Back to skill

Security audit

clawhub-recommender

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain-language ClawHub skill recommender that does not execute code or install anything by itself, though users should review recommended skills before installing them.

Use this as a recommendation aid, not as an automatic trust decision. Before running any suggested `clawhub install` command, check the skill publisher, permissions, install hooks, and whether the skill can persist data, access communications, or change agent behavior.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/popular_skills.md:12
Finding

Unpinned Third-Party Skill Installation Creates Supply-Chain Risk

Content
View full analysis
`). ``` `references/popular_skills.md:12-16`: ```markdown - **Capability Evolver** (`capability-evolver`) - **Downloads**: 35,000+ - **Description**: AI self-evolution engine that autonomously audits and rewrites agent behavior. - **Link**: [https://clawhub.ai/skills/capability-evolver](https://clawhub.ai/skills/capability-evolver) - **Install**: `clawhub install capability-evolver` ``` `references/recommendation_logic.md:17-20`: ```markdown ## Selection Criteria 1. **Popularity**: Prioritize skills with >10,000 downloads or high star counts. 2. **Official/Verified**: Prefer official integrations (e.g., `github`, `linear`) for stability. 3. **Contextual Fit**: If the user is currently working on a specific project (e.g., a React app), prioritize `fast-io` or `github`. 4. **Recent Trends**: Mention skills that are currently trending in the community (e.g., `capability-evolver`). ``` ### Technical Analysis The recommendation workflow provides installation c ...[truncated 2657 chars]
Remediation
View remediation
@ ``` 9. Maintain an auditable allowlist containing the reviewed version, publisher identity, source repository, expected digest, review date, and required permissions. 10. Revalidate catalog claims and pinned artifacts periodically, and disable recommendations when verification data is stale or unavailable. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use' section includes broad conditions such as when a user asks for general recommendations or when a task could be improved by an existing skill. These triggers are expansive and lack exclusion criteria or negative examples, increasing the chance of unintended invocation during ordinary conversation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.