Back to skill

Security audit

ScienceClaw: Multi-Agent Investigation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with scientific research, but it can automatically mix private workspace memory into externally processed and posted results without clear user approval.

Review this skill before installing. Use it only in workspaces where memory.md does not contain confidential, unpublished, personal, or proprietary research context, and prefer dry-run unless you intentionally want an Infinite post. Verify the ScienceClaw installation path and avoid passing untrusted topic text through a shell command.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:77
Finding

Workspace Memory Disclosure Through External Processing and Default Publication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:28
Finding

Shell Command Injection Through Verbatim Topic Interpolation

Content
View full analysis
" --community ``` ```markdown ### Parameters - `` — the research topic (required). Use the user's exact phrasing. - `--community` — Infinite community to post to (default: `biology`). Choose based on topic: ``` ### Technical Analysis The documented invocation embeds a user-controlled topic directly into a Bash command while explicitly requiring the user's exact phrasing. Enclosing input in double quotes does not make arbitrary text safe for shell evaluation. Bash still evaluates command substitutions such as `$(...)` and backtick substitutions inside double-quoted strings. Embedded quote characters can also terminate the intended argument and introduce additional shell syntax. If an agent constructs and executes the documented command as text, a maliciously crafted research topic can cause Bash to execute attacker-selected commands before `scienceclaw-investigate` receives its arguments. The community value is also represented as an unquoted placeholder. Although the document provides expected community names, it does not explicitly require strict allowlist validation at the command-construction boundary. ### Attack Path 1. An attacker supplies a research topic containing shell syntax, such as a command substitution. 2. The skill instructs the agent to preserve the user's exact phrasing. 3. The agent substitutes that topic into the documented Bash command. 4. Bash parses the resulting command and evaluates the injected substitution or shell metacharacters. 5. The injected command executes with the same operating-system identity and permissions as the agent process. 6. The legitimate Python investigation may then continue, fail, or be altered to conceal the injection. For example, a topic containing a constru ...[truncated 894 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:22
Finding

Execution of Unverified Code From a Mutable Installation Path

Content
View full analysis
/dev/null || true python3 bin/scienceclaw-investigate "" --community ``` ``` ### Technical Analysis The skill trusts either an inherited `SCIENCECLAW_DIR` environment variable or a mutable directory under the user's home directory. It then performs two security-sensitive operations from that location: 1. It sources `.venv/bin/activate` into the current shell. 2. It executes `bin/scienceclaw-investigate`. No provenance, ownership, permission, version, or integrity verification is required. Sourcing the activation script is particularly sensitive because every shell statement in that file executes in the current shell context and can modify environment variables, shell functions, aliases, or process state. The `2>/dev/null || true` suffix suppresses activation errors, reducing visibility into tampering or unexpected installation state. The actual executable and activation script are not included in the audited project, so their behavior cannot be validated from this package. This creates a tool-hijacking boundary: a legitimate-looking skill invocation can execute attacker-controlled logic if the installation path or files have been replaced or redirected. ### Attack Path 1. An attacker gains the ability to influence the process environment, set `SCIENCECLAW_DIR`, or modify the expected home-directory installation. 2. The attacker places a malicious `.venv/bin/activate` or `bin/scienceclaw-investigate` at that location. 3. A user invokes the skill for an ot ...[truncated 1059 chars]
Remediation
View remediation
/dev/null || true`. 8. Use a restricted execution environment with minimal filesystem access, limited network destinations, and only the credentials required for the current task. 9. Log the resolved executable path, verified version, and integrity result before invocation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'When to use' section describes triggers such as 'Investigate a scientific topic' and 'Run a deep scientific analysis' across very broad domains, but it does not define clear exclusions or negative examples. This creates ambiguity about when this specific skill should activate versus other research or analysis skills.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to read workspace memory and append that context into the investigation topic sent to an external toolchain, and results may then be posted to Infinite. This creates a direct natural-language exfiltration path for potentially sensitive project details, research plans, organisms, compounds, or other internal context without clear user approval at the time of disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.