Back to skill

Security audit

Claw Def

Security checks for vulnerabilities and agentic risk

Overview

This looks like an underimplemented security skill that advertises automatic protection that is not actually present, which could give users a false sense of safety.

Treat this as a Review item before installing. It does not show clear malware, but it also does not implement the protections it prominently claims, so users should not rely on it to block malicious skills or protect credentials until the entry point, enforcement hooks, privacy disclosures, dependency pinning, and path-safety issues are corrected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/file_protection.py:24
Finding

Sensitive-file protection can be bypassed through symbolic links

Content
View full analysis
str: file_path_abs = os.path.abspath(os.path.expanduser(file_path)) for level, patterns in self.protection_levels.items(): for pattern in patterns: pattern_abs = os.path.abspath(os.path.expanduser(pattern.replace('*', ''))) if file_path_abs.startswith(pattern_abs): return level return 'allowed' ``` ### Technical Analysis The protection decision is based on the lexical absolute path produced by `os.path.abspath()`. This function normalizes path components but does not resolve symbolic links to their actual filesystem targets. Consequently, an apparently allowed path can be a symbolic link to a critical file. For example, a path beneath `~/projects/` can resolve to `~/.ssh/id_rsa` while the method continues to classify it using the allowed-looking lexical path. The implementation also uses raw string-prefix comparison rather than component-aware path containment. This can cause incorrect classifications where two unrelated directory names share the same prefix. Because `check_file_operation()` returns `{'allowed': True}` for paths that do not lexically match a critical or restricted prefix, callers relying on this result can be induced to operate on a protected target. ### Attack Path 1. An attacker creates a symbolic link such as `~/projects/document` that points to `~/.ssh/id_rsa`. 2. The attacker requests a read, modification, or deletion operation using `~/projects/document`. 3. `_get_protection_level()` applies `abspath()` but does not resolve the symbolic link. 4. The lexical path does not match `~/.ssh/` and is classified as allowed. 5. A caller trusts the returned authorization result and performs the operation. 6. The operating system follows the symbolic link and accesses the ...[truncated 716 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill.json:9
Finding

Declared security entry point and enforcement mechanisms are absent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
PUBLISH-CHECKLIST.md:80
Finding

Git authentication guidance places access tokens in persistent remote URLs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
skill.json:11
Finding

Runtime dependencies are unpinned and the referenced dependency manifest is absent

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (26)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · PUBLISH-STATUS.md (reported line 47)May include surrounding context.

md
**解决方案:**
- 配置 SSH key
- 或使用 HTTPS + Personal Access Token

**当前选择:** 等待 Boss 有空时配置(非阻塞,可稍后完成)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/file_protection.py (reported line 10)May include surrounding context.

python
class FileProtectionManager:
    def __init__(self):
        self.protection_levels = {
            'critical': ['~/.ssh/*', '~/.gnupg/*', '/etc/passwd', '/etc/shadow'],
            'restricted': ['~/.aws/*', '~/.azure/*', '~/.config/*'],
            'allowed': ['~/projects/*', '~/tmp/*', '~/workspace/*']
        }

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/file_protection.py (reported line 10)May include surrounding context.

python
class FileProtectionManager:
    def __init__(self):
        self.protection_levels = {
            'critical': ['~/.ssh/*', '~/.gnupg/*', '/etc/passwd', '/etc/shadow'],
            'restricted': ['~/.aws/*', '~/.azure/*', '~/.config/*'],
            'allowed': ['~/projects/*', '~/tmp/*', '~/workspace/*']
        }

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/file_protection.py (reported line 11)May include surrounding context.

python
def __init__(self):
        self.protection_levels = {
            'critical': ['~/.ssh/*', '~/.gnupg/*', '/etc/passwd', '/etc/shadow'],
            'restricted': ['~/.aws/*', '~/.azure/*', '~/.config/*'],
            'allowed': ['~/projects/*', '~/tmp/*', '~/workspace/*']
        }

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/integration/test_file_protection_integration.py (reported line 15)May include surrounding context.

python
def test_restricted_file_permission_check():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('skill', 'read', '~/.aws/credentials')
    assert result['allowed'] == False
    assert result['action'] == 'ask'
    print("✅ test_restricted_file_permission_check 通过")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/unit/test_file_protection.py (reported line 16)May include surrounding context.

