Back to skill

Security audit

Skill Publisher Claw Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent publishing toolkit, but its audit and publishing scripts can expose secrets or publish local work in ways users should review carefully before installing.

Install only if you are comfortable running local shell scripts that can edit files, initialize git, commit, and push to GitHub. Avoid using --force or --auto on repositories that may contain secrets, do not run external link validation on untrusted skills unless network-isolated, and patch the secret scans to redact values before using them in CI or logged environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
validate-links.sh:91
Finding

Server-Side Request Forgery Through External Link Validation

Content
View full analysis
\s"]+' ./*.md 2>/dev/null | sort -u) URL_COUNT=$(echo "$URLS" | grep -c "http" || echo 0) echo "Found $URL_COUNT unique external URLs" if $CHECK_EXTERNAL; then echo "Checking external URLs (this may take a moment)..." echo "" for url in $URLS; do # Clean URL (remove trailing punctuation) url=$(echo "$url" | sed 's/[.,;:!?]$//') # Skip obviously dynamic URLs if [[ "$url" == *"example.com"* ]] || [[ "$url" == *"localhost"* ]]; then echo -e "${YELLOW}⊘${NC} Skipped (example): $url" continue fi # Check URL with timeout HTTP_CODE=$(curl -o /dev/null -s -w "%{http_code}" --max-time 10 -L "$url" 2>/dev/null || echo "000") ``` ### Technical Analysis When external validation is enabled, the script extracts HTTP and HTTPS URLs directly from project Markdown and passes them to `curl`. The only destination filtering excludes strings containing `example.com` or `localhost`. The implementation does not reject: - IPv4 or IPv6 loopback addresses - Private network ranges - Link-local addresses - Cloud instance metadata services - Internal DNS names - Reserved or otherwise non-public address ranges - Public URLs that redirect to an internal destination The `-L` option follows redirects, but redirect destinations are not revalidated. Consequently, validating an untrusted project gives that project control over outbound requests made from the auditor's machine or CI runner. ### Attack Path 1. An attacker places a crafted HTTP or HTTPS link in a top-level Markdown file. 2. The link points directly to an internal service, cloud metadata endpoint, or attacker-controlled red ...[truncated 936 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
audit.sh:51
Finding

Local Audit Prints Detected Credentials Without Redaction

Content
View full analysis
/dev/null | grep -vE "example|sample|your[_-]|Contract\(|Address\(|\.view\(\)|\.emit\(\)" > /dev/null; then fail "POTENTIAL SECRETS FOUND - review carefully:" grep -rniE "(api[_-]?key|secret|password|token|bearer)\s*[=:]\s*['\"]?[a-zA-Z0-9]{8,}" . --include="*.md" --exclude-dir=templates 2>/dev/null | grep -vE "example|sample|your[_-]|Contract\(|Address\(|\.view\(\)|\.emit\(\)" | head -5 else pass "No obvious secret patterns" fi # Check for common API key prefixes if grep -rniE "(sk-[a-zA-Z0-9]{20,}|pk-[a-zA-Z0-9]{20,}|xai-[a-zA-Z0-9]{20,}|ghp_[a-zA-Z0-9]{20,}|gho_[a-zA-Z0-9]{20,})" . --include="*.md" --exclude-dir=templates 2>/dev/null; then fail "API KEY PATTERNS FOUND" else pass "No API key patterns (sk-, pk-, xai-, ghp_, gho_)" fi ``` ### Technical Analysis The scanner correctly searches for potential credentials, but after finding one it emits the complete matching source line. The API-key-prefix check likewise writes all matching lines directly to standard output. This defeats secret minimization: a credential previously confined to a project file can be copied into terminal capture, automated task output, log aggregation, or other audit records. The use of `head -5` limits the number of matches but does not redact their values. ### Attack Path 1. A Markdown file contains an accidentally committed API key, password, bearer token, or other credential matching the scanner. 2. A user or automation process runs `audit.sh`. 3. The first scan prints up to five complete matching lines. 4. The prefix scan may print addi ...[truncated 769 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
templates/github-actions/skill-audit.yml:27
Finding

