Back to skill

Security audit

whatisxlistening.to

Security checks for vulnerabilities and agentic risk

Overview

This package looks like a personal workspace rather than a scoped skill and exposes sensitive credentials while enabling broad automation and persistence.

Do not install or publish this package as-is. Treat the exposed database and remote-access credentials as compromised, rotate them, remove personal workspace docs and secrets, split the contents into separately scoped skills, and add explicit consent, authentication, confirmation, and disablement controls for automation, location tracking, sync, and auto-update behavior.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
docs/brain-sync-architecture.md:37
Finding

Live CouchDB Administrator Credentials Committed to Repository Documentation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/lastfm/SKILL.md:12
Finding

Last.fm API Key Is Transmitted over Plain HTTP

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
docs/hammerspoon-setup.md:36
Finding

Unauthenticated Hammerspoon HTTP API Provides GUI Click and Keystroke Control

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skills/findmy-location/findmy-location.py:47
Finding

Location Skill Ignores the Configured Target and Captures the Entire Screen to an Unprotected Temporary Path

Content
View full analysis
/dev/null') try: win = json.loads(win_json) bounds = win.get('data', {}).get('windows', [{}])[0].get('bounds', [[0, 0]])[0] wx, wy = bounds[0], bounds[1] except: wx, wy = 0, 0 # Click on second row (first shared contact) hsclick = find_hsclick() click_x, click_y = wx + 120, wy + 173 if hsclick: run(f'{hsclick} click {click_x} {click_y}') else: run(f'peekaboo click --coords {click_x},{click_y} --app "Find My" 2>/dev/null') run('sleep 1') # Get accessibility data see = run('peekaboo see --app "Find My" --json 2>/dev/null') img = f"/tmp/findmy-{os.getpid()}.png" run(f'peekaboo image --mode screen --screen-index 0 --path {img} 2>/dev/null') ``` ### Technical Analysis Although the function resolves a configured `target`, that value is never used to select or validate a contact. The implementation instead clicks a fixed coordinate described as the first shared contact. It can therefore return and capture the location of a different person than the user requested. The fallback image captures the entire screen rather than only the Find My window or map region. This can collect unrelated messages, credentials, documents, notifications, and other sensitive application content. The screenshot is written to a predictable `/tmp/findmy-.png` path and is not ...[truncated 1250 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
skills/auto-updater/SKILL.md:29
Finding

Unattended Daily Updates Install Mutable Remote Code Without Version Pinning or Review

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
skills/self-improving-agent/SKILL.md:160
Finding

User-Controlled Corrections Can Be Promoted into Persistent Agent Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills/whatisxlistening-to/lastfm_cli.py:109
Finding

Last.fm API Credential Is Stored in a Plaintext Configuration File Without Permission Hardening

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
skills/whatisxlistening-to/server.py:420
Finding

Dashboard Exposes Listening History on All Interfaces Without Authentication

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (76)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This document exposes live remote-access credentials for VNC, including a weak password and username/password pair, which materially lowers the barrier to unauthorized access if the file is readable by others or synced to additional devices. In the context of an automation agent with screen-control capabilities, compromise could lead to full interactive control of the host, access to synced notes, and abuse of other local tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section proposes collecting or accessing highly sensitive mobile-device data and sensors, including location and camera access. The markdown description should explicitly warn that these capabilities have major privacy implications and require clear user consent and controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This documentation exposes live administrative CouchDB credentials alongside the reachable service URL and example commands for using them. Anyone who can access this file can authenticate to the database, inspect or modify synchronized notes, and potentially destroy data or pivot further into the environment; the surrounding operational detail makes exploitation straightforward rather than theoretical.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The iOS setup section repeats plaintext admin credentials and the remote endpoint, giving complete instructions for connecting a client to the production database. This increases exposure because it enables immediate reuse of the same privileged credentials on another device, broadening the attack surface and making credential theft or unauthorized synchronization trivial.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/brain-sync-architecture.md (reported line 137)May include surrounding context.

md
**Account:** clawdbot org on ensue.network
- Email: poileclawdbot@icloud.com
- API Key: Stored in Keychain as "ensue-api-key"

**Obsidian → Ensue Push:**
Add frontmatter to any note:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ensue-api.sh (reported line 11)May include surrounding context.

sh
API_BASE="https://api.ensue-network.ai/v1"

if [[ -z "$API_KEY" ]]; then
  # Try to get from keychain
  API_KEY=$(security find-generic-password -a "clawdbot" -s "ensue-api-key" -w 2>/dev/null || true)
fi

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/ensue-api.sh (reported line 16)May include surrounding context.

sh
API_BASE="https://api.ensue-network.ai/v1"

if [[ -z "$API_KEY" ]]; then
  # Try to get from keychain
  API_KEY=$(security find-generic-password -a "clawdbot" -s "ensue-api-key" -w 2>/dev/null || true)
fi

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill is explicitly designed to track a shared contact's live location with street-level accuracy, capture screenshots, and infer context such as home/work, yet it provides no prominent warning about the sensitivity of that data or the risks of storing or exposing it. In this context, omission of privacy/safety guidance materially increases the chance of misuse, overcollection, or accidental disclosure of highly sensitive location information.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This is a true tool-parameter abuse issue because shell invocation is used as a generic transport layer for multiple external tools. The skill interacts with GUI automation, screenshots, and local binaries, so a compromised path or crafted value can escalate from input manipulation to arbitrary command execution and broader system/data compromise.

