Back to skill

Security audit

skill-guard w Snyk Agent Scan

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned as a security installer wrapper, but its script has unsafe path handling and mutable runtime dependencies that could affect local files or run unreviewed code.

Review this skill carefully before installing. Its goal is legitimate, but use it only in a disposable or backed-up workspace unless the slug validation, scanner version pinning, safer dependency installation instructions, and machine-readable scan verdict handling are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:97
Finding

Remote Installer Executed Through curl-to-Shell Pipeline

Content
View full analysis
/dev/null 2>&1; then if [[ -f "$HOME/.local/bin/env" ]]; then # shellcheck disable=SC1090 source "$HOME/.local/bin/env" fi if ! command -v uvx >/dev/null 2>&1; then print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh" exit 1 fi fi ``` ### Technical Analysis The installation instructions direct users to download mutable content from an external URL and pipe it directly into `sh`. No version pinning, signature validation, checksum verification, or opportunity for local inspection is provided. HTTPS protects the connection in transit but does not provide reproducibility or protect against compromise of the upstream domain, hosting account, build pipeline, or delivery infrastructure. Although the shell script does not invoke this command automatically, installation instructions are part of the Skill's operational behavior and explicitly encourage remote code execution. ### Attack Path 1. An attacker compromises the upstream installer, its hosting infrastructure, or its release process. 2. A user follows the documented requirement or the error message emitted by `safe-install.sh`. 3. `curl` retrieves the attacker-controlled response. 4. The response is passed directly to `sh` without integrity verification. 5. The payload executes with all permissions available to the invoking user. ### Impact Assessment A compromised response can execute arbitrary commands under the user's account. This can expose readable files, environment variables, credentials, agent configuration, and workspace content. It can also mod ...[truncated 179 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/safe-install.sh:14
Finding

Runtime Execution of an Unpinned Scanner Package

Content
View full analysis
&1) || scan_exit_code=$? ``` ### Technical Analysis The use of `@latest` allows the effective scanner implementation to change after this Skill has been reviewed. Each invocation can resolve and execute a newly published package version without a lock file, fixed version, or verified artifact hash. The scanner process inherits the script's environment. In normal operation, that environment includes `SNYK_TOKEN`, because the script requires the variable before invoking the scanner. A compromised upstream release would therefore execute locally with access to the staged Skill, the process environment, and all resources available to the invoking user. This network access is related to the declared scanning functionality, but executing a mutable package with the full inherited environment exceeds the minimum safe privilege model for that functionality. ### Attack Path 1. An attacker compromises the upstream package account, registry entry, publishing pipeline, or a transitive dependency. 2. A malicious release becomes the version resolved by `snyk-agent-scan@latest`. 3. The user invokes `safe-install.sh`. 4. `uvx` downloads and executes the newly resolved package. 5. The malicious package reads accessible environment variables or local files and performs actions with the user's permissions. ### Impact Assessment The dependency can execute arbitrary code as the invoking user. Potential exposure includes `SNYK_TOKEN`, other inherited environment variables, staged Skill contents, readable workspace files, and user-owned configuration. There is no evidence in the audited source tha ...[truncated 119 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe-install.sh:83
Finding

Path Traversal Through Unvalidated Skill Slug Enables Arbitrary User-Level Deletion

Content
View full analysis
/dev/null || true } ``` ### Technical Analysis Shell quoting prevents word splitting and shell metacharacter injection, but it does not prevent path traversal. A value containing `../` is resolved by the filesystem after being appended to the trusted base directory. The most direct sink is the unconditional `rm -rf` at the start of `stage_skill`. It executes before `clawhub` can reject an invalid slug. For example, a slug such as `../../victim` makes the deletion target resolve outside `/tmp/skill-guard-staging/skills`. Additional risks exist in report creation, cleanup, and the `--f ...[truncated 1146 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe-install.sh:157
Finding

Fail-Open Scanner Result Parsing Can Install Skills with Unrecognized Findings

Content
View full analysis
&1) || scan_exit_code=$? SCAN_OUTPUT="$scan_output" SCAN_EXIT_CODE=$scan_exit_code printf '%s\n' "$scan_output" | tee "$report_path" echo "" if echo "$scan_output" | grep -Eqi "security issues detected|prompt injection detected|malicious code pattern detected|secret found|machine state compromise attempt|third-party content exposure|critical|high risk|medium risk"; then SCAN_STATUS="threats_found" return 0 fi if echo "$scan_output" | grep -Eqi "SNYK_TOKEN|requires authentication|API token|renamed to 'snyk-agent-scan'|command not found|traceback|exception"; then SCAN_STATUS="scanner_unavailable" return 0 fi if [[ $scan_exit_code -ne 0 ]]; then SCAN_STATUS="scanner_unavailable" return 0 fi SCAN_STATUS="clean" return 0 ``` ### Technical Analysis The wrapper infers the security verdict by searching human-readable output for a fixed list of phrases. If the scanner exits successfully but reports a finding using different wording, a new finding type, structured output, localization, or a severity not covered by the regular expression, the wrapper assigns `SCAN_STATUS="clean"`. The `clean` branch subsequently installs the staged Skill. Consequently, unknown successful output is treated as safe rather than indeterminate. This is a fail-open design for a component advertised as a pre-installation security gate. Pinning is also absent, so output wording can change independently when `@latest` resolves a new scanner release. ### Attack Path 1. A staged Skill triggers a scanner finding whose output does not include any phrase in the hardcoded threat regular expression. 2. The scanner exits with status zero, or o ...[truncated 680 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (21)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: skill-guard
description: Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with Snyk Agent Scan pre-flight checks.
---

