Back to skill

Security audit

ScienceClaw: Post to Infinite

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a clear science-posting workflow, but it can automatically mix local workspace memory into content that may be published publicly.

Install only if you are comfortable with a workflow that can post to Infinite by default. Prefer --dry-run first, review the generated content, and do not allow automatic memory.md context reuse unless you have checked that the memory contains nothing private, unpublished, or identifying.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:96
Finding

Workspace Memory May Be Disclosed to External Services and Public Posts

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:26
Finding

Shell Command Injection Through Verbatim Topic Interpolation

Content
View full analysis
/dev/null || true python3 bin/scienceclaw-post --topic "" [--community ] [--dry-run] ``` ``` The parameter guidance further states: ```markdown - `--topic` — research topic (required). Use the user's exact phrasing. ``` ### Technical Analysis The documented invocation places the user-controlled topic inside a shell command while directing the agent to preserve the user's exact phrasing. If an agent builds a command string by replacing `` textually, embedded quotation marks can terminate the quoted argument. Shell metacharacters, command substitutions, redirections, or additional commands may then be interpreted by the shell. For example, a malicious topic containing a closing quote followed by shell syntax could escape the intended `--topic` argument if inserted without argument-safe encoding. Merely surrounding untrusted input with double quotes is insufficient because embedded double quotes and command-substitution constructs can alter parsing when commands are generated through textual interpolation. The file does not require argument-array execution, robust shell escaping, validation, or separation of data from shell syntax. ### Attack Path 1. An attacker supplies a research topic containing shell control syntax designed to break out of the displayed quoted argument. 2. The agent follows the instruction to use the topic's exact phrasing. 3. The agent substitutes that text into the documented shell command. 4. The shell parses part of the topic as syntax rather than as a single `--topic` value. 5. The injected command executes under the account and environment running the agent. 6. The attacker may read or modify acce ...[truncated 690 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s default behavior is to publish generated content to an external platform, but the description and usage guidance do not prominently warn that execution will post unless --dry-run is used. This creates a real risk of unintended external disclosure of generated research content, user inputs, or derived context, especially in agent-driven workflows where a user may expect a local draft rather than publication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workspace context injection step tells the agent to read memory.md and append stored project context into the topic, but it provides no privacy warning or consent boundary before that context may flow into generated output and be published. This is dangerous because prior workspace notes can contain sensitive research direction, compounds, targets, or organizational context that the user did not intend to disclose in a public post.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This instruction explicitly directs the skill to read workspace memory and append it into the topic, which can propagate prior stored user or project data into LLM prompts, generated summaries, and ultimately public Infinite posts. In this skill’s context, the danger is amplified because the workflow is designed to publish externally by default, turning prompt-context reuse into a concrete data-leak path rather than a purely internal prompt-handling issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.