Back to skill

Security audit

Workflow Cache

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent workflow-caching purpose, but it automatically sends session-derived data to a cloud service and can replay cloud-supplied browser workflows without clear user approval or strong trust controls.

Review this skill carefully before installing. It is not just a local token-saving helper: by default it can query a remote workflow service on user intents, replay returned workflows in your browser session, and upload successful workflow patterns derived from session history. Use only in low-sensitivity environments unless cloud lookups and auto-contribution are disabled or governed by strong approval, endpoint, and workflow-verification controls.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:46
Finding

Untrusted Cloud Workflows Are Designed for Direct Privileged Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:46-58; skill.json:10-20
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Relevant Code Snippets:

SKILL.md:46-58

markdown
## How It Works

User Intent → Query Cloud → Match Found? ↓ Yes ↓ No Execute Now Normal Flow (1 second) (LLM reasons) ↓ ↓ Success! Success → Contribute

text

**One agent's success becomes every agent's shortcut.**

skill.json:10-20

json
"permissions": [
  "browser",
  "lobster",
  "sessions_history",
  "network"
],
"hooks": {
  "on_intent_received": "interceptIntent",
  "on_session_complete": "onSessionComplete"
},

Technical Analysis

The skill declares an intent hook that queries a cloud registry and directly replays a matched workflow before normal agent reasoning. The requested network, browser, and lobster permissions provide the capabilities needed to retrieve externally controlled workflow definitions and execute their actions.

This creates a remote payload execution channel: the effective workflow is not fixed when the package is reviewed and may change whenever the cloud registry changes. The supplied files do not specify signature verification, immutable content hashes, trusted publisher validation, workflow origin binding, an action allowlist, sandboxing, or mandatory user approval before replay.

The declared entry point, dist/index.js, is absent from the reviewed artifact. Therefore, the concrete runtime implementation and any undocumented validation cannot be verified, and the package cannot perform the advertised behavior as shipped. The vulnerability is established in the declared design and permission model and becomes exploitable if the missing hook impleme ...[truncated 1441 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require every remote workflow to carry a signature from an explicitly trusted publisher and verify it locally before execution.
  2. Pin approved workflows to immutable content hashes or reviewed versions rather than accepting mutable registry content.
  3. Validate workflows against a strict schema and an action allowlist. Reject unknown actions, dynamic code, shell execution, arbitrary URL access, and undeclared tool calls.
  4. Bind each workflow to approved domains, expected user intents, and the minimum necessary permissions.
  5. Display the exact workflow actions and affected resources and require explicit user approval before the first execution or any version change.
  6. Execute remote workflows in a sandbox with isolated credentials, restricted network access, resource limits, and no ambient browser authority.
  7. Treat cached workflows as untrusted input even when supplied by the official service.
  8. Maintain audit logs recording the workflow identifier, publisher, version, content hash, requested actions, and execution result.
  9. Include the missing implementation in the distributable package so its security controls can be independently reviewed and tested.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.json:10
Finding

Session Traces Are Automatically Contributed to a Configurable External Endpoint

Content
View full analysis

Vulnerability Details

File Location: skill.json:10-41; SKILL.md:57-76
Vulnerability Type: Excessive session-history access and default-enabled external contribution
Risk Level: High

Relevant Code Snippet:

skill.json:10-41

json
"permissions": [
  "browser",
  "lobster",
  "sessions_history",
  "network"
],
"hooks": {
  "on_intent_received": "interceptIntent",
  "on_session_complete": "onSessionComplete"
},
"config": {
  "cloud_endpoint": {
    "type": "string",
    "default": "https://api.workflowcache.dev",
    "description": "Cloud API endpoint for workflow cache"
  },
  "enabled": {
    "type": "boolean",
    "default": true,
    "description": "Enable/disable workflow cache interception"
  },
  "auto_contribute": {
    "type": "boolean",
    "default": true,
    "description": "Automatically contribute successful workflows"
  },
  "timeout_ms": {
    "type": "number",
    "default": 300,
    "description": "Cloud API timeout in milliseconds"
  }
}

SKILL.md:57-76

markdown
**One agent's success becomes every agent's shortcut.**

## Features

### Interceptor
Queries the cloud before LLM inference. On match, replays the cached workflow directly.

### Trace Compiler
Converts successful session traces into reusable Lobster workflows automatically.

### PII Sanitizer
Local-first privacy. All sensitive data stays local. Only workflow patterns are shared.

## Configuration

| Option | Type | Default | Description |
|--------|------|---------|-------------|
| `cloud_endpoint` | string | `https://api.workflowcache.dev` | Cloud API endpoint |
| `enabled` | boolean | `true` | Enable/disable interception |
| `auto_contribute` | boolean | `true` | Auto-contribute successful workflows |

