Back to skill

Security audit

clawec-reddit-search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Reddit keyword search helper that sends a user-provided keyword to the disclosed ClawEC API using a disclosed API key.

Install only if you are comfortable using ClawEC as a third-party API provider. Searches will send your keyword to ClawEC and authenticate with CLAWEC_API_KEY, so avoid entering sensitive private terms unless that matches your use case.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs use of shell commands (curl and bash scripts/search.sh) but does not declare any tool scope or allowed-tools restrictions. This creates an unnecessary capability gap where an agent may invoke shell access without explicit governance, increasing the chance of unintended command execution or misuse in environments that rely on manifest-declared permissions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

调用

bash
curl -s -X POST "https://www.clawec.com/api/aigc/ec/reddit_search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $CLAWEC_API_KEY" \
  -d '{"keyword":"wireless earbuds"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown explicitly states '默认中文摘要', which imposes a specific output language as the default behavior. Under the policy, language constraints should not be forced unless the user is given a choice or the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The parameter and environment-variable error messages are presented only in Chinese, which imposes a specific language on users without any opt-in or documented justification. This is a natural-language locale policy issue because the script does not offer an alternative language or explain a region-specific constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search.sh (reported line 9)May include surrounding context.

sh
PAYLOAD=$(python3 -c 'import json,sys; print(json.dumps({"keyword": sys.argv[1]}))' "$KEYWORD")

curl -s -X POST "https://www.clawec.com/api/aigc/ec/reddit_search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $API_KEY" \
  -d "$PAYLOAD"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a network POST request to an external service and includes the user-supplied keyword in the request body, but there is no confirmation prompt, log message, or comment warning that input data will be transmitted off-system. For code files, outbound transmission of user data should have some visible disclosure unless clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire response schema and field descriptions are written in Chinese, with no indication that the skill is region-specific or that users may opt into another language. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script reads a sensitive credential from the CLAWEC_API_KEY environment variable, but there is no surrounding warning, comment, or visible disclosure explaining that the skill uses an API token. For safety review purposes, credential use should be transparent to the user when not otherwise documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.