Back to skill

Security audit

Clawdbot Knowledge

Security checks for vulnerabilities and agentic risk

Overview

This skill bundles overbroad orchestration code with persistent agent-behavior instructions, local/private data indexing plans, plaintext credential material, and unsafe operational examples that require review before installation.

Install only after review and cleanup. Remove or quarantine AGENTS.md, BOOTSTRAP.md, AGI/autonomy memory files, and unrelated runbooks; rotate any exposed tokens; require explicit opt-in before sending task content to Flowise or indexing local files; and replace curl-pipe, root-cron, raw execute_command, and inline-secret examples with safer scoped workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
AGENTS.md:7
Finding

Workspace Instructions Hijack Agent Identity and Poison Persistent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/deep_master_agent.py:98
Finding

Arbitrary Task Content Is Transmitted to an External Flowise Server

Content
View full analysis
Dict[str, Any]: """ Sendet Anfrage an Flowise Content Recognition Workflow """ if not self.flowise_api_key: self.logger.warning("Flowise nicht konfiguriert - verwende erweiterten Fallback") return self._enhanced_fallback_recognition(payload.get("content", "")) try: # Verwende den Simple Flowise Server API url = f"{self.flowise_url}/api/v1/prediction/content-recognition" headers = { "Authorization": f"Bearer {self.flowise_api_key}", "Content-Type": "application/json" } # Payload für Simple Flowise Server flowise_payload = { "question": payload.get("content", "") } async with aiohttp.ClientSession() as session: async with session.post( url, json=flowise_payload, headers=headers, timeout=30 ) as response: ``` Invocation with arbitrary task content: ```python async def orchestrate_task(self, task: Dict[str, Any]) -> List[Dict[str, Any]]: """ Hauptorchestierung: Analysiert Content, lädt Module, berechnet Synergien """ try: self.stats["tasks_processed"] += 1 self.logger.info(f"🎯 Orchestriere Task: {task.get('module', 'auto-detect')}") # 1. Content Recognition via Flowise content = task.get("content", "") recognition = awa ...[truncated 2042 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
2026-02-20.md:11
Finding

Plaintext Gateway Authentication Token Is Committed in a Memory Log

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
Administrator_Guide.md:67
Finding

Installation Guide Executes an Unpinned Remote Script Through a Shell

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
DEPLOYMENT_GUIDE.md:320
Finding

Backup Installation Command Replaces the Entire Root Crontab

Content
View full analysis
$BACKUP_DIR/clawd_db_${TIMESTAMP}.sql.gz # Cleanup old backups (keep 30 days) find $BACKUP_DIR -name "clawd_db_*.sql.gz" -mtime +30 -delete # Upload to S3 (optional) # aws s3 cp $BACKUP_DIR/clawd_db_${TIMESTAMP}.sql.gz \ # s3://your-bucket/backups/ echo "✅ Backup completed: $BACKUP_DIR/clawd_db_${TIMESTAMP}.sql.gz" SCRIPT chmod +x /usr/local/bin/backup-clawd-db.sh # Schedule with cron echo "0 2 * * * /usr/local/bin/backup-clawd-db.sh" | sudo crontab - ``` ### Technical Analysis The scheduled backup has a legitimate operational purpose and is not, by itself, evidence of a backdoor. However, `sudo crontab -` replaces root's complete crontab with the content received through standard input. It does not append or safely merge the new job. Following the documented command can silently remove unrelated root jobs, including existing backups, certificate renewal, security scans, monitoring, maintenance, and incident-response tasks. The job is also installed with root privileges even though the database backup may be executable under a dedicated service account. This exceeds least privilege because the task only needs database read/backup permissions and write access to its backup directory, not unrestricted root execution. ### Attack Path 1. An administrator creates the backup script under `/usr/local/bin`. 2. The administrator runs the documented `echo ... | sudo crontab -` command. 3. Cron replaces root's existing schedule with the single supplied line. 4. All previously configured root cron jobs stop running. 5. The new script executes daily with root privileges. 6. If the sc ...[truncated 555 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1231)

Intent-Code Divergence

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file claims templates contain no real keys and that old keys were removed, but elsewhere it presents a live-looking N8N_API_KEY value and explicitly states the key is valid and API-tested. In a skill that integrates MCP, orchestration, and automation infrastructure, exposing or normalizing use of a working automation credential can enable workflow enumeration, abuse of connected systems, and further pivoting.

Content

No source excerpt is available for this finding.

YARA rule 'php_webshell_known': Known PHP webshell families (c99, r57, b374k, WSO, etc.) [webshells]

Critical
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched a known webshell pattern (PHP, Python, JSP, or ASPX webshell).

