Back to skill

Security audit

Oraclaw Bandit

Security checks for vulnerabilities and agentic risk

Overview

This is an instruction-only A/B optimization skill whose external API use is expected for its purpose, with no hidden code or destructive behavior found.

Before installing, verify the separate OraClaw MCP server you configure, use an API key with appropriate limits, monitor paid usage, and avoid sending sensitive personal, regulated, or proprietary context unless you have confirmed OraClaw's data handling and compliance terms.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill requires an API key and directs the user to connect to an external MCP server, which strongly implies that supplied arms, rewards, and contextual/history data may be transmitted to a third-party service. The documentation does not clearly disclose this data flow, retention, or privacy implications, creating a meaningful risk of unintended external sharing of potentially sensitive experimentation or user-behavior data.

Static analysis

No suspicious patterns detected.