T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Mandatory External Research May Disclose Sensitive Decision Context
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent decision-analysis skill, but it gives broad tool permissions and encourages external research for sensitive life decisions without clear user consent or privacy minimization.
Install only if you are comfortable with a skill that may be invoked by broad decision-making language and may research current facts online. Avoid including private names, account details, exact holdings, medical details, or sensitive relationship/employment context unless the agent confirms what will be searched. Prefer the ClawHub-reviewed install path over unpinned npx, and consider removing Write/general Bash or limiting Bash to the bundled calculator.
SKILL.md:10Mandatory External Research May Disclose Sensitive Decision Context
SKILL.md:10Skill Grants Filesystem and Command-Execution Permissions Beyond Its Minimum Needs
README.md:6Unpinned npx Installation Command Creates a Mutable Supply-Chain Execution Path
The code’s actual purpose is much narrower than the declared description. It provides EV and Kelly calculations plus a basic recommendation based on numeric parameters, which partially aligns with the investment/risk portion of the description. However, major declared features are absent: Bayesian updating is not implemented anywhere; there is no quick judgment questionnaire, no deep 8-step workflow, and no 5-resource audit. The description suggests a generalized life-decision assistant across domains like relationships and careers, but the code only accepts explicit numerical betting/investment-style inputs and produces formula-based outputs. This is a material description-behavior mismatch.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The trigger phrases and usage examples are extremely broad everyday language such as 'should I', 'worth it', 'risk', and 'how to choose', which can cause unintended invocation during normal conversation. In agent environments, overbroad activation can unexpectedly route sensitive personal, financial, or relationship queries into this skill, increasing the chance of inappropriate advice, privacy exposure, or workflow hijacking.
The trigger phrases are extremely broad terms like 'risk,' 'invest,' and 'should I,' which commonly appear in ordinary conversation. This can cause unintended activation of a skill with WebSearch, WebFetch, Bash, Read, and Write permissions, increasing the chance that the agent performs unnecessary tool use or shifts behavior in contexts where the user did not intend to invoke this capability.
The usage examples reinforce broad natural-language activation without defining boundaries, exclusions, or explicit confirmation requirements. In the context of a skill authorized to research and run Bash commands, ambiguous activation materially raises the risk of unintended execution flow, unnecessary external requests, or analysis being applied to sensitive personal topics without clear user consent.
The trigger list includes very broad, common phrases such as "should I," "risk," and "invest," which are likely to match ordinary conversation far outside the intended scope. This can cause the skill to activate unexpectedly and influence sensitive life, financial, relationship, or career decisions when the user did not explicitly request this framework, increasing the chance of overreach or unsafe advice insertion.
The phrase "English translation and adaptation" describes the skill as English-specific, but this file does not indicate that users can choose another language or that the English-only scope is required for a documented regional or compliance reason. Under the policy rule, fixed language constraints without opt-in or justification should be flagged.
No suspicious patterns detected.