Back to skill

Security audit

coding-agent

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently delegates coding work to background agents, but it requires Claude Code to run with permission safeguards disabled and gives workers broad unattended execution authority.

Install only if you are comfortable with autonomous background coding agents operating in trusted, isolated repositories. Avoid using the Claude Code path unless you intentionally accept disabled permission prompts, and prefer sandboxed workdirs with minimal environment secrets and trusted notification route values.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:43
Finding

Claude Code Runs with Permission Controls Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:54
Finding

Untrusted Notification Values Can Be Embedded in a Shell Command

Content
View full analysis
- target: - account: - reply_to: - thread_id: When finished, send exactly one completion or failure message using: openclaw message send --channel --target '' --message '' Add --account, --reply-to, or --thread-id only when present above. Do not use openclaw system event or heartbeat. ``` ### Technical Analysis The instructions require dynamic notification route values and a generated result message to be inserted into a command intended for shell execution. They do not define validation rules or a reliable argument-escaping mechanism. The `channel` placeholder is unquoted. The `target` and `message` placeholders are surrounded by literal single quotes, but an embedded apostrophe can terminate that quoting context. The optional `account`, `reply-to`, and `thread-id` fields also have no specified quoting or validation policy. Writing the worker prompt through a quoted heredoc protects the prompt-generation operation from immediate shell expansion. It does not protect the later `openclaw message send` command when the autonomous worker reconstructs and executes it. If an attacker can influence a route field or the generated result text, shell metacharacters may be interpreted as command syntax rather than data. ### Attack Path 1. An attacker influences a notification route field, such as the target, account, reply-to value, or thread identifier, or causes the worker to generate attacker-controlled result text. 2. The dynamic value contains a quote terminator and shell syntax. 3. The value is substituted into the documented `openclaw message sen ...[truncated 1348 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs use of claude --permission-mode bypassPermissions --print without any accompanying user-facing warning, approval step, or limitation on what the spawned worker may do. In a skill whose purpose is delegating coding work as a background agent, this increases risk because the worker can perform filesystem or command actions without normal permission prompts, making accidental destructive changes or unsafe execution easier.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.