Back to skill

Security audit

clawlite-office-hours

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent pre-coding consultation workflow, with limited and purpose-aligned repository inspection and a design-document write that users should be aware of.

Before installing, expect the skill to inspect relevant repository context and create a design document in the project directory. Ask the agent to confirm the filename or show the design in chat first if you do not want new files added automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a pre-coding consultation tool, but it instructs the agent to write a design document into the project directory. That creates an unexpected side effect on the repository and can modify user files without explicit consent, which is risky for a supposedly advisory skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs the agent to write a design document into the project directory without warning the user that repository files will be modified. Silent workspace writes can overwrite intended workflows, create unwanted artifacts, or be abused to persist misleading content in the repo.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest presents the skill primarily as a consultant for clarifying problems, users, risks, and metrics before implementation. The documented procedure additionally mandates reading local project docs, checking git history, and mapping codebase regions, which introduces repo-auditing behavior beyond the plain-language expectation of an Office Hours-style consultation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.