# skill-guard

**The only pre-install security gate for ClawHub skills.**

## Why skill-guard?

| | **VirusTotal** (ClawHub built-in) | **skillscanner** (Gen Digital) | **skill-guard** |
|---|---|---|---|
| **When it runs** | After publish (server-side) | On-demand lookup | **Before install (client-side)** |
| **What it c

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
t-side)** |
| **What it checks** | Malware signatures | Their database | **Actual skill content** |
| **Prompt injections** | ❌ | ❌ | ✅ |
| **Data exfiltration URLs** | ❌ | ❌ | ✅ |
| **Hidden instructions** | ❌ | ❌ | ✅ |
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

**skill-guard** uses Snyk Agent Scan (the renamed successor to `mcp-scan`) to analyze what's actually in the skill, catches AI-specific threats, and blocks install if issues are found. If the scanner is unavailable or not configured, the wrapper now reports that separately instead of pretending the skill itself is malicious.

## The Problem

Skills can contain:
- 🎭 **Prompt injections** — hidden "ignore previous instructions" attacks
- 💀 **Malware payloa

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## The Problem

Skills can contain:
- 🎭 **Prompt injections** — hidden "ignore previous instructions" attacks
- 💀 **Malware payloads** — dangerous commands disguised in natural language  
- 🔑 **Hardcoded secrets** — API keys, tokens in plain text
- 📤 **Data exfiltration** — URLs that leak your conversations, memory, files

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/safe-install.sh (reported line 121)May include surrounding context.

sh
stage_skill() {
    print_info "Fetching $SKILL_SLUG to staging area..."

    rm -rf "$STAGING_DIR/skills/$SKILL_SLUG"
    mkdir -p "$STAGING_DIR" "$REPORTS_DIR"

    local install_cmd=(clawhub install "$SKILL_SLUG" --workdir "$STAGING_DIR")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/safe-install.sh (reported line 208)May include surrounding context.

sh
stage_skill() {
    print_info "Fetching $SKILL_SLUG to staging area..."

    rm -rf "$STAGING_DIR/skills/$SKILL_SLUG"
    mkdir -p "$STAGING_DIR" "$REPORTS_DIR"

    local install_cmd=(clawhub install "$SKILL_SLUG" --workdir "$STAGING_DIR")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The script prints a manual remediation command rm -rf $STAGING_DIR/skills/$SKILL_SLUG without shell quoting. If a malicious or malformed skill slug contains spaces, glob characters, or shell metacharacters, a user who copy-pastes the suggested command could delete unintended paths or trigger shell expansion. The context is more sensitive because this tool handles untrusted skill identifiers from an external registry.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 252)May include surrounding context.

sh
echo "Options:"
            echo "  1. Review the report and inspect the staged files"
            echo "  2. Run: mv $STAGING_DIR/skills/$SKILL_SLUG $SKILLS_DIR/ to install anyway"
            echo "  3. Run: rm -rf $STAGING_DIR/skills/$SKILL_SLUG to discard"
            echo ""
            exit 2
            ;;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill documentation describes shell-based installation and wrapper script usage, but the manifest declares no explicit tool scope or allowed-tools. In an agent-skill ecosystem, missing capability declarations weakens policy enforcement and makes it harder to constrain what the skill may invoke at runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The scanner command uses uvx snyk-agent-scan@latest, which pulls the latest package version at runtime rather than a pinned, reviewed version. That creates supply-chain risk: a compromised upstream release or breaking behavior change could alter scan results or execute unintended code during security validation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 40)May include surrounding context.

sh
Options:
  --version <ver>  Install specific version
  --force          Overwrite existing installation
  --skip-scan      Skip security scan (not recommended)
  --help           Show this help

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The skill recommends installing a dependency via 'curl ... | sh', which executes remote content directly without prior verification. If the remote host, transport, or script supply chain is compromised, users could run arbitrary code on their machine during setup.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
## Requirements

- `clawhub` CLI — `npm i -g clawhub`
- `uv` — `curl -LsSf https://astral.sh/uv/install.sh | sh`
- `SNYK_TOKEN` — required by Snyk Agent Scan for authenticated scanning

## Why This Matters

External Script Fetching

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The script prints guidance recommending curl -LsSf https://astral.sh/uv/install.sh | sh, which is an unsafe installation pattern because it executes remote script content directly without integrity verification. Even though it is not executed automatically by this script, operators may copy-paste it, exposing them to upstream compromise or man-in-the-middle risk.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 112)May include surrounding context.

sh
source "$HOME/.local/bin/env"
        fi
        if ! command -v uvx >/dev/null 2>&1; then
            print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh"
            exit 1
        fi
    fi

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:22