Back to skill

Security audit

OEM/ODM RFQ Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent RFQ drafting assistant with only modest, disclosed workflow risks rather than hidden or malicious behavior.

Review generated replies before sending, especially if the buyer wrote in another language or included Markdown/HTML-like content. If you use the helper script, treat its Markdown output as a draft and avoid rendering untrusted RFQ fields in a viewer that automatically loads remote content. Publishers should pin any CLI tooling they install globally.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:76
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis

Vulnerability Details

File Location: README.md:76
Vulnerability Type: Supply-chain risk caused by an unpinned global dependency
Risk Level: Medium

Vulnerable Code

bash
npm i -g clawhub

Technical Analysis

The publishing instructions install the latest available version of the third-party clawhub package globally. No exact version, package integrity value, lockfile, or other verification mechanism is specified.

Consequently, the executable package installed by a user can differ from the version that was available when this project was audited. An upstream account compromise, malicious package release, or unexpected behavioral change could introduce arbitrary executable code. npm lifecycle scripts may run during installation, and a global installation increases exposure by making the resulting CLI available system-wide for the affected user.

This finding does not establish that the current clawhub package is malicious. It identifies an unsafe dependency installation practice that leaves future package contents outside the reviewed trust boundary.

Attack Path

  1. An attacker compromises the package publisher or otherwise causes a malicious future version of clawhub to be distributed through the configured npm registry.
  2. A user follows the documented publishing instructions and executes npm i -g clawhub.
  3. npm resolves the current package version rather than a previously reviewed version.
  4. Malicious package code or lifecycle scripts execute with the permissions of the user running npm.
  5. The globally installed CLI remains available for later invocation and may perform additional attacker-controlled behavior.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Depending on that user's access, this may expose project files, source code, authentication tokens accessible to the process, and ot ...[truncated 329 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to an exact reviewed version, for example npm install --global clawhub@X.Y.Z.
  • Document the expected package registry, publisher, and reviewed package version.
  • Verify package provenance and integrity before installation where the package ecosystem supports it.
  • Prefer a project-local development dependency governed by a committed lockfile instead of a global installation.
  • Disable lifecycle scripts during installation when they are not required, then invoke only reviewed package entry points.
  • Establish a dependency-update process that reviews package contents and release changes before updating the documented version.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/rfq-brief.mjs:108
Finding

Untrusted RFQ Values Are Embedded into Markdown Without Escaping

Content
View full analysis

Vulnerability Details

File Location: scripts/rfq-brief.mjs:108-112
Vulnerability Type: Markdown and HTML content injection
Risk Level: Low

Vulnerable Code

js
for (const [key, label] of section.fields) {
  const present = has(data[key]);
  const value = present ? String(data[key]).trim() : TBC;
  const status = present ? 'confirmed' : 'to confirm';
  out.push(`| ${label} | ${value} | ${status} |`);
}

Technical Analysis

Values originating from RFQ JSON are converted to strings and inserted directly into Markdown table cells. The code does not escape Markdown table delimiters, line breaks, link syntax, image syntax, or raw HTML.

An attacker who controls an inbound RFQ value can therefore alter the structure and rendered meaning of the generated report. Depending on the downstream Markdown renderer, crafted input could add deceptive rows, external links, raw HTML, or remote image references. A remote image may disclose viewer metadata such as an IP address and request timing when the document is opened in a renderer that automatically loads external resources.

This is a document-content injection issue rather than shell command injection. The reviewed script does not evaluate the generated text as code, launch subprocesses, or transmit it over the network itself.

Attack Path

  1. An attacker submits an RFQ containing crafted Markdown or HTML in a supported field, such as company, productType, or email.
  2. That value is copied into the structured JSON supplied to rfq-brief.mjs.
  3. The script inserts the value into a Markdown table without contextual escaping.
  4. The generated Markdown is opened or forwarded using a renderer that interprets the injected syntax.
  5. The attacker-controlled content changes the displayed report, presents a deceptive link, or causes an external resource request if remote content is enabled.

An illustrative input shape is:

json
{
  "co
...[truncated 707 chars]
Remediation
View remediation

Remediation Suggestions

  • Add a dedicated escaping function for all untrusted values before inserting them into Markdown.
  • Escape table delimiters such as |, normalize or encode line breaks, and neutralize Markdown link, image, and raw HTML syntax.
  • Consider rejecting raw HTML and image syntax entirely because RFQ fields are expected to contain plain text.
  • Apply length limits and type validation to every supported input field.
  • Render output using a Markdown configuration that disables raw HTML and automatic external-resource loading.
  • Add tests covering pipes, multiline values, links, images, HTML tags, control characters, and unusually long input.

A minimal table-cell hardening pattern could normalize line breaks and escape delimiters:

js
function escapeMarkdownCell(value) {
  return String(value)
    .replace(/\r?\n/g, ' ')
    .replace(/\|/g, '\\|')
    .replace(/</g, '<')
    .replace(/>/g, '>');
}

The final implementation should be matched to the exact capabilities and security configuration of the downstream Markdown renderer.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
node scripts/rfq-brief.mjs path/to/inquiry.json # or pipe JSON via stdin

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
node scripts/rfq-brief.mjs path/to/inquiry.json # or pipe JSON via stdin

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Mandating English output without user choice can cause the skill to ignore user language preference and potentially transform buyer communications into a different language than requested. In a business workflow this can create confidentiality, accuracy, or compliance issues if the output is forwarded without proper review, though the impact is limited compared with direct code-execution or data-exfiltration flaws.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation example is broad enough that the skill may trigger on ordinary drafting or reply-assistance requests, causing unintended processing of user content as an RFQ workflow. This is not a classic security bug, but it is a genuine prompt-scope issue because it can override user intent, apply the wrong workflow, and increase exposure of sensitive business correspondence to an unnecessary skill context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description requires a "professional English reply draft," and the output section later specifies a ready-to-send English email. This forces a specific language without user opt-in or a documented policy reason that the skill must operate only in English.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance includes phrases like "help me quote this" and broadly refers to a rough requirement the user wants turned into a professional reply. These are common business-assistance requests and the file does not provide exclusion conditions or tighter boundaries to distinguish when this skill should activate versus a more general writing or sales skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heading 'English reply templates' specifies a fixed language for responses. Under the policy rules, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.