Back to skill

Security audit

Agent Squad 0.9.4

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent autonomous coding-squad tool, but it starts persistent agents with broad approval-bypass authority and some under-disclosed side effects.

Review before installing. Use this only on isolated repositories or worktrees, keep .env files, keys, credentials, and sensitive data out of squad project directories, and consider disabling the watchdog for sensitive work. Expect the skill to run agents unattended, bypass some engine approval prompts, write task/report/log files, initialize git in new project directories, and show raw terminal/report content when checking status or peeking.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script deliberately enables high-risk engine flags such as '--dangerously-skip-permissions' and '--dangerously-bypass-approvals-and-sandbox', which remove user-approval and sandbox controls before launching autonomous coding agents. In the context of a persistent squad manager that can run unattended in tmux and operate on project directories, this materially increases the chance of destructive filesystem changes, secret exposure, or arbitrary command execution without meaningful human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script launches engines in unsafe approval-bypass modes without any explicit warning, consent flow, or runtime confirmation. Because the skill is designed to manage persistent autonomous agents and even register a watchdog for continued operation, the lack of user acknowledgment makes unsafe execution materially more dangerous and easier to trigger accidentally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to run npx clawhub@latest install agent-squad, which pulls and executes the latest published package version at install time rather than a pinned, reviewed version. If the upstream package is compromised or a malicious update is published, users could execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The skill explicitly advertises running AI engines in full-auto mode with permission bypass flags and states they can read, write, and execute anything in the project directory without asking. In the context of a persistent 24/7 coding squad with task queues and auto-restart, this materially increases the chance of destructive actions, secret exposure, or unsafe command execution from prompt injection, bad tasks, or model error.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
## Security

Squads run in **full-auto mode** — the AI can read, write, and execute anything in the project directory without asking. Only run squads on projects you trust. Keep credentials and `.env` files out of squad project directories.

## Documentation

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill orchestrates background coding agents that can write code and manipulate project files, yet it declares no explicit tool scope or permission boundary. In a multi-tool agent environment, this increases the risk of overbroad file modification and weakens user awareness and enforcement around what the skill is allowed to do.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to show raw live tmux screen output directly to the user without any warning or sanitization. Terminal screens commonly contain secrets, filesystem paths, tokens, command history, internal prompts, or proprietary code fragments, so direct exposure can leak sensitive information unintentionally.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly tells the agent to expose raw live terminal output and report contents in plain language. Because the squads are autonomous coding agents with full project access, these outputs can include sensitive source code, credentials, internal URLs, stack traces, or user data from the workspace, making disclosure risk substantial in context.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
User: "peek at my-squad" / "what's on my-squad's screen?" / "show me what my-squad is doing"

Show the raw tmux screen content. This is a quick way to see the agent's live terminal without checking reports.

Response: Show the screen output directly, formatted in a code block.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Directing the agent to read the latest squad report and surface its real-time contents can disclose sensitive workspace information beyond what the user intended to reveal. Reports generated by autonomous coding agents may contain copied code, debugging output, issue details, or embedded secrets, so relaying them verbatim creates a clear data exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The protocol explicitly instructs the agent to write coordination summaries into project files and logs during shutdown, but there is no user-facing warning, consent gate, or scope limitation for these persistent writes. In a coding-agent skill, silent background modification of repository contents can surprise users, pollute working trees, leak task context into tracked files, and create unintended commits or artifacts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The documented design creates persistent tmux sessions with a watchdog that automatically restarts unattended AI coding agents. This increases the blast radius of any bad prompt, model mistake, or malicious task because execution can continue indefinitely and recover from crashes without human review, especially since the guide also states the engines run in full-auto mode.

Content

Scanner excerpt · docs/guide.md (reported line 8)May include surrounding context.

text
You (via OpenClaw)          agent-squad              AI Agent (in tmux)
       │                         │                         │
       ├─ "start a squad" ──────►├─ create tmux session ──►├─ AI starts coding
       │                         ├─ register watchdog       │
       │                         │                         │
       ├─ "assign task" ────────►├─ write task file ───────►├─ picks up task

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest focuses on creating and operating AI squads, assigning tasks, and monitoring progress. This block modifies the user's project by creating a git repository and making an initial commit, which is a separate project-management action rather than a necessary implementation detail of tmux-based squad startup. That side effect is not disclosed in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script captures and prints the last lines of a live tmux pane, which can expose sensitive transient data such as prompts, credentials, file contents, or private agent output to whoever runs the status command or any logging wrapper around it. In this skill’s context, the pane likely contains live coding-agent activity, making accidental disclosure more likely because status checks are routine and may be performed by users who did not intend to inspect raw session content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically sends keystrokes into a live tmux session during a status check, causing side effects from what appears to be a read-only operation. This can alter agent behavior, interfere with interactive programs, or trigger unintended actions if the pane is running a shell/editor rather than safely awaiting natural-language input; in an autonomous multi-agent skill, that makes the behavior more dangerous because these sessions may execute commands based on injected text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The instruction says to default to claude when the user does not specify an engine, rather than first offering a choice. This imposes a specific provider/engine preference in natural-language behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.