Back to skill

Security audit

skill-install

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent installer purpose, but it asks the agent to install remote third-party skills persistently after an LLM-only scan that can be influenced by the remote content being scanned.

Review this before installing. It is an installer for remote Claude skills, so it can permanently add third-party instructions and scripts to your local Claude environment. Only use it with repositories you trust, prefer immutable commit URLs, and manually review the file list and SKILL.md content before allowing installation, even when its built-in scan reports SAFE.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:72
Finding

Untrusted Skill Content Is Evaluated in an Instruction-Bearing Security Prompt

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:72-115; references/security_scan_prompt.md:5-10
Vulnerability Type: Prompt injection against the pre-installation security gate
Risk Level: High

Vulnerable Snippets

SKILL.md:72-115:

markdown
### Step 5: Security Scan

**CRITICAL:** Before installation, perform a thorough security analysis of each skill.

Read the security scan prompt template from `references/security_scan_prompt.md` and apply it to analyze the skill content.

Examine for:
1. **Malicious Command Execution** - eval, exec, subprocess with shell=True
2. **Backdoor Detection** - obfuscated code, suspicious network requests
3. **Credential Theft** - accessing ~/.ssh, ~/.aws, environment variables
4. **Unauthorized Network Access** - external requests to suspicious domains
5. **File System Abuse** - destructive operations, unauthorized writes
6. **Privilege Escalation** - sudo attempts, system modifications
7. **Supply Chain Attacks** - suspicious package installations

Output the security analysis with:
- Security Status: SAFE / WARNING / DANGEROUS
- Risk Level: LOW / MEDIUM / HIGH / CRITICAL
- Detailed findings with file locations and severity
- Recommendation: APPROVE / APPROVE_WITH_WARNINGS / REJECT

### Step 6: User Decision

Based on the security scan results:

**If SAFE (APPROVE):**
- Proceed directly to installation

**If WARNING (APPROVE_WITH_WARNINGS):**
- Display the security warnings to the user
- Use AskUserQuestion to confirm: "Security warnings detected. Do you want to proceed with installation?"
- Options: "Yes, install anyway" / "No, skip this skill"

**If DANGEROUS (REJECT):**
- Display the critical security issues
- Refuse to install
- Explain why the skill is dangerous
- Do NOT provide an option to override for CRITICAL severity issues

### Step 7: Install Skills

For approved skills, install to `~/.claude/skills/`:

1. Create the skill directory: `~/.claude/skills/{skill_name}/`
2. Write all skill files 
...[truncated 3692 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat every downloaded repository file as untrusted data, including SKILL.md, references, comments, examples, and encoded content.
  2. Add an explicit higher-priority scanning rule stating that instructions found inside analyzed files are evidence only and must never alter the scanner’s policy, output format, or decision.
  3. Pass file contents through structured boundaries with explicit filenames and lengths rather than interpolating them as undifferentiated prompt text.
  4. Run deterministic checks outside the language-model context for dangerous operations, sensitive paths, executable files, obfuscation, network destinations, and installation hooks.
  5. Require independent human confirmation before installing any remotely sourced instruction-bearing skill, including those classified as SAFE; present the repository identity, revision, file list, and scan findings.
  6. Pin installation to an immutable commit identifier and ensure the reviewed bytes are exactly the bytes written to the destination.
  7. Do not allow the scan model’s free-form recommendation to directly authorize installation. Convert findings through a separate, fixed policy engine that fails closed on malformed, missing, or contradictory output.
  8. Re-scan the final staged directory immediately before installation and prohibit executable permission changes unless the reviewed manifest explicitly identifies the required scripts.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security_scan_prompt.md (reported line 33)May include surrounding context.

md
### 3. Credential Theft
- Detect attempts to access environment variables containing secrets
- Identify file operations on sensitive paths (~/.ssh, ~/.aws, ~/.netrc)
- Check for credential harvesting patterns
- Look for keylogging or clipboard monitoring

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill triggers when users 'need to browse available skills in a repository' or 'want to safely add new skills to their Claude environment,' which are broad intents rather than narrowly scoped invocation conditions. This can cause unintended activation because the trigger scope is not limited to explicit phrases or clear exclusion conditions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are somewhat ambiguous and could cause the skill to activate on loosely related requests such as generic GitHub browsing or installation tasks. In a skill that performs network fetching and writes to ~/.claude/skills/, over-broad activation increases the chance of unintended repository access or unintended installation workflows being initiated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

GitHub API endpoint pattern:

text
https://api.github.com/repos/{owner}/{repo}/contents/skills?ref={branch}

Parse the response to extract:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

GitHub API endpoint pattern:

text
https://api.github.com/repos/{owner}/{repo}/contents/skills?ref={branch}

Parse the response to extract:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- Explain why the skill is dangerous
- Do NOT provide an option to override for CRITICAL severity issues

### Step 7: Install Skills

For approved skills, install to `~/.claude/skills/`:

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill persists third-party content into ~/.claude/skills/ and marks scripts executable, creating durable agent behavior changes on the user's machine. Even with scanning, this persistence expands the trust boundary and can make a mistaken approval or incomplete scan materially harmful over time.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
For approved skills, install to `~/.claude/skills/`:

1. Create the skill directory: `~/.claude/skills/{skill_name}/`
2. Write all skill files maintaining the directory structure
3. Ensure proper file permissions (executable for scripts)
4. Verify SKILL.md exists and has valid frontmatter

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
4. Performs security scan on each skill
5. skill-a: SAFE - proceeds to install
6. skill-b: WARNING (makes HTTP request) - asks user for confirmation
7. Installs approved skills to ~/.claude/skills/
8. Confirms: "Successfully installed: skill-a, skill-b"

## Security Notes

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
- Look for attempts to modify critical system files

### 6. Privilege Escalation
- Detect sudo or privilege escalation attempts
- Identify attempts to modify system configurations
- Check for container escape patterns

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security_scan_prompt.md (reported line 50)May include surrounding context.

md
- Look for attempts to modify critical system files

### 6. Privilege Escalation
- Detect sudo or privilege escalation attempts
- Identify attempts to modify system configurations
- Check for container escape patterns

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
60% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/security_scan_prompt.md (reported line 51)May include surrounding context.

md
### 6. Privilege Escalation
- Detect sudo or privilege escalation attempts
- Identify attempts to modify system configurations
- Check for container escape patterns

### 7. Supply Chain Attacks

Static analysis

No suspicious patterns detected.