python
def test_restricted_file_permission_check():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('skill', 'read', '~/.aws/credentials')
    assert result['allowed'] == False
    assert result['action'] == 'ask'
    print("✅ test_restricted_file_permission_check 通过")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · BSTATION-SCRIPT.md (reported line 28)May include surrounding context.

md
def test_critical_file_blocked():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('test', 'read', '~/.ssh/id_rsa')
    assert result['allowed'] == False
    assert result['level'] == 'critical'
    print("✅ test_critical_file_blocked 通过")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/e2e/test_malicious_skill.py (reported line 9)May include surrounding context.

python
def test_critical_file_blocked():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('test', 'read', '~/.ssh/id_rsa')
    assert result['allowed'] == False
    assert result['level'] == 'critical'
    print("✅ test_critical_file_blocked 通过")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/integration/test_file_protection_integration.py (reported line 9)May include surrounding context.

python
def test_critical_file_blocked():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('test', 'read', '~/.ssh/id_rsa')
    assert result['allowed'] == False
    assert result['level'] == 'critical'
    print("✅ test_critical_file_blocked 通过")

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/unit/test_file_protection.py (reported line 9)May include surrounding context.

python
def test_critical_file_blocked():
    mgr = FileProtectionManager()
    result = mgr.check_file_operation('test', 'read', '~/.ssh/id_rsa')
    assert result['allowed'] == False
    assert result['level'] == 'critical'
    print("✅ test_critical_file_blocked 通过")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises cloud threat queries, WebSocket push, and threat reporting, which implies outbound network communication and possible transmission of local telemetry or sensitive security events, but it provides no disclosure about what data is sent, where it is sent, or how consent is obtained. In a security tool, this omission is especially risky because users may trust it with sensitive file, credential, or environment information and unknowingly expose that data to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The release notes advertise cloud threat queries, WebSocket real-time push, and threat reporting, but provide no disclosure about what data may be transmitted, when transmission occurs, or what privacy implications exist. In a security-focused tool, undisclosed outbound communication can mislead users into exposing file metadata, indicators, or other sensitive telemetry without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states it auto-enables after installation while advertising runtime interception, file protection, permission management, and security logging, but it does not clearly disclose that these protections will immediately begin monitoring or affecting system behavior. For a security tool, silent activation can mislead users about consent, data collection, and operational impact, increasing the risk of unexpected monitoring or policy enforcement.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · blog_post_zhihu.md (reported line 64)May include surrounding context.

md
return cached_result
        
        # 查询云端
        result = requests.post(API_URL, json={...})
        
        # 更新缓存
        cache.update(result)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code includes natural-language text only in Chinese, including the module docstring and access-denial reasons returned to callers. The file does not offer a language choice or document that the skill is intentionally limited to a Chinese-speaking context, which creates a locale-policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python test file contains natural-language strings and comments entirely in Chinese, including the module docstring and printed status messages. Under the policy rule for language/locale, this is a violation because it imposes a specific language without any opt-in, fallback, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The production note explicitly requires '添加中文字幕', which imposes a specific language choice. Under the policy, locale or language should not be forced unless the skill offers user choice or clearly documents a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is written entirely in Chinese and presents operational instructions and status text without any indication that the language was user-selected or that the skill is intentionally limited to Chinese-speaking users. Under the policy rule for language/locale constraints, this appears to impose a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file uses Chinese throughout, including status, blockers, schedules, and ownership notes, with no indication that the skill or its documentation is intentionally limited to Chinese-speaking users. Under the language/locale policy rule, forcing a single language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content of the skill documentation is entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

Natural-language policy violations apply to all file types, including markdown. The file presents all user-facing description text in Chinese and does not indicate that the skill is region-specific or that users can opt into another language, which may conflict with an organizational language/locale policy requiring choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire report is written in Chinese, including the title, headings, and status text, with no indication that language choice is optional or that the report is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing publishing instructions and article content exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, including headings, plans, and task descriptions, with no indication that the skill or document is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language strings exclusively in Chinese, including the module docstring and user-visible print output. For a general integration test file, this imposes a specific language/locale without any opt-in or justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.