Back to skill

Security audit

Advisory Council

Security checks for vulnerabilities and agentic risk

Overview

This skill is for market-analysis help, but it requires running an unreviewed local Python script outside the skill package.

Install only if you control and trust ~/clawd/advisory_council.py, understand it may make live network and model calls, and are comfortable with it running under the agent's local permissions. Prefer a version that bundles the script in the reviewed package, pins its integrity, and asks before execution.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:19
Finding

Mandatory Execution of an Unverified External Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3 and 19-31; reinforced at lines 48-49
Vulnerability Type: Execution of a replaceable local tool outside the reviewed skill package
Risk Level: High

Vulnerable Code

markdown
## CRITICAL RULE — NO FABRICATION
**You MUST actually execute the Python command using your shell/exec tool.** Read the real output. NEVER generate fake advisor analyses, fake synthesis, or simulated council responses. If the script fails, report the actual error to Boss Man.
markdown
## Run Full Advisory Council (All Assets)
Fetches live prices for BTC, ETH, XRP, SUI and runs all 5 advisors + synthesis.
```bash
cd ~/clawd && python3 advisory_council.py

Run Focused on a Specific Coin

Runs the full council but focuses analysis on one asset.

bash
cd ~/clawd && python3 advisory_council.py SUI
bash
cd ~/clawd && python3 advisory_council.py BTC
text

```markdown
## Rules
- **EXECUTE THE PYTHON COMMAND FOR REAL** — use your shell/exec tool. Never simulate council output.

Technical Analysis

The skill unconditionally directs the agent to execute advisory_council.py from ~/clawd, which is outside the reviewed project. The audited project contains only SKILL.md; it does not contain the referenced Python script, a cryptographic digest, an ownership requirement, a trusted installation process, or any other mechanism for validating the executable before use.

The command first changes into a user-writable directory and then resolves the script by its relative filename. Therefore, the effective behavior of the skill depends entirely on whatever file is present at ~/clawd/advisory_council.py when the command is executed. A process or user capable of creating or replacing that file can cause a legitimate-looking council request to execute attacker-controlled Python code.

The documented claims that the script only retrieves live prices, invokes five advisors, and formats a report ca ...[truncated 1707 chars]

Remediation
View remediation

Remediation Suggestions

  1. Package advisory_council.py inside the reviewed skill artifact so its implementation can be audited together with SKILL.md.
  2. Invoke the script through a fixed, package-relative path rather than changing into ~/clawd and resolving a user-controlled relative filename.
  3. Before execution, resolve the canonical path and reject symbolic links or paths that escape the expected package directory.
  4. Restrict ownership and write permissions so untrusted users and unrelated processes cannot replace the script.
  5. If an external deployment is unavoidable, verify a pinned cryptographic hash or authenticated signature immediately before each execution. Fail closed if validation fails.
  6. Run the script with least privilege in a sandbox that limits filesystem access, environment variables, subprocess execution, and outbound network destinations.
  7. Provide only the API credentials required for the documented functionality; do not expose unrelated secrets to the process.
  8. Remove the unconditional execution requirement. The agent should refuse execution when the script is missing, unverifiable, unexpectedly writable, or fails integrity checks.
  9. Document the script's expected network endpoints and dependencies, and include its dependency lockfile in the review scope.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill repeatedly instructs the agent to execute a Python script for real and states that it fetches live prices and uses external AI advisors, but it does not provide a clear safety warning or consent gate before incurring external network activity and usage charges. This can lead to silent cost-bearing actions and unintended disclosure of prompts or data to third-party services whenever the skill is triggered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill defines broad natural-language triggers such as general requests for market analysis or buy/sell advice, which can cause the agent to invoke this skill in situations where the user did not explicitly authorize running an external script. Because the script performs real execution and likely external API/model calls, overbroad triggering increases the risk of unintended actions, cost incurrence, and exposure to live, unreviewed outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.