T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/continuum.py:486- Finding
Untrusted capsule controls the filesystem verification base
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This local verification skill is mostly coherent, but untrusted capsules can steer local file reads and inject active or agent-directed content into generated outputs.
Install only if you are comfortable reviewing capsules before use. Always pass an explicit --base for the intended project, do not verify or hand off capsules from others without reading them, avoid opening generated witness-card HTML from untrusted capsules, and prefer a pinned installer instead of npx clawhub@latest.
scripts/continuum.py:486Untrusted capsule controls the filesystem verification base
scripts/continuum.py:592Unescaped capsule fields allow active-content injection into witness cards
{rh}…scripts/continuum.py:370Attacker-controlled regular expressions can cause denial of service
SKILL.md:58Installation instructions execute an unpinned mutable dependency
scripts/continuum.py:548Untrusted capsule content is promoted into Agent handoff instructions
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
base=root,
)
abs_esc = c.evaluate_claim(
{"id": "y", "kind": "file_exists", "path": str(Path.home() / "secret.txt")},
base=root,
)
glob_esc = c.evaluate_claim(
Without declared permissions the skill's intent is opaque and cannot be validated.
Using npx clawhub@latest install ... introduces a supply-chain risk because @latest is mutable and can resolve to a different package version over time. If the registry package or dependency chain is compromised, users may execute unreviewed code during installation even though the skill itself claims local-only behavior afterward.
The module documentation asserts that writes are confined under --base or state/ with --i-consent, but the implementation includes an unrestricted override path. This is dangerous because downstream agents, operators, or policy engines may rely on the documented safety guarantees and grant the skill trust it has not actually earned, leading to unsafe file writes outside the workspace boundary.
The code explicitly permits arbitrary filesystem writes when --i-allow-any-out is supplied, which contradicts the stated confinement model of writes being limited to --base or state/ with --i-consent. In an agent setting, this weakens a key safety boundary: a prompt or workflow that can influence CLI arguments may cause the tool to overwrite files outside the intended workspace, including user config or project files.
No suspicious patterns detected.