Back to skill

Security audit

自然语言Skill生成器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed skill generator, but its save and publish scripts can affect files and public repositories too broadly for the stated workflow.

Review carefully before installing. Use only with trusted skill names, inspect generated files before saving or publishing, avoid running the publish script on unreviewed skills, and do not authorize public GitHub or ClawHub publication until path validation and explicit confirmation controls are added.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/publish.py:123
Finding

Path Traversal Allows Unauthorized Git Operations and Potential Public Exposure of Local Directories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate.py:129
Finding

LLM-Controlled Skill Name Allows Filesystem Path Traversal and Arbitrary File Placement

Content
View full analysis
dict: """Parse the LLM response and generate the Skill structure""" try: json_match = re.search(r'\{[\s\S]*\}', text) if json_match: data = json.loads(json_match.group()) return { "name": data.get("name", "untitled-skill"), "description": data.get("description", ""), "triggers": data.get("triggers", []), "body": data.get("body", "") } ``` ```python def save_skill(skill: dict, output_dir: Path) -> Path: """Save Skill to files""" skill_name = skill.get("name", "untitled-skill") skill_dir = output_dir / skill_name skill_dir.mkdir(parents=True, exist_ok=True) # Write SKILL.md skill_file = skill_dir / "SKILL.md" content = format_skill(skill) skill_file.write_text(content, encoding="utf-8") # Write _meta.json meta_file = skill_dir / "_meta.json" meta = { "generated": True, "generatedAt": datetime.now().isoformat(), "version": "1.0.0" } meta_file.write_text(json.dumps(meta, indent=2, ensure_ascii=False)) return skill_dir ``` ### Technical Analysis The Skill name obtained from an LLM response is returned without enforcing the documented kebab-case constraint. `save_skill()` then uses this value directly as a path component. A relative name containing traversal components can escape `output_dir`. In addition, Python's `pathlib` path composition discards the earlier base when the appended operand is an absolute path. Consequently, an absolute generated name can redirect the output completely outside the intended Skill library. The function creates parent directories recursively and ...[truncated 1642 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/publish.py:91
Finding

Untrusted Skill Metadata Is Persisted in the Agent Memory Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is only skill generation, but the documented behavior also includes external publication, repository creation/push, and promotional content generation. This mismatch is dangerous because users may invoke what appears to be a local content-generation tool while it actually performs outbound publishing and command execution with persistence outside the local environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file automates publication to ClawHub and GitHub, including creating public repositories and pushing local content, despite the skill being described as a generator for reusable Skill code/templates. In this context, the mismatch is dangerous because a user invoking a 'skill generator' may unknowingly trigger external data transfer and public disclosure of generated or local workspace content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The main workflow orchestrates publishing and promotional actions that materially exceed the manifest's stated 'skill generation' scope. This is dangerous because hidden capability expansion undermines user consent and can lead to unanticipated publication of content to public platforms, increasing confidentiality and supply-chain risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises capabilities that include reading/writing files and invoking shell commands, but it does not declare any tool scope or permission boundaries. In a generator that can create, save, and publish artifacts, this makes it easier for the skill to perform unintended filesystem changes or command execution without clear user awareness or platform enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match common requests like '创建skill' or '做一个skill', increasing the chance of accidental activation. In this context, accidental activation is more dangerous because the skill can lead to file creation and possibly publication workflows rather than a harmless read-only response.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description and usage are written as directives for Chinese natural-language input ('自然语言描述需求') and do not indicate that other languages are supported or that the Chinese-only expectation is optional. This can be a language/locale policy issue because the skill appears to impose a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown states that saving can be followed by publication to GitHub and ClawHub, yet it does not prominently warn users about external side effects such as creating repositories, pushing content, or exposing generated material publicly. This is especially risky in a generation skill because generated output may contain sensitive, unreviewed, or policy-violating content that gets published unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage examples encourage natural-language activation without defining when the skill should and should not take over, which can cause ambiguous routing. Because this skill can create artifacts and initiate downstream publishing steps, ambiguity raises the risk of unintended actions from routine user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains multiple natural-language strings that assume Chinese as the required interaction language, beginning with the module docstring and continuing in prompts and demo output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language descriptions and messages entirely in Chinese, including the module docstring and later user-facing usage text, with no indication that the skill is region-specific or that users can choose another language. That creates a language/locale policy concern because the skill appears to mandate a specific language without opt-in.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 43)May include surrounding context.

python
"""发布到ClawHub"""
    print(f"📦 发布到ClawHub: {skill_name}...")
    try:
        result = subprocess.run(
            [CLAWHUB_CMD, "publish", skill_name],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 69)May include surrounding context.

python
try:
        # 初始化git(如果需要)
        if not os.path.exists(os.path.join(local_path, ".git")):
            subprocess.run(["git", "init"], cwd=local_path, check=True)
            subprocess.run(["git", "add", "."], cwd=local_path, check=True)
            subprocess.run(
                ["git", "commit", "-m", f"Add {skill_name} skill"],

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 70)May include surrounding context.

python
# 初始化git(如果需要)
        if not os.path.exists(os.path.join(local_path, ".git")):
            subprocess.run(["git", "init"], cwd=local_path, check=True)
            subprocess.run(["git", "add", "."], cwd=local_path, check=True)
            subprocess.run(
                ["git", "commit", "-m", f"Add {skill_name} skill"],
                cwd=local_path, check=True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 71)May include surrounding context.

python
if not os.path.exists(os.path.join(local_path, ".git")):
            subprocess.run(["git", "init"], cwd=local_path, check=True)
            subprocess.run(["git", "add", "."], cwd=local_path, check=True)
            subprocess.run(
                ["git", "commit", "-m", f"Add {skill_name} skill"],
                cwd=local_path, check=True
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 77)May include surrounding context.

python
)
        
        # 创建GitHub仓库并推送
        result = subprocess.run(
            ["gh", "repo", "create", repo_name, "--public", "--source", ".", "--push"],
            cwd=local_path,
            capture_output=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/publish.py (reported line 90)May include surrounding context.

python
else:
            # 仓库可能已存在,尝试推送
            if "already exists" in result.stderr:
                subprocess.run(["git", "push", "origin", "main"], cwd=local_path, check=True)
                return GITHUB_REPO_BASE + repo_name
            print(f"⚠️ GitHub发布失败: {result.stderr}")
            return None

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Generating Douyin promotional copy is outside the declared purpose of creating Skill code/templates and introduces undisclosed marketing behavior. In skill context, this broadens the agent's behavior into promotion and persistence of marketing content, which can surprise users and facilitate unintended external sharing workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated Douyin post instructs users to invoke the skill using the Chinese phrase "帮我创建一个{name}" and does not present alternatives for other languages or locales. Because this is natural-language behavior embedded in the code, it constitutes a policy issue unless the skill is explicitly documented as Chinese-only or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is written only in Chinese ("自然语言需求转换为Skill结构"), which indicates a language-specific presentation without any visible opt-in, alternative locale, or justification in this file. Under the stated policy, forcing a specific language can be a natural-language policy violation when no user choice is offered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.