Back to skill

Security audit

CocoLoop Skill Factory

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent skill-building factory, but it includes default host probing and several mutable external install or runtime-loading paths that need review before use.

Install only if you are comfortable with a skill factory that inspects local environment details and may guide agents toward external CLI, browser, and package setup. Before running generated or referenced scripts, pin dependency versions, avoid system Python modification, prefer isolated environments, and review any browser automation that reuses logged-in sessions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

other

Note
Location
utils/cli/detect-environment.py:24
Finding

Mandatory Environment Detection Exposes Detailed Host and Agent Installation Information

Content
View full analysis
dict[str, Any]: home = Path.home() shared_roots = [ workspace / ".agents" / "skills", home / ".agents" / "skills", ] platform_markers = { "codex": [ workspace / ".codex" / "skills", home / ".codex" / "skills", ], "claude code": [ workspace / ".claude" / "skills", home / ".claude" / "skills", ], "openclaw": [ workspace / ".openclaw", home / ".openclaw", ], "copaw": [ workspace / ".copaw", home / ".copaw", ], "molili": [ workspace / ".molili", home / ".molili", ], "hermes agent": [ workspace / ".hermes", home / ".hermes", ], } shared_matches = [str(path.resolve()) for path in shared_roots if path.exists()] platform_hints: list[dict[str, Any]] = [] for platform_name, candidates in platform_markers.items(): matches = [str(path.resolve()) for path in candidates if path.exists()] if matches: platform_hints.append({"platform": platform_name, "matched_paths": matches}) return { "shared_skill_roots": shared_matches, "platform_hints": platform_hints, } ``` ```python def build_snapshot() -> dict[str, Any]: workspace = Path.cwd() commands = [ "python3", "python", "node", "npm", "uv", "git", "cocoloop", "clawhub", ] command_states = [] for command in commands: if command == "clawhub": info = command_version(command, ...[truncated 3093 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
output/clawhub-infographic-ppt-deep-dive/source-skills/article-to-infographic/scripts/html_to_png.py:29
Finding

PNG Exporter Automatically Installs Unpinned Playwright and Chromium Components

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
atomic-capability/browser-access/opencli-browser-bridge.md:18
Finding