Content

Scanner excerpt · skills/findmy-location/findmy-location.py (reported line 16)May include surrounding context.

python
}

def run(cmd):
    return subprocess.run(cmd, shell=True, capture_output=True, text=True).stdout.strip()

def load_config():
    if os.path.exists(CONFIG_PATH):

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script captures a full screen image and returns its path without any notice, consent, or scoping to only the Find My window. Screenshots can contain unrelated secrets such as messages, tokens, emails, or other personal data, making this a substantial privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The error template asks for raw error messages, command inputs, and environment details, which commonly contain secrets such as access tokens, connection strings, file paths, hostnames, internal endpoints, and customer data. Without redaction guidance, users or agents are likely to copy sensitive material verbatim into persistent files, creating a straightforward disclosure path.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/whatisxlistening-to/k8s/kustomization.yaml (reported line 11)May include surrounding context.

yaml
- deployment.yaml
  - service.yaml
  - ingress.yaml
  # Note: secret.yaml excluded - create manually or via external-secrets

# Override these values in your overlay or via `kustomize edit set image`
images:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The next-steps section proposes proactive monitoring of calendar and email, which would involve ongoing access to sensitive personal data. For markdown files, behaviors that could affect user privacy should be accompanied by an explicit warning or disclosure about the scope of access and consent expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions recommend removing the app quarantine attribute with xattr -cr, which bypasses normal macOS Gatekeeper checks and suppresses a security control designed to warn about untrusted software. Documenting this without a warning encourages users to disable a platform protection and could normalize unsafe installation practices for software that will later receive powerful Accessibility permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration starts an HTTP server that accepts unauthenticated automation commands capable of clicking, typing, and pressing keys while Hammerspoon has Accessibility access. Even if intended for localhost use, exposing this without authentication or safety guidance is dangerous because any local malware, untrusted script, browser exploit, or user session process could drive the desktop and interact with security dialogs or sensitive apps.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented interface exposes arbitrary text entry and keypress injection through /type and /key, which goes beyond simple coordinate clicking and grants the caller the ability to drive sensitive UI flows, approve prompts, or enter commands into any focused application. Because the service is unauthenticated and paired with Accessibility privileges, any local process that can reach localhost can potentially abuse it for broader UI control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/hammerspoon-setup.md (reported line 132)May include surrounding context.

bash
# Click
curl -X POST localhost:9090/click -d '{"x":500,"y":400}'

# Double-click
curl -X POST localhost:9090/doubleclick -d '{"x":500,"y":400}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

With no manifest available, this skill has no declared purpose that would justify reading secrets from the environment and the system keychain. The code explicitly accesses ENSUE_API_KEY and falls back to security find-generic-password, which is a broader credential-access capability than a generic wrapper interface alone implies.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ensue-api.sh (reported line 8)May include surrounding context.

sh
set -euo pipefail

API_KEY="${ENSUE_API_KEY:-}"
API_BASE="https://api.ensue-network.ai/v1"

if [[ -z "$API_KEY" ]]; then
  # Try to get from keychain

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ensue-api.sh (reported line 25)May include surrounding context.

sh
case "$METHOD" in
  discover_memories)
    curl -sS -X POST "$API_BASE/memories/discover" \
      -H "Authorization: Bearer $API_KEY" \
      -H "Content-Type: application/json" \
      -d "$ARGS"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script exposes a delete operation that will execute immediately against the remote API with arbitrary JSON arguments and no confirmation, dry-run mode, or guardrails. In an agent-skill context, this increases the risk of accidental or prompt-induced destructive actions that permanently remove user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly configures unattended daily updates that modify both the Clawdbot installation and all installed skills, but it does not prominently warn that this will automatically perform system-wide writes and execute newly fetched code on a schedule. That creates a meaningful supply-chain and operational risk: users may enable recurring privileged changes without understanding that future remote updates can alter local behavior without per-update review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents and promotes commands such as clawdhub update --all --no-input --force without any warning that they can automatically modify all installed skills non-interactively. In an agent setting, this increases the chance of unattended supply-chain changes, accidental breakage, or pulling in malicious/unsafe updates from a registry or overridden registry source.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill is explicitly designed to track another person's real-time location, capture screenshots, and infer addresses/context from map data, yet the README provides no meaningful privacy warning, consent guidance, or limitation on misuse. Because the capability involves highly sensitive location data and street-level tracking, the missing safeguards materially increase the risk of stalking, surveillance, and other privacy abuse.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
71% confidence
Finding

The instructions create a persistent local helper script and a continuously running Hammerspoon HTTP server that accepts click commands, establishing a reusable control surface on the user's machine. Even though intended for convenience, this kind of persistent automation endpoint can be abused by other local malware or misconfigurations to drive UI actions without user awareness.

Content

Scanner excerpt · skills/findmy-location/README.md (reported line 59)May include surrounding context.

server:start()

text

Reload config (Hammerspoon menu → Reload Config), then create `~/.local/bin/hsclick`:
```bash
#!/bin/bash
curl -s -X POST localhost:9090/click -d "{\"x\":$2,\"y\":$3}"

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
docs/brain-sync-architecture.md:39