Back to skill

Security audit

Agent Loop Engineering

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent AI coding-loop controller, but its bundled runner can repeatedly execute arbitrary PowerShell commands and persist raw command output into project state.

Install only if you want a coding-loop controller that writes persistent project Docs files. Treat the bundled runner as powerful: do not run it with secrets, production data, destructive commands, or broad shell commands, and set RunnerLogPath to a non-versioned log directory or sanitize logs before sharing/committing. Consider disabling implicit use and invoking the skill only when you explicitly want loop orchestration.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/agent-loop-runner.ps1:144
Finding

Unsanitized Command and Process Output Persisted in Project State

Content
View full analysis

Vulnerability Details

File Location: scripts/agent-loop-runner.ps1:144-147, 178-191, 199-209
Vulnerability Type: Plaintext persistence of potentially sensitive command data
Risk Level: Medium

Vulnerable Code

powershell
$runnerLog = if ([string]::IsNullOrWhiteSpace($RunnerLogPath)) {
  Join-Path $workspace "Docs\RUNNER_LOG.jsonl"
} else {
  $RunnerLogPath
}
powershell
$checkEvent = @{
  timestamp = (Get-Date).ToString("o")
  event = "runner_check"
  loop = $loopIndex
  workspace = $workspace
  checker_status = $status
  checker_exit_code = $checkerResult.ExitCode
  strict_mode = $strictMode
  checker_warnings = $checkerWarnings
  checker_issues = $checkerIssues
  checker_raw = $checkerResult.Raw
}
Write-RunnerLog -RunnerLogPath $runnerLog -Record $checkEvent
powershell
$loopEvent = @{
  timestamp = (Get-Date).ToString("o")
  event = "runner_loop_command"
  loop = $loopIndex
  workspace = $workspace
  command = $loopRun.Command
  exit_code = [int]$loopRun.ExitCode
  started_at = $loopRun.StartedAt
  finished_at = $loopRun.FinishedAt
  duration_ms = [int]$loopRun.DurationMs
  output = if ([string]::IsNullOrWhiteSpace($loopRun.Raw)) {
    "<empty>"
  } else {
    $loopRun.Raw.Substring(0, [Math]::Min(1000, $loopRun.Raw.Length))
  }
}
Write-RunnerLog -RunnerLogPath $runnerLog -Record $loopEvent

Technical Analysis

The runner records the complete caller-provided loop command, raw checker output, the absolute workspace path, and up to 1,000 characters of combined process standard output and standard error. No redaction or sensitivity filtering is performed before these fields are serialized as JSONL.

By default, the log is written to Docs/RUNNER_LOG.jsonl. Because Docs/ is the Skill's durable project-state directory, its contents may be committed, archived, included in handoffs, or uploaded by CI. This behavior contradicts the repository's stated requirements to retain only sanitized command summaries and to reda ...[truncated 1731 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change the default log destination from Docs/RUNNER_LOG.jsonl to a non-versioned location such as .agent/logs/RUNNER_LOG.jsonl.
  2. Add .agent/logs/ and any runner log file to the recommended .gitignore configuration.
  3. Do not persist the complete loop command. Record only an allowlisted executable name or a stable command identifier, and omit arguments by default.
  4. Redact output before serialization. Cover common token formats, authorization headers, passwords, cookies, private URLs, connection strings, email addresses, customer identifiers, and machine-specific paths.
  5. Make raw command and output logging explicitly opt-in, with a warning that the data may be sensitive.
  6. Prefer structured summaries containing the exit code, duration, verification category, and sanitized error classification rather than arbitrary process output.
  7. Apply restrictive filesystem permissions when creating the log.
  8. Add automated tests that inject representative secrets into commands, stdout, stderr, and checker output and verify that none appear in persisted logs.
  9. Document a retention policy and provide a safe mechanism for deleting or rotating old runner logs after explicit user approval.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/automation-runner.md (reported line 115)May include surrounding context.

{"loop_id":"2026-06-09T13:00:00Z-001","state":"Continue","verification":{"test":"pass","typecheck":"pass"},"next_action":"Run functional smoke check"}

text

If `LOOP_RUNS.jsonl` is missing or invalid, parse the latest decision section in `Docs/EVALUATION.md`. If neither source has a clear state, stop as `Blocked` and ask a human to repair the loop state.

Valid states:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/runner-adapters.md (reported line 118)May include surrounding context.

md
## GitHub Actions

Use for CI checks, scheduled diagnostics, issue creation, and repair PRs. Do not use GitHub Actions to access secrets, production resources, or perform destructive changes unless explicitly approved.

Suggested use:

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · scripts/agent-loop-check.ps1 (reported line 81)May include surrounding context.

text
$meaningful = $Text -split "`r?`n" | Where-Object {
    $line = $_.Trim()
    $line -and
      -not $line.StartsWith("<!--") -and
      -not $line.StartsWith("-->") -and
      -not ($line -match "^#+\s+") -and
      -not ($line -match "^Use this file") -and

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SECURITY.md (reported line 1)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/bootstrap.md (reported line 1)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 1)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/runner-adapters.md (reported line 1)May include surrounding context.

md
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · sitemap.xml (reported line 1)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:skill="https://clawhub.ai/schemas/skill-sitemap/1.0">
  <url>

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SECURITY.md (reported line 8)May include surrounding context.

md
## Secrets and Credentials

- Do not write API keys, tokens, passwords, OAuth sessions, cookies, SSH keys, or `.env` values into `Docs/`, `.agent/logs/`, chat summaries, commits, issues, or pull requests.
- Do not ask the user to paste secrets into the chat.
- If a task requires a secret or account login, mark the loop `Blocked` and record the needed credential class, not the credential value.