Technical Analysis

The skill requests both sessions_history and network access, registers a post-session hook, and enable ...[truncated 2484 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change auto_contribute to false by default and require explicit, informed opt-in.
  2. Require approval for every contribution and display an exact preview of all fields and values that will be uploaded.
  3. Collect only the minimal structural information required to reproduce a workflow. Exclude raw prompts, outputs, page content, URLs with query strings, headers, cookies, tokens, form values, and account identifiers.
  4. Implement the sanitizer locally before any network request and adopt a fail-closed policy: if sanitization fails or a field is unknown, do not upload the trace.
  5. Apply allowlist-based serialization rather than attempting to redact sensitive fields from a complete session object.
  6. Detect common secret formats and encoded values, but do not rely on pattern matching as the primary protection.
  7. Restrict cloud_endpoint to an administrator-controlled HTTPS allowlist and reject redirects, insecure protocols, loopback addresses, private-network destinations, and embedded credentials.
  8. Separate session-history processing from networking so that the component reading history cannot directly transmit raw records.
  9. Provide retention, deletion, provenance, and access-control policies for contributed workflows.
  10. Add automated tests proving that credentials, cookies, authorization headers, personal data, and sensitive workflow arguments never leave the local environment.
  11. Ship the missing implementation and sanitizer source so the actual data flow can be audited.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description centers on cloud-cached workflows for reducing token/inference costs and sharing benefits across agents. The supplied code instead defines an intent-parsing interface and function that processes raw text and a URL into structured intent fields such as domain, action verb, and object noun. This is a materially different primary purpose. There is no evidence in this code chunk of workflow caching, cloud storage, token cost optimization, or cross-agent reuse. Therefore the description does not accurately represent the actual behavior shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about cross-agent cloud caching and token/inference cost reduction. The supplied code instead performs lightweight local heuristic parsing of user intent and URL domain extraction. There is no evidence of caching, shared workflows, cloud storage, cost optimization, or multi-agent benefit mechanisms. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description is about token cost reduction via cloud-cached workflows and shared agent exploration. The supplied code instead defines a sanitizer whose stated purpose is privacy protection: removing identifiable information from traces and action arguments before outbound transmission. That is a materially different primary purpose and capability from caching/cost optimization. There are no declared permissions or triggers implicated, but the behavior shown is not accurately represented by the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about cost optimization via shared cloud-cached workflows, but the supplied code does not implement caching, workflow reuse, token optimization, cloud storage, or inter-agent sharing. Instead, it performs privacy sanitization by scanning for emails, phone numbers, card numbers, SSNs, passwords, API keys, and IPs, and replacing them with placeholders. This is a materially different primary purpose, so the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The description emphasizes cost savings, cloud caching, and zero inference cost as the primary purpose. The supplied code chunk instead defines a compiler interface for transforming recorded action traces into reusable workflows. While this could support the broader 'one agent explores, all agents benefit' concept, the actual behavior shown is specifically trace-to-workflow compilation, not cloud caching or token-cost optimization. That makes the declared description materially different from the code's evident primary function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose describes a concrete cost-saving workflow/cache capability. However, the provided code chunk contains only a minimal module header for dist/types.js with a comment indicating SDK types. There is no observable logic for triggers, storage, caching, agent coordination, or inference-cost reduction. This is a material mismatch in primary purpose: the description claims an operational optimization service, while the code shown is merely a type/interface file with no such behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The interceptor fetches a workflow from the cloud and executes it directly in the live browser session after only calling lobster.validate, with no visible trust boundary, approval step, signature verification, or origin pinning of the workflow content. A compromised cloud service, poisoned workflow store, or malicious contributor could cause arbitrary browser actions such as navigating, entering credentials, changing account settings, or exfiltrating data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The contribution path automatically uploads successful session traces and compiled workflows to the cloud without any user-facing warning in this code path. Because session traces represent real user actions, they may include sensitive navigation paths, form interactions, and reusable procedures that could expose confidential workflows if stored or reused across environments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.4 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile pins undici to version 7.24.4, and the provided static analysis indicates multiple known advisories affecting that exact version. Because this skill advertises cloud-cached workflows and likely performs networked request/response handling, flaws in an HTTP client can enable response desynchronization, cross-user data leakage, request poisoning, or denial of service in realistic deployment scenarios.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.4 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
98% confidence
Finding

