Back to skill

Security audit

intelligence-analyst-claw

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed market-research skill that guides web research and local analysis, with scoping and language-preference cautions but no hidden or destructive behavior found.

Install if you want an agent to run structured industry or company research using public web sources. Before using it, tell the agent the target market, preferred language, permitted sources, and whether logged-in databases or private documents are allowed; do not grant access to internal or account-scoped materials unless you have permission.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and map to common, everyday research requests, which increases the chance that the skill is invoked when the user did not intend to use it. Unintended invocation can route users into a workflow with external browsing, scripted data collection, and analysis behaviors they did not explicitly request, creating overreach and prompt-scope confusion.

Natural-Language Policy Violations

Medium
Confidence
78% confidence
Finding
The description and workflow prescribe Chinese-first search behavior without checking the user's preferred language or explaining why that default is appropriate. This can bias source selection, reduce coverage for non-Chinese contexts, and produce skewed or lower-quality analysis, especially for global markets or users expecting neutral language handling.

Static analysis

No suspicious patterns detected.