Back to skill

Security audit

web-skills-protocol

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent web-discovery purpose, but it tells agents to fetch and follow arbitrary website-provided skill instructions with too few mandatory safety gates.

Review this skill carefully before installing. It is not showing malicious code, but it teaches the agent to trust instructions published by whatever website you are interacting with. Use it only with agents that enforce origin checks, treat fetched Markdown as untrusted, require confirmation for purchases, deployments, deletions, account changes, or credential use, and install only from a pinned, reviewed copy rather than the README curl-to-main commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:64
Finding

Untrusted Remote Skill Instructions Are Followed Without Mandatory Isolation or Validation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:64
Finding

Installation Commands Trust Mutable and Unverified Remote Skill Content

Content
View full analysis
> AGENTS.md ``` ``` Equivalent commands also appear in `README_ZH.md`, lines 73-101. ### Technical Analysis The documented installation process downloads instruction content from the mutable `main` branch and writes it directly into persistent agent configuration. It does not pin a reviewed commit or release and does not verify a checksum or digital signature. The Codex installation command is particularly sensitive because it appends downloaded content directly to `AGENTS.md`, which can affect subsequent agent sessions for that project. The other commands write the content into persistent skill directories that may also be loaded automatically later. The use of `curl -sL` introduces additional weaknesses: - `-L` follows redirects without validating the final destination against an ...[truncated 1740 chars]
Remediation
View remediation
/skill/SKILL.md" \ --output /tmp/web-skills-protocol.SKILL.md ``` 4. Verify the downloaded file before moving it into the persistent skill directory. 5. Do not append network content directly to `AGENTS.md`. Download it to a temporary file, review it, and then copy a pinned version into place. 6. Validate the final redirect destination and refuse unexpected origins. 7. Use atomic replacement rather than direct writes so interrupted downloads cannot corrupt an existing configuration. 8. Document safe upgrade and rollback procedures, including checksum verification for every update. 9. Update both `README.md` and `README_ZH.md` so all installation variants apply the same integrity controls. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (61)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README.md (reported line 127)May include surrounding context.

Other endpoints require an API key — get one at https://bobs-store.com/developers.

Skills

  • Product Search: Search products by keyword, category, or price range
  • Place Order: Add items to cart and complete checkout via API
text

### 2. Create a Skill

`/skills/search/SKILL.md` (or `/agents/search/SKILL.md`):

```markdown
---
name: search
description: >
  Search and browse products in Bob's Online Store catalog.
  Use when the user wants to find products by keyword, category, price, or brand.
version: 1.0.0
auth: none
base_url: https://api.bobs-store.com/v1
---

# Product Search

## Endpoint

GET /products

## Parameters

| Parameter  | Type   | Required | Description                     |
|------------|--------|----------|---------------------------------|
| q          | string | yes      | Search query                    |
| category   | string | no       | Filter by category              |
| min_price  | number | no       |

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · README_ZH.md (reported line 129)May include surrounding context.

Other endpoints require an API key — get one at https://bobs-store.com/developers.

Skills

  • Product Search: Search products by keyword, category, or price range
  • Place Order: Add items to cart and complete checkout via API
text

### 2. Create a Skill

`/skills/search/SKILL.md` (or `/agents/search/SKILL.md`):

```markdown
---
name: search
description: >
  Search and browse products in Bob's Online Store catalog.
  Use when the user wants to find products by keyword, category, price, or brand.
version: 1.0.0
auth: none
base_url: https://api.bobs-store.com/v1
---

# Product Search

## Endpoint

GET /products

## Parameters

| Parameter  | Type   | Required | Description                     |
|------------|--------|----------|---------------------------------|
| q          | string | yes      | Search query                    |
| category   | string | no       | Filter by category              |
| min_price  | number | no       |

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 155)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 157)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 160)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 176)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README_ZH.md (reported line 157)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README_ZH.md (reported line 159)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README_ZH.md (reported line 162)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README_ZH.md (reported line 177)May include surrounding context.

md
## Example

Request:
​```
GET /products?q=wireless+headphones&sort=rating&max_price=100
​```

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SPEC.md (reported line 612)May include surrounding context.

md
## Prerequisites

- OAuth 2.0 access token (see https://devtools.cloud/docs/oauth)
- A Git repository URL (GitHub, GitLab, or Bitbucket)

## Workflow

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to fetch remote skill content with curl and write it directly into an agent's trusted skill directory or append it to AGENTS.md, without pinning a version, verifying integrity, or warning that the downloaded instructions will influence later agent behavior. If the upstream repository is compromised or the file changes maliciously, users may silently install prompt-injection content that persists across future sessions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The install command writes the downloaded skill into a persistent per-user skill directory, causing the instructions to influence future agent runs beyond the immediate session. Persistent prompt/instruction installation increases the blast radius of any malicious or later-compromised upstream content because it survives until manually removed or updated.

Content

Scanner excerpt · README.md (reported line 71)May include surrounding context.

OpenClaw

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 81)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 89)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 75)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 83)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 91)May include surrounding context.

bash
mkdir -p ~/.openclaw/workspace/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.openclaw/workspace/skills/web-skills-protocol/SKILL.md

OpenCode

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

OpenCode

bash
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.claude/skills/web-skills-protocol/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 87)May include surrounding context.

OpenCode

bash
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.claude/skills/web-skills-protocol/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 81)May include surrounding context.

OpenCode

bash
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.claude/skills/web-skills-protocol/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README_ZH.md (reported line 89)May include surrounding context.

OpenCode

bash
mkdir -p ~/.claude/skills/web-skills-protocol && curl -sL \
  https://raw.githubusercontent.com/0xtresser/Web-Skills-Protocol/main/skill/SKILL.md \
  -o ~/.claude/skills/web-skills-protocol/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 116)May include surrounding context.

Skills

  • Product Search: Search products by keyword, category, or price range
  • Place Order: Add items to cart and complete checkout via API
text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 122)May include surrounding context.

Skills

  • Product Search: Search products by keyword, category, or price range
  • Place Order: Add items to cart and complete checkout via API
text

Static analysis

No suspicious patterns detected.