Back to skill

Security audit

Version Decider

Security checks for vulnerabilities and agentic risk

Overview

This is a local SemVer version recommendation skill with disclosed read-only project inspection and no hidden network use, persistence, or destructive behavior found.

This skill is reasonable to install if you want a local helper for deciding SemVer bumps. Expect it to read version metadata, ask about breaking changes, and run its Python script. Treat the i18n plan's publish/tag/push notes as maintainer documentation, not normal runtime instructions, and only allow release-management actions when you explicitly asked for them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should decide the next SemVer version for an upcoming release based on scope of code changes. The actual code chunk does something entirely different: it parses a markdown file, extracts frontmatter fields like description and when_to_use, estimates token usage, and prints documentation-maintenance diagnostics. The script itself explicitly states it is a dev/maintenance-only helper and is never invoked for release-decision questions. This is a materially different primary purpose, with unrelated inputs, outputs, and triggers. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- This skill's `SKILL.md` and `references/` are **English by default** (ClawHub Natural Language Policy: English default).

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says this skill is for deciding the next SemVer recommendation only, not general release or project-management tasks. This plan explicitly includes running publish gates, tagging, pushing to remote, and creating a release, which are software release-management capabilities not justified by a deterministic version-decision skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description emphasizes deciding the next version from the scope of code changes and highlights a deterministic arithmetic core. However, the documented behavior also includes reading project files and git tag output to discover the current version, which extends beyond pure change-scope arithmetic and can vary by repository state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

For a version-decision skill, reading files is clearly justified, but granting a general Bash(python*) tool and documenting shell commands such as git tag introduces broader execution capability than the purpose itself requires. This is not obviously necessary for recommending a version when the user can provide the current version directly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest frames the skill as a deterministic arithmetic core for deciding SemVer bumps from code-change scope. This document adds locale autodetection via LC_ALL/LANG, which is a user-environment inspection capability unrelated to the actual version-decision logic and only tangentially related to output localization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file includes a Chinese-only explanatory sentence, and the script's user-facing output strings are also in Chinese elsewhere in the file. For a general-purpose maintenance tool, this imposes a specific language/locale without any opt-in or alternative, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.