Back to skill

Security audit

Si Clawhub

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local inventory tool for reviewing installed agent skills, with optional user-confirmed settings changes to disable skills or save a language preference.

Before installing, understand that the default report is local and read-only, but using --overrides --apply --yes can persistently disable listed skills through WorkBuddy settings. Review the impact output and backup path before applying changes, and point --root or --probe only at the intended skills directory to avoid scanning unrelated local folders.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
allowed-tools: Bash(python scripts/skill_inventory.py:*), Read, Glob, Grep, Write(~/.workbuddy/settings.json), Edit(~/.workbuddy/settings.json), Write(~/.workbu

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
| 技能目录 | ✅(已知平台可自动探测) | 每个子目录 = 一个技能(含 `SKILL.md` 即可);其他平台用 `--root <目录>`,或直接 `--probe` 让它自己找 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

md
| 技能目录 | ✅(已知平台可自动探测) | 每个子目录 = 一个技能(含 `SKILL.md` 即可);其他平台用 `--root <目录>`,或直接 `--probe` 让它自己找 |

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill explicitly permits a persistent local write to ~/.workbuddy/settings.json to modify skillOverrides, which changes future agent behavior beyond the current session. Although the write is consent-gated and backed up, it is still session persistence that can disable skills and create durable state changes if invoked improperly or through confused-deputy prompting.

Content

Scanner excerpt · SKILL.en.md (reported line 205)May include surrounding context.

md
before trusting the tool. This section keeps only the **three SKILL-side technical points**
relevant to closing (no duplication of the README contract):

- **The tool never closes a skill on its own.** The close write path runs only with your
  explicit `--overrides --apply --yes` on a closable platform: it backs up `settings.json` first,
  then merges "off" entries into `skillOverrides`; without `--yes` it is a dry-run; non-closable
  platforms reject `--apply` outright.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.en.md (reported line 244)May include surrounding context.

md
| # | Wrong move | Why it's wrong | Right move |
|---|---|---|---|
| 1 | **Deleting the skill directory directly** to "close" a skill | Bypasses the backup artifact and protected-lock detection; may delete a skill still referenced by automations/hooks/triggers with no rollback | Let the tool emit an `--overrides` draft, then close via the host `/skills` menu or manual removal using the backup path printed in the report |
| 2 | **Closing without checking impact preview** | The skill may still be called implicitly by keyword triggers / experts / automations, leaving no log trace → false kill | Run `--impact <name>` first; confirm `referenced_by` is empty before acting |
| 3 | **Treating "no usage record" as "unused"** | "No record" only means no T1 explicit hit; T2 auto-mount / T3 keyword routing / T4 scheduled tasks / T5 hooks / T6 expert-internal calls leave no trace | Read both the "close candidates" and "manual review" buckets; confirm every candidate with the user before closing |
| 4 | **Expecting `--apply` to work on non-closable platforms** | `can_close=False` platforms (QwenWork / Baidu / generic) have no programmatic close channel; `--apply` is rejected outright | Use the host's own enable/disable toggles or manual client removal; the tool only reports inventory and candidates |
| 5 | **Treating `--protect` as a universal guard** | `--protect` only adds named skills to the protected bucket; it does not change the fact that "reverse-dependency scan only covers discoverable config roots" | Pair with `--refs` to point at extra reference-definition roots (automations/hooks/routing) for double coverage |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.en.md (reported line 251)May include surrounding context.

md
| 6 | **`--root` pointing at a parent directory** that swallows unrelated dirs | In generic mode, `--root` scans **every** subdirectory under it as a skill, pulling in unrelated folders | Point `--root` exactly at the "skills root" (each subdirectory = one skill); on unknown hosts prefer `--probe` to let the tool find the root itself |

> Design posture: **under-report rather than false-kill.** The tool will never decide for you
> that a skill "may be closed" — it only emits candidates and impacts, and every write
> requires your explicit authorization plus a printed backup path.

---

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
Office-agent skill inventory & health check. Scans any skills directory, measures size and
  context-token footprint, detects duplicates, and classifies skills into used / protected /
  closeable / manual-review buckets. Reverse-dependency scanning locks every skill referenced by
  automations, hooks or plugins. Read-only by default: two disclosed, consent-gated write targets —
  `--overrides --apply --yes` (programmatic close on platforms like WorkBuddy; dry-run without
  --yes) and `--set-lang` (saves the report language preference to
  ~/.workbuddy/skill-inventory.json) — plus one disclosed backup artifact: a timestamped

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/skill_inventory.py (reported line 17)May include surrounding context.

python
权限与驻留声明 / Permission & residency declaration
------------------------------------------------------
WRITE SCOPE: two target paths + one disclosed backup artifact, all declared here:
  1. ~/.workbuddy/settings.json -> key "skillOverrides", via --overrides --apply --yes
     (dry-run without --yes; see the backup artifact below). Written atomically:
     a temp file in the same directory, then os.replace -- a half-written config is

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/skill_inventory.py (reported line 32)May include surrounding context.

python
its own config open) are retried twice at 0.5s before the error is surfaced.
ERROR CODES: E-LOG (usage log missing/unreadable) · E-ROOT (skills dir not found) ·
E-PLATFORM (unknown --agent) · E-NOCLOSE (host has no programmatic close channel) ·
E-CONF (settings.json read/write failed; nothing modified) · E-READ (one skill dir unreadable, skipped).
AUTONOMOUS RESIDENCY: none (no cron, startup script or daemon; no self-modification). This tool
performs no autonomous execution. It does perform two user-consented, reversible cross-session
writes — the "off" entries in skillOverrides (reversible via the host's /skills menu) and the

Static analysis

No suspicious patterns detected.