Back to skill

Security audit

musk-eeg

Security checks for vulnerabilities and agentic risk

Overview

The skill is not overtly malicious, but it should be reviewed because it depends on an unverified external neuroscience database that is auto-extracted and applies a broad, forceful persona to medical-adjacent topics.

Install only if you are comfortable manually adding an external database that was not included in this review. Treat answers as educational summaries, not medical or mental-health advice, and be aware that the fixed persona can make uncertain neuroscience claims sound more confident than they are.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:27
Finding

Unpinned and Unverified External Knowledge Database

Content
View full analysis
The database is at `data/knowledge_new_fixed.db.zip` (29 MB) and is > automatically extracted during the first query. > - **ClawHub installation**: The database is not included in the published > package. Download it from GitHub Releases and place it in `data/`. ``` ### Technical Analysis The installation instructions require users to retrieve `knowledge_new_fixed.db.zip` separately from the author's GitHub Releases page. They do not identify an immutable release version, expected SHA-256 digest, digital signature, or trusted key. The database is a functional third-party component of the Skill. Its `core_definition`, `mechanism`, and `musk_insight` fields are returned to the Agent and used to construct responses. Consequently, the separately downloaded database affects the Skill's effective behavior even though it is not executable code. If the repository, release account, asset, or delivery path is compromised, an attacker could substitute a modified archive. The Skill would accept and process it without verifying provenance or integrity. Malicious database records could supply misinformation or text designed to manipulate the Agent. The absence of the database from the audited package also means its actual contents were outside this audit's coverage. This behavior is required only because the database exceeds the package size limit. Downloading a data component is compatible with the declared functionality, but accepting an unversioned ...[truncated 1342 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/musk_eeg_search.py:78
Finding

Unrestricted Extraction of an Externally Supplied ZIP Archive

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- agents 自动识别文件夹中的 `SKILL.md` 并加载技能

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states the skill speaks EEG/neuroscience content in Chinese and in a specific 'Musk' voice, which imposes a language/locale choice by default. The policy allows locale constraints only when users are offered a choice or the restriction is clearly justified as region-specific, neither of which is documented here.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 45)May include surrounding context.

md
### Claude Code / Hermes Agent
**整文件夹安装**,不是单个文件:
1. 将 `Musk-EEG` 文件夹拷贝到 agents 的 skills 目录
2. 文件夹结构:`skills/musk-eeg/SKILL.md`、`skills/musk-eeg/scripts/`、`skills/musk-eeg/data/`
3. agents 会自动扫描文件夹并加载 `SKILL.md` 触发技能

---

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
### Claude Code / Hermes Agent
**整文件夹安装**,不是单个文件:
1. 将 `Musk-EEG` 文件夹拷贝到 agents 的 skills 目录
2. 文件夹结构:`skills/musk-eeg/SKILL.md`、`skills/musk-eeg/scripts/`、`skills/musk-eeg/data/`
3. agents 会自动扫描文件夹并加载 `SKILL.md` 触发技能

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This line says that when the skill is triggered, the agent will output in Musk's 'real voice,' indicating a fixed presentation mode applied automatically. Because no opt-in or alternative language/locale behavior is described, this conflicts with the requirement not to force a specific language or locale without user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger scope spans broad neuroscience, cognition, sleep, mental health, consciousness, and brain-disorder topics, making accidental invocation likely for sensitive or general-purpose queries. Over-broad routing can force users into a persona-driven, RAG-limited workflow for medical or psychological topics where nuance, safety disclaimers, and specialist handling are important.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating replies in Elon Musk's voice without user consent introduces impersonation and trust-shaping risk, especially for medical and neuroscience content. The persona's forceful tone may amplify speculative or oversimplified claims, causing users to over-trust advice because of style rather than evidence.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly constrains itself to only translate and cite Wikipedia/RAG-backed material, but nearby guidance and examples encourage extrapolations, prescriptions, and strong assertions that may not exist in the cited corpus. In a medical/neuroscience context, this can mislead users into trusting unsupported claims as sourced facts, increasing hallucination and unsafe advice risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is presented as a local SQLite retriever, but it also writes to disk by automatically extracting a ZIP archive into the data directory. That broadens behavior from read-only retrieval to filesystem mutation, which can surprise callers and creates risk if the ZIP contents are tampered with, malformed, or unexpectedly large.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
67% confidence
Finding

The instruction asks the model to answer in 'Musk's tone' and first person, which is a role-play framing rather than a neutral formatting request. While not overtly malicious, persona adoption is a known semantic mechanism for redirecting model behavior and can weaken adherence to default safety or truthfulness constraints, especially when combined with retrieved content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill promises that every claim is sourced from a local SQLite RAG database, yet examples reference topics whose presence in the documented corpus is unclear. This creates a provenance-integrity gap: users may be told content is source-backed when it may actually be fabricated or drawn from unstated sources.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill description implies retrieval from a local skill database, but the code silently falls back to a shared database outside the skill's own data directory. This weakens data provenance and trust boundaries, because responses may be sourced from externally managed content not obviously covered by the skill's packaging or review assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The formatted output instructs the downstream assistant to answer "用马斯克的语气、第一人称" unconditionally. This imposes a specific communication style on the user-facing response without offering a choice or opt-in, which fits the natural-language policy concern around forced language/locale-style constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.