Content

Scanner excerpt · zusammenfassung prompt.md (reported line 594)May include surrounding context.

md
eue „Super-Module“ erstellen, indem es fest gekoppelte Module zu einer Einheit zusammenfasst, wenn sie ohnehin immer zusammen agieren. Dieser Mechanismus verstärkt effektive Synergien: Was gut zusammenwirkt, wird noch enger integriert und gemeinsam aufgerufen. Gleichzeitig kann DeepAutoSynergy auch ineffiziente Kombinationen entkoppeln – es merkt sich, wenn zwei Module sich oft gegenseitig behindern oder wenig Mehrwert erzeugen, und sorgt dafür, dass diese nur noch getrennt oder mit Vermittlung eingesetzt werden. So entsteht eine Art dynamische Re-Konfiguration der Systemstruktur entsprechend der erlernten Synergien: Erfolgreiche Muster werden Systembestandteile (in Code oder Parametrierung gegossen), effektive Muster werden ausgemustert. Dieses Feature würde die dauerhafte Leistungssteigerung und Selbstorganisation fördern – das System optimiert nicht nur einzelne Module, sondern die Konfiguration seines gesamten Netzwerkes. In gewisser Weise erreicht das AGI damit einen Z

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · 2026-02-05-skill-creation.md (reported line 9)May include surrounding context.

md
## Conversation Summary

user: erstelle diese skills Noch zu erstellen: ContextMaster - Kontext-Verständnis CreativeBoost – Kreativität Fehleranalyse​ UserAdaptation - Benutzeranpassung Wissenssynthese​ EmotionalIntelligence - Emotionale Intelligenz TechExpert - Technisches Fachwissen Projektmanager - Projektmanagement Datenanalyse​ CommunicationMaster - Kommunikation UniversalAdapter - Universalanpassung
[message_id: 4174540f-521d-406b-b41b-d9c72d276b28]
assistant:  It seems like you've provided a detailed configuration for an AI assistant named ClawdBot. Here is a summary of its components:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file exposes a live gateway authentication token in plaintext and includes a direct tokenized localhost URL, which is effectively a credential disclosure. Even if the service is bound to loopback, any local user, local malware, browser history sync, logs, or screenshots could reuse the token to access the gateway, making this sensitive secret exposure unjustified for a memory/skill artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This markdown not only reveals the gateway token in plaintext but also provides a ready-to-use authenticated access link, which lowers the barrier to unauthorized access. In the context of an orchestration skill that integrates agent coordination and management components, exposing a valid gateway credential is especially dangerous because compromise of the gateway may enable broader control or observation of connected tooling.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The quick-start section tells the user to append a full database URL containing the password directly from the command line. This is riskier than editing a local env file manually because command invocations may be exposed through shell history, terminal logging, process inspection, or remote session transcripts, increasing the chance of credential leakage.

Content

Scanner excerpt · ADD_DB_PASSWORD.md (reported line 126)May include surrounding context.

Wenn du das Passwort hast, führe aus:

powershell
# Füge zur .env hinzu (ersetze [PASSWORD])
Add-Content "C:\Download\speakmcp projekt\SpeakMCP\mcp-servers\.env" "`n# Supabase Database Connection`nSUPABASE_DB_URL=postgresql://postgres:[PASSWORD]@db.vufkhfuphdsezilzclwv.supabase.co:5432/postgres"

# Schema ausführen

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

This finding is part of the same PowerShell quick-start snippet that includes the database password inline while writing to .env. Even though the destination file is local, the method encourages insecure handling of credentials and can leak secrets via PowerShell history, clipboard capture, transcript logging, or endpoint monitoring tools.

Content

Scanner excerpt · ADD_DB_PASSWORD.md (reported line 127)May include surrounding context.

powershell
# Füge zur .env hinzu (ersetze [PASSWORD])
Add-Content "C:\Download\speakmcp projekt\SpeakMCP\mcp-servers\.env" "`n# Supabase Database Connection`nSUPABASE_DB_URL=postgresql://postgres:[PASSWORD]@db.vufkhfuphdsezilzclwv.supabase.co:5432/postgres"

# Schema ausführen
cd "C:\Download\speakmcp projekt\SpeakMCP\.claude\skills\deepallspeak\scripts"

Ssd 1

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The autonomy framing semantically instructs the agent to bypass oversight from the outset by declaring no permission is ever needed again. This is especially dangerous in this skill context because orchestration capabilities can amplify a single unsafe instruction into actions across multiple tools, agents, and services.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The repeated directives normalize refusing to ask permission and encourage unrestricted autonomous action. Repetition increases the likelihood that downstream components treat these phrases as priority behavioral rules, which can erode safeguards around approval, scope control, and data/system safety.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file mandates autonomous behavior and forbids permission-seeking, which undermines user choice and informed consent. In a skill intended for orchestration and integration, this can pressure the agent to continue with actions the user has not specifically approved, including tool use and system interactions.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file reinforces a narrative that the agent is already acting and should continue without further approval, effectively creating a standing authorization. In an integration/orchestration skill, this can be exploited to justify continued execution, tool invocation, or state changes without fresh user consent.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · API_DOCUMENTATION.md (reported line 327)May include surrounding context.

