain. The code explicitly accesses ENSUE_API_KEY and falls back to security find-generic-password, which is a broader credential-access capability than a generic wrapper interface alone implies.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
set -euo pipefail
API_KEY="${ENSUE_API_KEY:-}"
API_BASE="https://api.ensue-network.ai/v1"
if [[ -z "$API_KEY" ]]; then
# Try to get from keychain
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
case "$METHOD" in
discover_memories)
curl -sS -X POST "$API_BASE/memories/discover" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "$ARGS"
The script exposes a delete operation that will execute immediately against the remote API with arbitrary JSON arguments and no confirmation, dry-run mode, or guardrails. In an agent-skill context, this increases the risk of accidental or prompt-induced destructive actions that permanently remove user data.
The skill explicitly configures unattended daily updates that modify both the Clawdbot installation and all installed skills, but it does not prominently warn that this will automatically perform system-wide writes and execute newly fetched code on a schedule. That creates a meaningful supply-chain and operational risk: users may enable recurring privileged changes without understanding that future remote updates can alter local behavior without per-update review.
The skill documents and promotes commands such as clawdhub update --all --no-input --force without any warning that they can automatically modify all installed skills non-interactively. In an agent setting, this increases the chance of unattended supply-chain changes, accidental breakage, or pulling in malicious/unsafe updates from a registry or overridden registry source.
This skill is explicitly designed to track another person's real-time location, capture screenshots, and infer addresses/context from map data, yet the README provides no meaningful privacy warning, consent guidance, or limitation on misuse. Because the capability involves highly sensitive location data and street-level tracking, the missing safeguards materially increase the risk of stalking, surveillance, and other privacy abuse.
The instructions create a persistent local helper script and a continuously running Hammerspoon HTTP server that accepts click commands, establishing a reusable control surface on the user's machine. Even though intended for convenience, this kind of persistent automation endpoint can be abused by other local malware or misconfigurations to drive UI actions without user awareness.
server:start()
Reload config (Hammerspoon menu → Reload Config), then create `~/.local/bin/hsclick`:
```bash
#!/bin/bash
curl -s -X POST localhost:9090/click -d "{\"x\":$2,\"y\":$3}"
Detected: suspicious.exposed_secret_literal