Back to skill

Security audit

debate-research

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent debate-research skill that uses subagents and web search for its stated purpose, with manageable prompt-injection and installer-version risks users should understand.

Before installing, consider pinning the ClawHub installer version instead of using @latest. When using the skill on consequential topics, verify important sources yourself because web content and earlier agent outputs are reused in later debate phases and could bias the final report.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:66
Finding

Untrusted Web-Derived Content Is Recursively Injected into Agent Prompts

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:55
Finding

Installation Documentation Executes a Mutable Latest Package Release

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/prompts.md (reported line 83)May include surrounding context.

md
Do NOT judge who is right or wrong. Only audit evidence quality.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install command uses npx clawhub@latest, which fetches and executes the latest published package rather than a pinned, reviewed version. If the package is compromised, a malicious release is published, or the publisher account is hijacked, users installing the skill could execute attacker-controlled code during setup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.