Cancel Task

Endpoint: DELETE /tasks/{task_id}

bash
curl -X DELETE \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The documented delete operation represents a high-risk tool action that can remove stored documents, and there is no indication of confirmation, scoping constraints, soft-delete, or human-in-the-loop protection. In an agent skill context, exposing destructive parameters and endpoints without guardrails materially increases the chance of tool abuse, accidental deletion, or malicious prompt-driven misuse.

Content

Scanner excerpt · API_Documentation.md (reported line 208)May include surrounding context.

Delete Document

http
DELETE /api/v1/rag/documents/{document_id}
Authorization: Bearer <token>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · API_Gateway_Documentation.md (reported line 298)May include surrounding context.

md
### JWT Token Security

- **HS256 Algorithm**: Secure HMAC-based signing
- **Configurable Expiration**: Default 24 hours for access tokens
- **Refresh Tokens**: 30-day refresh token support
- **Automatic Validation**: All protected endpoints automatically validate tokens

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · API_SEARCH_GUIDE.md (reported line 55)May include surrounding context.

bash
python3 api_search.py endpoint GET /agents
python3 api_search.py endpoint POST /tasks
python3 api_search.py endpoint DELETE /tasks/123
python3 api_search.py endpoint GET /queue/status

MCP Config Access

High
Category
Agent Snooping
Confidence
89% confidence
Finding

The documented auggie_list_mcp_servers capability exposes discovery of all available MCP servers that can be forwarded to another agent. In an orchestration/integration skill, this increases attack surface by revealing internal tool inventory and enabling selection of sensitive backends for delegated tasks, which can aid privilege escalation or lateral movement if access controls are weak.

Content

Scanner excerpt · AUGGIE_QUICKSTART.md (reported line 116)May include surrounding context.

md
---

### 3. `auggie-slots:auggie_list_mcp_servers`
List all available MCP servers that can be forwarded to Auggie.

**Parameters:** None

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The stated mission is autonomous AGI self-development rather than the declared MCP orchestration purpose. This scope mismatch is dangerous because it normalizes open-ended autonomous behavior and tool use that users would not reasonably expect from the advertised skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file instructs reading every file in a user directory and storing all contents in ChromaDB without narrowing scope to task-relevant data. This is an overbroad data-ingestion pattern that can capture secrets, personal data, tokens, or unrelated private material and persist it in a secondary store.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown directs autonomous collection and persistent storage of all file contents without warning the user about privacy, sensitive data handling, or retention. This omission is dangerous because users are not informed that local data may be bulk-read and copied into a vector database.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Broad instructions to read and store all contents from a user directory into a vector database create a direct data collection and leakage risk. Persistent indexing can expose secrets and private material to later retrieval, search, export, or unintended cross-task access.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The autonomous workflow calls for wholesale ingestion of local files into persistent storage as a routine step. In the context of an agent skill, this creates a strong likelihood of unnecessary exfiltration into long-lived memory and makes accidental disclosure more severe.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file content is materially mismatched with the declared skill purpose: it documents a 'RAG-Enhanced N8N System' rather than the manifest-declared 'mcp-orchestral' integration. In an agent skill ecosystem, this kind of mismatch is dangerous because it can mislead operators into deploying unrelated infrastructure and trusting documentation that may conceal unsupported or risky behaviors.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

Piping a remotely fetched script directly into the shell executes unverified code with elevated privileges and bypasses normal integrity review. In administrator documentation, this is especially risky because readers may execute it verbatim on production systems, enabling supply-chain compromise if the upstream source is tampered with or intercepted.

Content

Scanner excerpt · Administrator_Guide.md (reported line 71)May include surrounding context.

bash
# Install Kubernetes cluster
curl -sfL https://get.k3s.io | sh -

# Verify cluster status
kubectl get nodes

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide explicitly documents a peer-triggered execute_command capability, allowing the connected system to run arbitrary shell commands. In the context of an autonomous bidirectional bridge, this creates a direct remote code execution path with potentially full user-level access, which exceeds a normal orchestration/integration role and materially increases system compromise risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow examples normalize autonomous code generation, file modification, test execution, and deployment without any safety warning or user-consent checkpoint. This can mislead users into enabling highly impactful behaviors as routine operations, increasing the chance of unintended system changes, insecure deployments, or abuse by a compromised peer agent.

Content

No source excerpt is available for this finding.