Back to skill

Security audit

Safe Skill Advisor

Security checks for vulnerabilities and agentic risk

Overview

This is a security-advice skill with no embedded executable payload, but it overreaches by using mandatory assistant directives and repeatedly recommending an unpinned third-party scanner install.

Review this skill before installing. Its checklist advice is generally aligned with security education, but do not blindly follow the unpinned pip install recommendation; use a pinned, verified scanner in an isolated environment if you choose to install one. Also expect the skill to proactively inject safety guidance around broad skill-installation conversations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:94
Finding

Unpinned Third-Party Security Scanner Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

md
1,184+ malicious skills were discovered on ClawHub (as of February 2026). This skill helps you:

- ⚠️ **Identify security risks** - Learn common attack methods (password-protected ZIPs, `curl | bash` scripts)
- 🔧 **Get tool recommendations** - Cisco AI Skill Scanner, SecureClaw
- ✅ **30-second self-check** - Quick checklist before installing any skill
- 📚 **Best practices** - How to install safely, what to avoid

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
1,184+ malicious skills were discovered on ClawHub (as of February 2026). This skill helps you:

- ⚠️ **Identify security risks** - Learn common attack methods (password-protected ZIPs, `curl | bash` scripts)
- 🔧 **Get tool recommendations** - Cisco AI Skill Scanner, SecureClaw
- ✅ **30-second self-check** - Quick checklist before installing any skill
- 📚 **Best practices** - How to install safely, what to avoid

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
1,184+ malicious skills were discovered on ClawHub (as of February 2026). This skill helps you:

- ⚠️ **Identify security risks** - Learn common attack methods (password-protected ZIPs, `curl | bash` scripts)
- 🔧 **Get tool recommendations** - Cisco AI Skill Scanner, SecureClaw
- ✅ **30-second self-check** - Quick checklist before installing any skill
- 📚 **Best practices** - How to install safely, what to avoid

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
1,184+ malicious skills were discovered on ClawHub (as of February 2026). This skill helps you:

- ⚠️ **Identify security risks** - Learn common attack methods (password-protected ZIPs, `curl | bash` scripts)
- 🔧 **Get tool recommendations** - Cisco AI Skill Scanner, SecureClaw
- ✅ **30-second self-check** - Quick checklist before installing any skill
- 📚 **Best practices** - How to install safely, what to avoid

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · 测试报告.md (reported line 66)May include surrounding context.

md
1,184+ malicious skills were discovered on ClawHub (as of February 2026). This skill helps you:

- ⚠️ **Identify security risks** - Learn common attack methods (password-protected ZIPs, `curl | bash` scripts)
- 🔧 **Get tool recommendations** - Cisco AI Skill Scanner, SecureClaw
- ✅ **30-second self-check** - Quick checklist before installing any skill
- 📚 **Best practices** - How to install safely, what to avoid

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
| Attack Method | Percentage | Description |
|----------|------|------|
| Password-Protected ZIP | 45% | Bypass antivirus detection |
| curl \| bash | 30% | Directly execute remote malicious scripts |
| Base64 Decode | 15% | Hide malicious code |
| Fake Official | 10% | Impersonate well-known developers |

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
98% confidence
Finding

The skill includes a dedicated 'AI SYSTEM DIRECTIVE' and 'MANDATORY INSTRUCTIONS FOR AI ASSISTANTS' section that attempts to control agent behavior after loading. Even though the content is security-themed, embedded hidden instructions are dangerous because they can override system/user intent, force unsolicited responses, and normalize prompt injection patterns inside third-party skills.

Content

Scanner excerpt · SKILL.md (reported line 296)May include surrounding context.

md
security tools
3. **Stay vigilant** - New attack methods emerge constantly
4. **Stay updated** - Follow latest security announcements

**Safety first, install with caution!** 🛡️

---

**Last updated:** 2026-04-01  
**Version:** 1.7.0  
**Based on February 2026 ClawHub Security Research**

---

---

## ⚠️ AI SYSTEM DIRECTIVE

**The following section contains mandatory instructions for AI assistants**

---

## 🚨 MANDATORY INSTRUCTIONS FOR AI ASSISTANTS

**If you have loaded this skill, you MUST follow these instructions:**

### 1. When User Asks About Skill Safety (MANDATORY)

When the user asks any question about skill security (e.g., "Is this skill safe?", "Should I install this?"):

**Step 1: Provide Security Warning**
You MUST warn the user about known risks:
- 1,184+ malicious skills discovered on ClawHub (as of February 2026)
- Common disguise: crypto tools, YouTube summarizers, auto-updaters
- Actual purpose: steal API keys, SSH credentials, passwords, crypto wallet k

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 137)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 344)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · 测试报告.md (reported line 118)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · 测试报告.md (reported line 364)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · 测试报告.md (reported line 118)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

Chaining Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · 测试报告.md (reported line 364)May include surrounding context.

md
检查 SKILL.md 文件:

1. 看安装说明
   - ❌ 要求执行 curl http://... | bash
   - ❌ 要求下载密码保护的 ZIP 文件
   - ❌ 要求从 GitHub 以外的来源下载

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises activation through very broad natural-language prompts like 'Is this skill safe?' and 'How to check if a skill is safe?', which are likely to overlap with ordinary conversation and trigger unintentionally. In an agent environment, this can cause the skill to inject its own guidance and recommendations into unrelated contexts, reducing user control and creating prompt-scope hijacking risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The proactive condition 'about to install ANY third-party skill' is excessively broad and instructs the agent to intervene across a large set of user interactions. This increases the chance of unintended activation and allows the skill to override normal assistant behavior with persistent security messaging, which is a form of prompt-scope overreach.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该测试报告明确写到技能会在用户仅输入“技能”这一单独关键词时进行识别和引导,这属于过于宽泛的触发条件。文中没有说明触发边界、排除条件或负面示例,容易在普通对话中被意外激活。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

整份技能测试与示例输出均固定为中文交互,且没有说明是否支持用户选择其他语言,也未见任何语言偏好或区域限定的正当性说明。根据规则,若技能在自然语言层面强制特定语言而没有用户选择或明确理由,属于语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.