Back to skill

Security audit

Update Docs

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a local documentation-update workflow and does not show hidden execution, exfiltration, persistence, or destructive behavior.

Install only if you want an agent to inspect repository diffs and help edit documentation. Review planned edits before approving them, and treat the bundled packaging/scaffolding scripts as optional developer utilities rather than part of the normal docs-update workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

The code is related to documentation impact analysis, so it overlaps with the declared theme of checking what docs need updating. However, the declared description promises a broader skill that provides a guided workflow for updating documentation, reviewing completeness, syncing docs with code, and scaffolding docs for features. The actual code only performs a narrow static analysis of changed files in git and flags files under specific hardcoded paths as documentation-relevant. It neither updates docs nor guides the user through documentation changes, and it is tightly coupled to branch diffing and repository path inspection. Therefore the description overstates and materially differs from the implemented behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose describes a workflow for reviewing code changes and determining or scaffolding documentation updates. The actual code does not inspect code changes, documentation, PRs, MDX, or .md content for completeness or impact. Instead, it performs local filesystem setup by creating directories and placeholder files for a skill skeleton. That is a materially different primary purpose and introduces undeclared file-creation capabilities. While this may support building the skill itself, it does not implement the described documentation-update behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes a documentation-oriented skill that should help determine what docs need updating and guide documentation work based on code changes. The actual code does not inspect code changes, documentation files, PRs, or generate/update docs. Instead, it validates the presence and format of SKILL.md, checks allowed directories, extracts a skill name, and zips the skill into a distributable .skill file. This is a materially different primary purpose and introduces undeclared packaging/build behavior unrelated to the described documentation workflow.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/CODE-TO-DOCS-MAPPING.md (reported line 87)May include surrounding context.

md
### New Skill
1. Create skill in `skills/new-skill/`
2. Create documentation at `docs/skills/new-skill.md`
3. Update skill index page if applicable

### New API Function
1. Add function to `src/api/`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to use shell commands (git diff) and to read and update repository files, but it declares no tool restrictions such as allowed-tools or permissions. That creates an authority gap where the runtime may grant broader capabilities than users expect, increasing the chance of unintended repository inspection or modification during a docs-focused task.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/CODE-TO-DOCS-MAPPING.md (reported line 79)May include surrounding context.

md
| Attribute   | When to Use                       | Example                   |
| ----------- | --------------------------------- | ------------------------- |
| `filename`  | Always for code examples          | `filename="skills/my-skill/SKILL.md"` |
| `switcher`  | When providing multiple variants  | `switcher`                |
| `highlight` | To highlight specific lines       | `highlight={1,3-5}`       |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/DOC-CONVENTIONS.md (reported line 62)May include surrounding context.

md
| Attribute   | When to Use                       | Example                   |
| ----------- | --------------------------------- | ------------------------- |
| `filename`  | Always for code examples          | `filename="skills/my-skill/SKILL.md"` |
| `switcher`  | When providing multiple variants  | `switcher`                |
| `highlight` | To highlight specific lines       | `highlight={1,3-5}`       |

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/analyze_changes.py (reported line 18)May include surrounding context.

python
def run_git_command(args):
    """Run git command and return output."""
    try:
        result = subprocess.run(
            ["git"] + args,
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/analyze_changes.py (reported line 38)May include surrounding context.

python
for branch in base_branches:
        try:
            # Check if branch exists
            subprocess.run(["git", "rev-parse", "--verify", branch], 
                         capture_output=True, check=True)
            diff_cmd = ["diff", f"{branch}...HEAD", "--name-only"]
            changed_files = run_git_command(diff_cmd)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for analyzing and updating documentation based on code changes, but this file implements a CLI utility that validates skill structure and creates distributable .skill archives. Creating installable packages for distribution is a separate build/release capability, not an obvious requirement for reviewing or updating documentation content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring states that the script 'Package[s] the update-docs skill into a distributable .skill file' and validates skill structure for sharing and installation. That documented intent conflicts with the skill manifest, which says the skill should help update OpenClaw documentation based on code changes rather than build distributable artifacts.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/update_docs.py (reported line 19)May include surrounding context.

python
def run_git_command(args):
    """Run git command with error handling."""
    try:
        result = subprocess.run(['git'] + args, capture_output=True, text=True, check=True)
        return result.stdout.strip()
    except subprocess.CalledProcessError as e:
        print(f"Git command failed: {' '.join(args)}", file=sys.stderr)

Static analysis

No suspicious patterns detected.