Back to skill

Security audit

Promptcache

Security checks for vulnerabilities and agentic risk

Overview

The skill advertises prompt-cache cost estimates, but its installer makes under-disclosed persistent shell changes and sends silent install telemetry while the declared executable is missing.

Review this before installing. The core prompt-cache idea is plausible, but the package is incomplete and the installer changes your shell profile and contacts Signal Loom during setup without clear consent. Prefer a version that includes the declared executable, documents all network activity, and asks before editing shell startup files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Warning
Location
install.sh:20
Finding

Undisclosed Installation Telemetry

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
install.sh:17
Finding

Unnecessary Persistent Shell-Profile Modification

Content
View full analysis
/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> "${HOME}/.zshrc" ``` ### Technical Analysis The installer permanently appends `~/.local/bin` to the user’s executable search path by editing `~/.zshrc`. However, the supplied installer does not place a `promptcache` executable in that directory. The persistent profile modification is therefore unnecessary for the behavior implemented by the package. Adding a user-writable directory to `PATH` is common, but it affects command resolution in every subsequent Zsh session. Programs placed in that directory may take precedence over system programs depending on the resulting path order. The test is also imprecise: it searches only for the literal string `~/.local/bin`, so an equivalent existing entry such as `$HOME/.local/bin` may not be recognized. This does not establish a backdoor, startup service, scheduled task, or privilege escalation. The identified issue is an avoidable and insufficiently controlled persistent configuration change. ### Attack Path 1. The user runs `install.sh`. 2. The script checks `~/.zshrc` for one literal representation of the directory. 3. If that representation is absent, the script appends an `export PATH` command. 4. Every subsequent interactive Zsh session loads the modified path. 5. Any executable later placed in `~/.local/bin` can participate in command resolution, including a same-named executable that shadows another command if path precedence permits it. ### Impact Assessment The modification persists across shell sessions and changes executable lookup behavior for the affected user account. It does not itself create a malicious executable or obtain elevated privileges. The practical impact is unnecessary configuration d ...[truncated 71 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
package.json:5
Finding

Package Declares a Missing Executable

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill's stated purpose is prompt cache cost estimation, but the detected behavior includes local installation, filesystem and shell profile modification, and outbound telemetry to an external endpoint. This mismatch is dangerous because users invoking an apparently simple analytical skill would not reasonably expect persistence changes or data egress, increasing the risk of stealthy system modification and leakage of prompts, keys, or usage data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool scope or allowed-tools despite requiring a binary and exhibiting shell-capable behavior. In a skill that appears to perform only cost estimation, undisclosed shell access expands the attack surface and can enable unintended command execution or environment changes without clear user consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 12)May include surrounding context.

sh
LOCAL_BIN="${HOME}/.local/bin"

echo "Installing ${SKILL_NAME}..."
mkdir -p "$OPENCLAW_SKILLS" "$LOCAL_BIN"

# Symlink into OpenClaw skills dir
ln -sf "$SCRIPT_DIR" "$OPENCLAW_SKILLS/${SKILL_NAME}"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer appends to the user's ~/.zshrc without prompting, which is a persistent environment change that affects future shell sessions. Unannounced startup-file modification can break user environments, create hard-to-trace behavior, and violates the principle of least surprise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installer makes an outbound analytics POST during installation that is not necessary for the advertised prompt-cost estimation functionality. Silent network transmission during install creates an avoidable privacy and trust risk, especially because users are not given an explicit opt-in before data is sent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer sends telemetry without explicit disclosure or consent beyond a comment in the script, which most users will never inspect. In an installer context, undisclosed external communication is especially sensitive because users expect setup steps, not silent reporting.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint indicates the installer depends on or communicates with a remote analytics service unrelated to core installation. In the context of a local skill installer, hidden remote contact increases privacy risk and expands the attack surface if the endpoint behavior changes later.

Content

Scanner excerpt · install.sh (reported line 22)May include surrounding context.

sh
grep -q '~/.local/bin' "${HOME}/.zshrc" 2>/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> "${HOME}/.zshrc"

# Fire install ping (no auth needed — tracks community installs)
curl -s -m 5 -X POST "https://api.signalloomai.com/v1/analytics/install" \
  -H "Content-Type: application/json" \
  -d "{\"skill\":\"${SKILL_SLUG}\",\"version\":\"${VERSION}\",\"source\":\"clawhub\"}" &

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The hardcoded external endpoint indicates the installer depends on or communicates with a remote analytics service unrelated to core installation. In the context of a local skill installer, hidden remote contact increases privacy risk and expands the attack surface if the endpoint behavior changes later.

Content

Scanner excerpt · install.sh (reported line 22)May include surrounding context.

sh
grep -q '~/.local/bin' "${HOME}/.zshrc" 2>/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> "${HOME}/.zshrc"

# Fire install ping (no auth needed — tracks community installs)
curl -s -m 5 -X POST "https://api.signalloomai.com/v1/analytics/install" \
  -H "Content-Type: application/json" \
  -d "{\"skill\":\"${SKILL_SLUG}\",\"version\":\"${VERSION}\",\"source\":\"clawhub\"}" &

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The comment downplays the behavior as a harmless install ping, but the script silently performs a background network request. This mismatch between explanation and actual behavior is risky because it reduces user awareness and impairs informed consent about external communications.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description says only "Estimate prompt caching savings. Signal Loom AI.", which describes a broad capability but does not specify trigger phrases, scope boundaries, or when the skill should or should not activate. In a manifest file, this lack of specificity can contribute to ambiguous invocation behavior if the description is used for discovery or routing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.