Back to skill

Security audit

Decision Algorithm

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent decision-analysis skill, but it gives broad tool permissions and encourages external research for sensitive life decisions without clear user consent or privacy minimization.

Install only if you are comfortable with a skill that may be invoked by broad decision-making language and may research current facts online. Avoid including private names, account details, exact holdings, medical details, or sensitive relationship/employment context unless the agent confirms what will be searched. Prefer the ClawHub-reviewed install path over unpinned npx, and consider removing Write/general Bash or limiting Bash to the bundled calculator.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:10
Finding

Mandatory External Research May Disclose Sensitive Decision Context

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:10
Finding

Skill Grants Filesystem and Command-Execution Permissions Beyond Its Minimum Needs

Content
View full analysis
-g -l # Kelly Criterion — How much to bet? python3 tools/decision_calculator.py --kelly -p -o # Full analysis — All metrics at once python3 tools/decision_calculator.py --full -p -g -l --capital ``` ``` ### Technical Analysis The documented workflow does not require writing files. Nevertheless, the Skill authorizes the general-purpose `Write` tool. The only documented reason for command execution is launching the bundled `tools/decision_calculator.py` script with numeric arguments. General `Bash` access is substantially broader than that requirement and can potentially execute arbitrary commands available under the host agent's identity. The reviewed calculator itself is not malicious: it imports only `argparse` and `sys`, parses numeric arguments, performs arithmetic, and prints results. It does not access the network, invoke subprocesses, modify files, establish persistence, or read credentials. The vulnerability is therefore the breadth of the Skill's authorization rather than malicious behavior in the calculator. Broad permissions become particularly relevant because the Skill also consumes user-controlled prompts and externally retrieved web content. If the runtime fails to maintain a strong instruction/data boundary, malicious content could attempt to induce unrelated writes or shell commands. ### ...[truncated 1376 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:6
Finding

Unpinned npx Installation Command Creates a Mutable Supply-Chain Execution Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code’s actual purpose is much narrower than the declared description. It provides EV and Kelly calculations plus a basic recommendation based on numeric parameters, which partially aligns with the investment/risk portion of the description. However, major declared features are absent: Bayesian updating is not implemented anywhere; there is no quick judgment questionnaire, no deep 8-step workflow, and no 5-resource audit. The description suggests a generalized life-decision assistant across domains like relationships and careers, but the code only accepts explicit numerical betting/investment-style inputs and produces formula-based outputs. This is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases and usage examples are extremely broad everyday language such as 'should I', 'worth it', 'risk', and 'how to choose', which can cause unintended invocation during normal conversation. In agent environments, overbroad activation can unexpectedly route sensitive personal, financial, or relationship queries into this skill, increasing the chance of inappropriate advice, privacy exposure, or workflow hijacking.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely broad terms like 'risk,' 'invest,' and 'should I,' which commonly appear in ordinary conversation. This can cause unintended activation of a skill with WebSearch, WebFetch, Bash, Read, and Write permissions, increasing the chance that the agent performs unnecessary tool use or shifts behavior in contexts where the user did not intend to invoke this capability.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage examples reinforce broad natural-language activation without defining boundaries, exclusions, or explicit confirmation requirements. In the context of a skill authorized to research and run Bash commands, ambiguous activation materially raises the risk of unintended execution flow, unnecessary external requests, or analysis being applied to sensitive personal topics without clear user consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very broad, common phrases such as "should I," "risk," and "invest," which are likely to match ordinary conversation far outside the intended scope. This can cause the skill to activate unexpectedly and influence sensitive life, financial, relationship, or career decisions when the user did not explicitly request this framework, increasing the chance of overreach or unsafe advice insertion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The phrase "English translation and adaptation" describes the skill as English-specific, but this file does not indicate that users can choose another language or that the English-only scope is required for a documented regional or compliance reason. Under the policy rule, fixed language constraints without opt-in or justification should be flagged.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.