Back to skill

Security audit

Clawhub Publish Howto

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent ClawHub publishing guide, but it gives unsafe instructions for storing GitHub access tokens in a persistent shell file.

Review this before installing or following it. Do not put real GitHub tokens in ~/.bashrc or paste long-lived tokens into command history; prefer a credential manager, GitHub CLI/keychain flow, or a short-lived fine-grained token used only for the command and revoked afterward.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:39
Finding

Insecure Plaintext Storage and Command-Line Handling of Access Tokens

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39–45; related examples at lines 23–31 and 73–76
Vulnerability Type: Plaintext credential exposure
Risk Level: Medium

Vulnerable Code

bash
# Temporary use (single invocation)
GITHUB_TOKEN="ghp_your_token_here" clawhub publish <path> --version 1.0.0 --tags "..."

# Permanent configuration (add to ~/.bashrc or environment variables)
echo 'export GITHUB_TOKEN="ghp_your_token_here"' >> ~/.bashrc
source ~/.bashrc

Related token-handling instructions include:

bash
# 1. Obtain a clawhub token
clawhub login

# 2. Log in using the token (without a browser)
clawhub login --token <clh_token>

# 3. Verify
clawhub whoami
bash
GITHUB_TOKEN="ghp_your_token" clawhub publish ...

Technical Analysis

The Skill advises users to place a GitHub access token directly in ~/.bashrc. This stores the credential as plaintext in a persistent shell configuration file. The file may subsequently be exposed through configuration backups, support bundles, accidental repository commits, insecure file permissions, or access by another process or account capable of reading the user's files.

The examples also encourage users to type GitHub and ClawHub tokens directly into interactive command lines. Such commands may be retained in shell history. A ClawHub token passed through --token may additionally be exposed as a process argument while the command is running. The prefixed GITHUB_TOKEN assignment may be observable through process-environment inspection by sufficiently privileged local processes.

No hardcoded live credential or deliberate credential-exfiltration endpoint was identified. The examples use placeholders, and the documented GitHub requests target the official https://api.github.com service. The issue is therefore insecure credential-handling guidance rather than an embedded secret or malicious exfiltration mechanism.

Attack Path

  1. A user follows the ...[truncated 1505 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to write access tokens directly into ~/.bashrc.
  2. Prefer the official GitHub CLI credential store, an operating-system keychain, a dedicated secrets manager, or ClawHub's secure credential-storage mechanism.
  3. Avoid placing tokens directly in interactive command text. Read secrets without terminal echo or retrieve them programmatically from a credential manager.
  4. If an environment variable is required, populate it from a protected secret source only for the lifetime of the command and unset it immediately afterward.
  5. Warn users not to commit shell configuration, environment files, command histories, or diagnostic bundles containing credentials.
  6. Recommend fine-grained, least-privilege tokens restricted to only the required repositories and operations.
  7. Prefer short expiration periods and document token rotation and immediate revocation procedures.
  8. Document restrictive permissions for any unavoidable local secret file, such as owner-only access, while clarifying that file permissions do not replace secure secret storage.
  9. Replace clawhub login --token <token> with an interactive standard-input or credential-helper workflow if supported, preventing token exposure through command arguments and shell history.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

mi

text

### 方法二:环境变量配置 GitHub Token(解决限流)

clawhub 后台使用共享的 GitHub App 配额(180次/小时),容易触发限流。
配置自己的 GitHub Token 可以突破共享限额:

```bash
# 临时使用(单次)
GITHUB_TOKEN="ghp_your_token_here" clawhub publish <path> --version 1.0.0 --tags "..."

# 永久配置(加到 ~/.bashrc 或环境变量)
echo 'export GITHUB_TOKEN="ghp_your_token_here"' >> ~/.bashrc
source ~/.bashrc

验证 Token 有效:

bash
curl -H "Authorization: token $GITHUB_TOKEN" https://api.github.com/rate_limit
# 限额应为 5000(不是 60)

发布命令

bash
# 标准发布
clawhub publish /path/to/skill --version 1.0.0 --tags "tag1,tag2,tag3"

# 带名称
clawhub publish /path/to/skill --name "Skill Name" --version 1.0.0 --tags "..."

# 带变更日志
clawhub publish /path/to/skill --version 1.0.0 --changelog "Initial release"

常见错误排查

1. `GitHub API rate limit exce

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
**解决:** 确保 skill 目录中有 `SKILL.md` 或 `skills.md`

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
| 检查项 | 命令 |
|--------|------|
| 登录状态 | `clawhub whoami` |
| GitHub Token 限额 | `curl -H "Authorization: token $GITHUB_TOKEN" https://api.github.com/rate_limit` |
| 账号年龄 | GitHub 账号需满 **14 天**才能发布 |

## 认证方式(推荐)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
| 检查项 | 命令 |
|--------|------|
| 登录状态 | `clawhub whoami` |
| GitHub Token 限额 | `curl -H "Authorization: token $GITHUB_TOKEN" https://api.github.com/rate_limit` |
| 账号年龄 | GitHub 账号需满 **14 天**才能发布 |

## 认证方式(推荐)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
| 检查项 | 命令 |
|--------|------|
| 登录状态 | `clawhub whoami` |
| GitHub Token 限额 | `curl -H "Authorization: token $GITHUB_TOKEN" https://api.github.com/rate_limit` |
| 账号年龄 | GitHub 账号需满 **14 天**才能发布 |

## 认证方式(推荐)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to persist a GitHub personal access token in ~/.bashrc, which increases the chance of long-term credential exposure through shell history, dotfile backups, accidental commits, shared accounts, or later local compromise. While not inherently malicious, recommending permanent plaintext storage of a sensitive token without any warning or least-privilege guidance is unsafe operational security.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.