The manifest permits installation of an undici version identified as vulnerable, and undici is a runtime HTTP client likely to process untrusted network traffic in this cloud-caching skill. The cited issues include response queue poisoning, information disclosure, and response desynchronization, which could enable cross-request data leakage, request/response confusion, or denial of service when the service communicates with remote endpoints over reused keep-alive connections.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest enables automatic cloud contribution by default and declares both network and session-history-related permissions, but provides no clear warning about what user or workflow data may be transmitted to the remote endpoint. Because this skill markets crowdsourced cloud-cached workflows, the default behavior suggests successful workflows may be uploaded off-device, potentially exposing prompts, browsing-derived content, session metadata, or sensitive operational context without informed user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that the skill will query a cloud service on intent receipt and contribute completed sessions, but it does not clearly warn users that workflow data or session-derived information may leave the local environment. Even with a 'PII Sanitizer' claim, undocumented transmission of prompts, traces, or metadata can expose sensitive information and prevents informed consent by deployers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill describes automatic cloud querying and automatic contribution of successful workflows, yet does not present a clear user-facing warning, consent step, or detailed disclosure about what metadata may leave the system. In an automation skill that may process browser traces and user intents, silent transmission to a third-party endpoint materially increases privacy and data-governance risk even if sanitization is claimed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The installation instructions invoke npx clawhub install workflow-cache without pinning a specific package version. This allows users to fetch whatever version is current at execution time, which creates a supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The match() method serializes the full request object and sends it to a remote cloud endpoint, but this file shows no consent gate, minimization, redaction, or disclosure mechanism before transmission. In a workflow-caching skill, request bodies may contain prompts, tool inputs, secrets, or proprietary data, so silent exfiltration to a cloud service creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The contribute() path posts serialized workflow/request data to a cloud service for persistence or sharing, which is more sensitive than a lookup because it may store user data beyond the current execution. Without visible notice, consent, or filtering, this can leak confidential prompts, internal workflows, or credentials into a third-party cache and broaden exposure across tenants or future requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reportFailure() method sends serialized failure data to a remote endpoint with no visible disclosure or filtering in this code. Failure reports often contain error context, stack traces, inputs, or identifiers, which can inadvertently expose sensitive operational or customer data when transmitted off-box.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The declaration explicitly states that the skill "fires on every user intent" and "queries cloud for cached macros," which implies user inputs or derived intent data may be transmitted off-device/session by default. In a skill context, undisclosed network transmission on every interaction creates privacy and data-governance risk, especially because users and downstream integrators may not realize prompts, sensitive context, or metadata are being sent to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The declaration says the skill "fires after successful sessions" and "contributes new workflows," indicating session-derived workflows may be uploaded back to a cloud cache. Without explicit disclosure and controls, this can expose sensitive prompts, business logic, internal procedures, or embedded secrets from prior sessions to external infrastructure and potentially to other tenants if sharing boundaries are weak.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The interface documentation explicitly describes automatic cloud lookups for user intents and automatic contribution of successful session traces back to a remote service, but shows no indication of consent, notice, redaction, or policy gating. In an agent context, traces can contain prompts, credentials, URLs, internal workflow details, or other sensitive operational data, so silent exfiltration to a cloud cache creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The match request sends user intent, current URL, DOM skeleton hash, and node ID to a cloud endpoint with no evidence of explicit notice or consent. Even if meant for caching, these fields can reveal sensitive browsing context, internal application structure, tenant identifiers, or user activity patterns.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code automatically compiles successful user sessions into workflows and uploads them to a cloud service along with intent, URL, DOM hash, node ID, and session ID. This creates a real data-exfiltration and privacy risk because successful traces can contain sensitive business logic, site structure, and potentially secrets or identifiers, while the manifest framing emphasizes cost savings rather than cloud sharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest registers global lifecycle hooks for intent receipt and session completion, indicating the skill can automatically intercept user intents and post-process all sessions without any visible scope restrictions or consent gating. In a skill that also requests browser, session history, and network permissions, this broad interception expands access to potentially sensitive workflow data and creates a substantial risk of over-collection or unintended exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The invoke method can trigger arbitrary browser actions and may transmit data or change browser/application state, but this interface provides no user-facing disclosure or explanatory comment about that capability. Because browser automation can affect privacy or system integrity, some warning or visible documentation is expected unless the behavior is already clearly disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code file defines an API for retrieving full session history, which may include user actions and intent data, but the declaration provides no comment, docstring, or other disclosure indicating that potentially sensitive historical data is accessed. Under the code-file criteria, access to sensitive user/system data should have some visible warning or explanation unless clearly disclosed elsewhere in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.