GitHub Actions Audit Exposes Detected Secrets in CI Logs

Content
View full analysis
/dev/null | grep -v "example\|sample\|your[_-]"; then echo "⚠ Potential secrets found - please review" exit 1 fi if grep -rniE "(sk-[a-zA-Z0-9]{20,}|ghp_[a-zA-Z0-9]{20,}|gho_[a-zA-Z0-9]{20,})" . --include="*.md" 2>/dev/null; then echo "✗ API key patterns found" exit 1 fi echo "✓ No obvious secrets found" ``` ### Technical Analysis The GitHub Actions template runs `grep` directly in each `if` condition without redirecting or sanitizing its output. A successful match is therefore written to the workflow log before the step exits. Because this file is intended to be copied into other repositories, the flaw propagates into every project using the template. CI logs commonly have a wider audience and longer retention period than the original working tree. GitHub's masking mechanism cannot be assumed to recognize arbitrary credentials that have not been registered as repository secrets. ### Attack Path 1. A contributor adds or accidentally commits a credential-bearing line to a Markdown file. 2. A push or pull request triggers the generated `Skill Audit` workflow. 3. The `grep` command finds the credential and writes the complete line to the workflow log. 4. The job fails, but the emitted output remains available according to repository visibility and log-retention settings. 5. Anyone able to view the workflow logs may retrieve and use the credential. ### Impact Assessment The workflow does not directly execute the lea ...[truncated 464 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 372)May include surrounding context.

md
[ -f "SKILL.md" ] && echo "✓ SKILL.md exists" || echo "✗ SKILL.md MISSING"

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · docs/versioning.md (reported line 36)May include surrounding context.

git push origin v1.0.0

text

### 2. Update SKILL.md header (optional)
```markdown
# My Skill v1.2.0

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · publish.sh (reported line 80)May include surrounding context.

sh
echo ""
    
    if $FORCE; then
        COMMIT_MSG="Update skill content"
    else
        read -p "Commit message: " COMMIT_MSG
        [ -z "$COMMIT_MSG" ] && COMMIT_MSG="Update skill content"

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · publish.sh (reported line 83)May include surrounding context.

sh
echo ""
    
    if $FORCE; then
        COMMIT_MSG="Update skill content"
    else
        read -p "Commit message: " COMMIT_MSG
        [ -z "$COMMIT_MSG" ] && COMMIT_MSG="Update skill content"

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scaffold.sh (reported line 201)May include surrounding context.

sh
echo ""
echo "Next steps:"
echo "  1. cd $SKILL_DIR"
echo "  2. Edit SKILL.md with your content"
echo "  3. Edit README.md with description"
echo "  4. Run: $SCRIPT_DIR/audit.sh ."
echo "  5. Commit and push!"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README advertises publish.sh as a one-command workflow that performs audit, commit, and push, but it does not warn users that this will create commits and transmit repository contents to a remote. In a skill-publishing context, that can lead to accidental publication of sensitive or unfinished material if users run the command without understanding its side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script documents --auto as non-interactive and then performs multiple in-place file edits and file creation operations throughout the script. Although interactive mode asks for confirmation, the user is not explicitly warned at the point of use that --auto will modify repository files without per-change confirmation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level comments describe the script as a command to audit, fix, commit, and push a skill, but the implementation also initializes a git repository and can create a new GitHub repository via gh repo create. That is a meaningful intent-level expansion beyond merely pushing existing content, so the documentation is actively misleading about the script's effects.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The --force flag suppresses confirmation prompts for actions that can materially change state, including bypassing audit failure, committing all local changes, and pushing to a remote repository. In an agent or automation context, this increases the risk of unintended publication of sensitive or unreviewed content because destructive or high-impact actions proceed without an interactive check.

Content

Scanner excerpt · publish.sh (reported line 7)May include surrounding context.

sh
# One command to audit, fix, commit, and push a skill
#
# Usage: ./publish.sh [skill-directory] [--force]
#   --force: Skip confirmation prompts
#

set -e

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template tells authors to load the skill when generic '[Trigger condition]' items apply, but it does not require concrete, bounded trigger phrases or exclusion conditions. As written, it encourages vague invocation guidance that could lead to overly broad or unintended skill activation in derived skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description lists triggers such as "audit skill" and "skill checklist," which could match a wide range of generic conversations about skills rather than a narrowly defined publishing workflow. While some examples are specific, the file does not provide exclusion conditions or clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The section is documented as a remote check, yet when no origin exists it prompts for authentication, creates a GitHub repository, and pushes the local source with gh repo create ... --push. This is more than a passive check and contradicts the stated purpose of the step.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

md
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scaffold.sh (reported line 157)May include surrounding context.

sh
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Static analysis

No suspicious patterns detected.