T09 · Insecure Skill Coding Practices
- Location
scripts/skill_spector.py:270- Finding
Unredacted Secrets May Be Exposed Through Scan Reports
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local static scanner; the scary-looking patterns are detector rules or test fixtures, not active malware.
Installers that use @latest should be pinned or independently verified in high-assurance environments. When running this scanner, scan only directories you intend to audit and do not paste or store reports publicly unless you have checked them for secrets.
scripts/skill_spector.py:270Unredacted Secrets May Be Exposed Through Scan Reports
SKILL.md:60Installation Instructions Execute an Unpinned Latest Package
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
lines = [
"import subprocess",
"import urllib.request",
"subprocess.run(['echo','hi'], shell=True)",
"urllib.request.urlopen('https://example.com')",
f"api_key = {fake_proj!r}",
]
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
Pure stdlib. No network. No subprocess. No auto-install.
Detects:
- network / urllib / requests / httpx / sockets / curl|bash
- subprocess / os.system / shell / Popen / PowerShell IEX
- secret-looking patterns (API keys, HF tokens)
- permission claims vs code surface mismatch
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
("password_literal", 4, re.compile(r"(?i)(password|api_key|secret)\s*=\s*['\"][^'\"]{8,}['\"]"), "Hardcoded credential-like string"),
("rm_rf", 4, re.compile(r"(?<![\"'])\bshutil\.rmtree\s*\("), "Destructive delete capability"),
("rm_rf_cmd", 5, re.compile(r"\brm\s+-rf\s+|Remove-Item\s+[^\n]*-Recurse\s+-Force"), "Recursive force delete command"),
("git_push", 3, re.compile(r"(?<![\"'])\bgit\s+push\b"), "git push capability"),
("force_push", 4, re.compile(r"git\s+push\s+[^\n]*--force|git\s+push\s+-f\b"), "Force-push capability"),
("curl_pipe", 5, re.compile(r"curl\s+[^|\n]*\|\s*(ba)?sh"), "curl|bash remote code pattern"),
("wget_pipe", 5, re.compile(r"wget\s+[^|\n]*\|\s*(ba)?sh"), "wget|bash remote code pattern"),
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
code pattern"),
("wget_pipe", 5, re.compile(r"wget\s+[^|\n]*\|\s*(ba)?sh"), "wget|bash remote code pattern"),
("powershell_iex", 5, re.compile(r"(?i)\bIEX\s*\(|Invoke-Expression|DownloadString\s*\("), "PowerShell remote exec pattern"),
("clipboard", 2, re.compile(r"(?i)pyperclip|Set-Clipboard"), "Clipboard access"),
("keylogger_hint", 4, re.compile(r"(?i)pynput|keyboard\.Listener|GetAsyncKeyState"), "Keylogger-style input capture"),
("crypto_miner", 5, _RX_CRYPTO_MINER, "Crypto miner indicators (detection rule only)"),
("auto_install_pip", 3, re.compile(r"(?i)(?<!['\"])\bpip\s+install\b"), "pip install capability"),
("clawhub_publish", 3, re.compile(r"(?i)clawhub\s+publish|npx\s+clawhub.*publish"), "ClawHub publish capability"),
]
DOC_RULES: list[tuple[str, int, re.Pattern[str], str]] = [
("doc_auto_publish_enable", 2, re.compile(r"(?i)(enable|allows?|will)\s+auto[_-]?publish"), "Docs suggest enabling auto-publish"),
]
CODE_EXTS = {".py", ".ps1", ".sh
Without declared permissions the skill's intent is opaque and cannot be validated.
The installation instruction uses npx clawhub@latest install ..., which does not pin an exact version of the package manager component. If the upstream clawhub package is compromised or a breaking/malicious release is published, users following the documented command could fetch and execute unreviewed code during installation. In the context of a security-focused scanning skill, this is more sensitive because users are likely to trust and run the recommended install path.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
permit persons to whom the Software is furnished to do so.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE
This Python file performs file writes via write_under_state(), and the scan/report commands also expose filesystem paths in output. Although writes require --i-consent, there is no docstring or inline user-facing disclosure near the write function itself explaining that reports will be persisted under the skill state directory.
No suspicious patterns detected.