## Production Data and External Accounts

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/examples.md (reported line 36)May include surrounding context.

md
## Secrets and Credentials

- Do not write API keys, tokens, passwords, OAuth sessions, cookies, SSH keys, or `.env` values into `Docs/`, `.agent/logs/`, chat summaries, commits, issues, or pull requests.
- Do not ask the user to paste secrets into the chat.
- If a task requires a secret or account login, mark the loop `Blocked` and record the needed credential class, not the credential value.

## Production Data and External Accounts

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation description is extremely broad and targets nearly any AI coding scenario, making accidental or over-eager activation likely. Because this skill is a top-level controller that can direct implementation loops, verification, file updates, and stopping behavior, overbroad triggering can cause it to take control in contexts where a narrower or safer skill should apply.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- `Blocked`
- Budget exhausted

No verification means no `Done`. Failed verification means continue debugging, report `Done with Risk` with explicit limits, or stop as `Blocked` when a stop rule or human decision is required.

Checker `Done` means the project-local loop state is valid. It does not, by itself, prove the product behavior is correct. Before accepting a completion claim, use real project verification and read `references/checker-and-evidence.md` when strict evidence, command exit codes, or cross-repo checking are relevant.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
Checker `Done` means the project-local loop state is valid. It does not, by itself, prove the product behavior is correct. Before accepting a completion claim, use real project verification and read `references/checker-and-evidence.md` when strict evidence, command exit codes, or cross-repo checking are relevant.

When the user asks to absorb feedback from a real project and update the CMS process, Skill, or references, do not automatically modify that project's active `Docs/` state. First classify the feedback and update the reusable Skill/reference layer unless the user explicitly asks you to act as that project's Developer, Controller, or Acceptance agent. See `references/host-runtime-integration.md`.

## Task Classification

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/automation-runner.md (reported line 45)May include surrounding context.

md
- Store the only copy of memory outside `Docs/`.
- Continue after `Done`, `Done with Risk`, or `Blocked`.
- Loosen hard stop rules.
- Retry indefinitely.
- Run multiple writers against the same `Docs/` state without a lock.
- Hide failed verification, missing evidence, or human-decision requirements.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/environment-escalation.md (reported line 7)May include surrounding context.

md
## Agent May Handle Automatically

The agent may proceed without asking when the change is project-local, reversible, and verifiable:

- Install dependencies declared by the project manifest or lockfile.
- Restore dependency consistency using the project's package manager.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains a substantial policy/instruction section in Chinese, but it does not state that the user may choose the language or that the skill is intentionally Chinese-only for a justified audience. Under the language/locale policy, forcing one language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script executes an arbitrary PowerShell command supplied via -LoopCommand using powershell.exe -Command with ExecutionPolicy Bypass, and does so in an automated loop without any confirmation, allowlist, or safety gate. In an agent skill context, this is dangerous because a caller or upstream agent can cause repeated execution of destructive commands, making misuse or prompt-driven command injection materially more impactful.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- Mark completion only when evidence supports it.
- Resolve state conflicts in this order: `TARGET.md` -> `ACCEPTANCE.md` -> `STATUS.md` -> `PENDING.md` -> `NEXT_ACTIONS.md`.
- Use canonical `Docs/` file names. Legacy aliases may be read for migration, but write canonical files only.
- In multi-agent work, `WORK_ORDER.md` is the Developer's only task authority. `TARGET.md` guards direction and non-goals, `ACCEPTANCE.md` defines evidence gates, and `STATUS.md`, `NEXT_ACTIONS.md`, `LOOP_RUNS.jsonl`, or chat context must not expand scope.
- Keep one current acceptance table per active work order. Duplicate acceptance IDs, raw feedback pasted into acceptance rows, or competing AC sections are `Invalid State` until Controller or the project maintainer cleans them up.
- Treat CMS/process rules as maintainer-owned. Ordinary Developer, Controller, or Acceptance agents may propose rule changes, but must not edit reusable CMS settings unless the user explicitly assigns that maintainer role.
- If a work order depends on local/cloud mode, provider configuration, feature flags, unavailable devices/models, or waived criteria, it must name the environment mode, authoritative config, waived reason, and mandatory validation before `Done`.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This reference switches into Chinese for a dedicated explanatory section and later repeats key operational guidance in Chinese, but it does not say whether Chinese is optional, audience-specific, or accompanied by an explicit language choice. That can conflict with language/locale policy expectations when a skill or reference implicitly assumes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This reference switches into Chinese for a substantial instructional section labeled as a quick explanation, but it does not indicate that the user can choose the language or that the document is intentionally bilingual by opt-in. That can conflict with language/locale policy expectations when skills should not force a language without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script automatically creates a Docs directory if needed and appends JSONL records to RUNNER_LOG.jsonl in the workspace. While this behavior is visible in code, there is no user-facing warning or confirmation in the script before modifying the filesystem.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.