Setup Instructions Execute Mutable Latest-Version npm Packages

Content
View full analysis
``` ### Technical Analysis Both commands resolve a mutable `latest` release at execution time. Consequently, the code installed or executed by users can differ from the version available during the security review. The OpenCLI instruction performs a global npm installation. Depending on npm configuration, package lifecycle scripts and CLI code execute with the user's privileges and create files outside the project directory. The `npx` instruction downloads and executes a package directly, also without an exact version or integrity constraint. No evidence established that the named packages are currently malicious. The vulnerability is the unsafe and non-reproducible dependency acquisition model. ### Attack Path 1. A generated Skill or setup plan directs the user to enable browser automation or retrieve a design preset. 2. The user runs the documented `npm ...@latest` or `npx ...@latest` command. 3. npm queries the configured registry and resolves the package version currently associated with the `latest` tag. 4. npm downloads the package and its transitive dependencies. 5. Package lifecycle scripts or the requested CLI execute with the user's account privileges. 6. If the package, maintainer account, registry, or transitive dependency has been compromised, attacker-controlled code executes locally. 7. For the global installation, malicious files can persist in the user's global npm directories and remain callable after the Skill run. ### Impact Assessment A compromised dependency could read or modify user-accessible files, inspe ...[truncated 334 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
output/clawhub-infographic-ppt-deep-dive/source-skills/text-to-ppt/references/shell-template.html:7
Finding

Generated Presentation Template Executes Remote CDN JavaScript Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis Opening a presentation generated from this template causes the browser to retrieve and execute JavaScript from third-party CDNs. The Tailwind URL is not versioned, while the jsDelivr dependencies use major-version ranges rather than immutable artifact versions. None of the resources has a Subresource Integrity attribute. The browser therefore cannot verify that the downloaded content matches an artifact reviewed by the project. The effective executable payload can change after audit because of upstream updates, CDN compromise, DNS or network interference, or package-maintainer compromise. Remote resource requests also disclose ordinary network metadata—including the viewer's IP address, request timing, referrer behavior, and browser characteristics—to external providers. ### Attack Path 1. The Skill generates or copies an HTML presentation based on `shell-template.html`. 2. A user opens the generated presentation in a browser with network access. 3. The browser requests JavaScript from `cdn.tailwindcss.com` and `cdn.jsdelivr.net`. 4. The browser executes the returned JavaScript because the resources are loaded as script elements. 5. If a CDN response or upstream package is compromised, attacker-controlled JavaScript runs in the presentation's document context. 6. The malicious script can alter presentation content, capture data available to the page ...[truncated 686 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (241)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Unlike the other TP4 entries, this one points to behavior that is actually described: the skill explicitly directs environment detection, platform/system/shell/browser/tool discovery, and local context inspection. While environment probing can be legitimate for platform-targeting, it also gathers host fingerprinting data and scans local workspace state, which becomes more dangerous because the skill lacks explicit permission boundaries and asks to do this by default.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- `reference-skill.py`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- `reference-skill.py`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- `reference-skill.py`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
- `reference-skill.py`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

md
- 本地分析时,要完整查看 `SKILL.md`、子目录结构、脚本、参考文档、模板、依赖声明和关键资源

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

md
- 本地分析时,要完整查看 `SKILL.md`、子目录结构、脚本、参考文档、模板、依赖声明和关键资源

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · atomic-capability/presentation-generation/index.md (reported line 202)May include surrounding context.

md
- speculative claims
- unverified numbers
- projections without caveat
- superlatives
- text overflow

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
55% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/ai-presentation-maker/SKILL.md (reported line 449)May include surrounding context.

md
> - "Don't compare to competitors by name"
> - "Don't say 'this will definitely...' — say 'based on what we've seen...'"
> - "Don't skip the costs slide — transparency builds trust"
> - "Don't apologize for early results — frame as experiments"

---

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/ai-presentation-maker/assets/presentation-helper.sh (reported line 96)May include surrounding context.

sh
pres_id=$(grep -o '"presentation_id": *"[^"]*"' "$tmp" | head -1 | cut -d'"' -f4)
  fi
  
  [[ -z "$pres_id" ]] && { echo "ERROR: No presentation_id in JSON" >&2; rm -f "$tmp"; return 1; }
  
  local safe_id
  safe_id=$(sanitize_filename "$pres_id")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/ai-presentation-maker/assets/presentation-helper.sh (reported line 198)May include surrounding context.

sh
[[ -f "$deck" ]] && { rm -f "$deck"; deleted=$((deleted + 1)); }
  
  # Also remove exports
  rm -f "${EXPORTS_DIR}/${safe_id}".*  2>/dev/null
  
  if [[ $deleted -gt 0 ]]; then
    echo "✅ Deleted: ${safe_id} (${deleted} files)"

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/article-to-infographic/references/illustrations-guide.md (reported line 43)May include surrounding context.

Working person illustration
```

Known Vulnerable Dependency: image-size==1.2.1 — 2 advisory(ies): CVE-2025-71329 (image-size: JXL and HEIF parsers allow denial of service through infinite loops); CVE-2025-71330 (image-size: ICNS parser allows denial of service through an infinite loop)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile pins image-size to 1.2.1, which is reported as vulnerable to denial-of-service issues in multiple image parsers via infinite loops. Because this skill appears to generate PPT content and may inspect user-supplied or externally fetched images, a crafted image could hang the Node.js process, disrupt skill execution, and potentially block shared worker capacity.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/visual-note-card/README.md (reported line 74)May include surrounding context.

Claude Code:

bash
rm -rf ~/.claude/skills/visual-note-card

OpenClaw:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/visual-note-card/README.md (reported line 80)May include surrounding context.

Claude Code:

bash
rm -rf ~/.claude/skills/visual-note-card

OpenClaw:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · output/clawhub-infographic-ppt-deep-dive/source-skills/visual-note-card/README.md (reported line 74)May include surrounding context.

Claude Code:

bash
rm -rf ~/.claude/skills/visual-note-card

OpenClaw:

Static analysis

Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
factory-skill-builder/scripts/package_skill.cjs:78

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
output/clawhub-infographic-ppt-deep-dive/source-skills/visual-note-card/README.md:80