Back to skill

Security audit

Zen Founder Fundraising Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Zen.GP API helper, but users should know their pitch deck content is sent to an external service.

Install only if you are comfortable sending pitch deck text, startup profile details, and search criteria to Zen.GP using your API key. Consider redacting confidential financials, customer names, or unreleased product details unless you trust the service's privacy and retention practices.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
91% confidence
Finding

The unusually large amount of padding around the Quick Start section is consistent with context-window stuffing or visibility reduction techniques that can hide content from reviewers or automated tooling. While no overt malicious instruction is embedded here, the obfuscating formatting increases review difficulty and can be used to conceal risky behavior in skill metadata or instructions.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Connect startups with the right VCs. Analyze pitch decks and get 5 recommended investors from Zen.GP's curated database of venture capital firms.

Quick Start

  1. Install the skill
bash
clawhub install zen-founder-agent

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
94% confidence
Finding

A run of 286 spaces is unnecessary for normal documentation and functions as whitespace padding that reduces readability and may conceal adjacent content or defeat naive scanners. In a security review context, such obfuscation is suspicious even if the visible content appears ordinary.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

Connect startups with the right VCs. Analyze pitch decks and get 5 recommended investors from Zen.GP's curated database of venture capital firms.

Quick Start

  1. Install the skill
bash
clawhub install zen-founder-agent

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
93% confidence
Finding

The long whitespace padding on this line is not needed for functionality and contributes to documentation obfuscation. Although the line itself contains setup guidance, this formatting pattern can hinder review and hide risky edits in surrounding text.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

bash
clawhub install zen-founder-agent  
  1. Get your API Key at: https://zen.gp/settings/#api-keys
  2. Add it to OpenClaw:
bash
  openclaw config set skills.entries.zen-founder-agent.env.ZEN_FOUNDER_AGENT_API_KEY "YOUR_API_KEY_HERE"

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
93% confidence
Finding

The excessive spacing on this line is another instance of suspicious padding that serves no legitimate operational purpose. Repeated occurrences increase the likelihood that the formatting is careless at best and obfuscatory at worst.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

clawhub install zen-founder-agent

text
 2. Get your API Key at: https://zen.gp/settings/#api-keys                                                                                        
 3. Add it to OpenClaw:                                                                                                             
   ```bash                                                                                                                                          
     openclaw config set skills.entries.zen-founder-agent.env.ZEN_FOUNDER_AGENT_API_KEY "YOUR_API_KEY_HERE"                                         

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
93% confidence
Finding

This line contains over 100 spaces of padding, continuing the same obfuscating pattern found elsewhere in the file. Such formatting makes manual auditing harder and can be abused to bury important security-relevant text.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

bash
     openclaw config set skills.entries.zen-founder-agent.env.ZEN_FOUNDER_AGENT_API_KEY "YOUR_API_KEY_HERE"                                         
  1. Restart:
bash
  openclaw gateway restart   

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to submit full pitch deck content and startup profile data to a third-party API, but it does not clearly warn that sensitive business information will leave the local environment. This can cause unintentional disclosure of confidential fundraising, product, customer, or financial data to an external service without informed user consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This skill is designed to send user-supplied pitch deck content to https://zen.gp for remote analysis and investor matching, which is a clear external data transmission path. In context, that behavior is expected, but it is still security-relevant because startup pitch decks often contain highly sensitive nonpublic business information and contact data.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

Combined operation - analyze pitch and get investor matches in one call.

bash
curl -X POST https://zen.gp/api/v1/founder/analyze-and-match \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $ZEN_FOUNDER_AGENT_API_KEY" \
  -d '{