Back to skill

Security audit

Before You Build Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only product-risk review skill with an optional, disclosed external case lookup that requires user permission.

Before installing, understand that this skill will steer product or feature requests into a skeptical pre-build review and may advise validating or deferring work. Do not use the optional Case Memory lookup with confidential business ideas, customer data, financials, credentials, or unreleased details unless you are comfortable sending a minimal summary to beforeyoubuild.fyi. Maintainers following the publishing docs should pin and verify CLI tooling rather than running mutable npm/npx commands blindly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
docs/OPENCLAW.md:128
Finding

Unpinned ClawHub CLI Installation and Execution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
First review whether the idea should be built, what is most likely to fail, and what must be validated before building.

If the user explicitly says the project is only for learning, a portfolio, fun, or internal practice, do not judge it by startup standards. You may still point out scope and clarity risks.

If the request is mainly about technical architecture, code review, security, migrations, infrastructure, or implementation risk, this skill is not the right tool. Use a general cold-shower technical review instead.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
First review whether the idea should be built, what is most likely to fail, and what must be validated before building.

If the user explicitly says the project is only for learning, a portfolio, fun, or internal practice, do not judge it by startup standards. You may still point out scope and clarity risks.

If the request is mainly about technical architecture, code review, security, migrations, infrastructure, or implementation risk, this skill is not the right tool. Use a general cold-shower technical review instead.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 222)May include surrounding context.

Case Memory endpoint:

text
POST https://api.beforeyoubuild.fyi/api/v1/case-memory/search

The endpoint is used to retrieve similar public product cases from Before You Build. It is not required for the core skill to work.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes broad natural-language phrases like 'Should I add this feature?' and 'Competitors have X. Should we add it?' that can match ordinary product discussions far beyond the intended narrow use case. Overbroad invocation can cause the wrong skill to activate, steering conversations away from the user's actual goal and potentially suppressing more appropriate safety, technical, or domain-specific guidance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The default prompt uses a broad natural-language invocation phrase ('before you build') without any visible trigger constraints or namespacing. This can cause accidental or ambiguous activation when users say common phrases, leading to unintended skill routing or prompt injection opportunities through mis-invocation, though the skill’s business-analysis scope limits the severity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/OPENCLAW.md (reported line 28)May include surrounding context.

md
- No API key is required for normal use.
- Optional Case Memory lookup is documented separately and should only be used after user permission.

A separate OpenClaw-only fork would create duplicate maintenance work and increase the chance that the public instructions drift apart.

## Recommended OpenClaw Install

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation recommends executing npx --yes clawhub without pinning a specific package version. This creates a supply-chain risk because users may fetch and run whatever version is current at execution time, including a compromised or maliciously republished package. In a security-sensitive publishing workflow, that can lead to arbitrary code execution on the publisher's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation recommends running npx --yes clawhub without pinning a specific package version. Because npx resolves and executes the latest published package by default, a compromised upstream release or unexpected breaking change could cause users to run unreviewed code on their machine. In this context, the risk is real but limited to users who follow the operational instruction in the docs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "before you build" is generic and can plausibly appear in ordinary product or planning conversations, which increases the chance the skill is invoked outside its intended niche. Unintended invocation can cause workflow confusion, irrelevant guidance, or context switching, though this file does not suggest direct code execution, data exfiltration, or privilege abuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill instructs sending user-derived idea summaries to an external API, which creates a real data exfiltration/privacy risk if the summary contains confidential business information, personal data, or unreleased product details. The file partially mitigates this by requiring explicit user agreement and warning not to send secrets, but remote transmission remains security-relevant because users or downstream agents may still overshare sensitive content.

Content

Scanner excerpt · references/case-memory-api.md (reported line 12)May include surrounding context.

Endpoint:

text
POST https://api.beforeyoubuild.fyi/api/v1/case-memory/search

Request fields:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example request sets "language": "en", which imposes a specific language/locale in the skill instructions. Because the document does not indicate that users may choose another language or explicitly opt into English-only behavior, this appears to violate the language/locale policy.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
### Feature additions and requirement changes

If the user wants to add a feature, change requirements, expand scope, copy a competitor, or pivot an in-progress product, do not treat it as a brand-new product idea.

Give a short Feature Reality Check.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file includes repeated natural-language notes about submitting the skill to Chinese skill lists and guides. Because the file presents locale-specific targeting without any stated user opt-in or documented justification for language/locale constraints, it may conflict with the policy against forcing a specific language or locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.