Back to skill

Security audit

ScienceClaw: Watch (Live Collaboration)

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its scientific workflow purpose, but it has under-scoped workspace memory access and an unsafe shell-template pattern for user topics.

Review before installing. Use only with trusted topics and consider disabling the memory.md context step unless the user explicitly approves the exact context being added. The command template should pass the topic as a structured argument or safely escaped value rather than interpolating raw user text into shell source.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:105
Finding

Unnecessary Workspace Memory Access and Context Disclosure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 105–111
Vulnerability Type: Excessive access to persistent workspace information
Risk Level: Medium

Vulnerable Code

markdown
## Workspace context injection

Before running, check if the user's workspace memory contains project context:
- Read `memory.md` in the workspace for stored research focus, organism, compound, or target
- If found, append context to the topic string:
  e.g. `"BACE1 inhibitors [project context: NSCLC, BBB penetration focus]"`

Technical Analysis

The skill instructs the agent to read persistent workspace memory and automatically append information from it to the research topic. Running a multi-agent scientific investigation does not inherently require unrestricted access to persistent workspace memory.

This behavior violates least-privilege principles because it expands the skill's data access beyond the topic explicitly supplied by the user. The appended information becomes part of the input passed to scienceclaw-watch and may consequently be processed by multiple agents or external model services used by that executable.

The instruction does not require explicit user consent, define an allowlist of permissible fields, limit the amount of information extracted, or require the resulting enriched topic to be shown to the user before execution.

Attack Path

  1. A user invokes the skill with an ordinary scientific research topic.
  2. The skill searches the workspace for memory.md.
  3. It reads stored project context, which may include information unrelated to the immediate request.
  4. It appends selected workspace information to the topic string.
  5. The enriched topic is passed to bin/scienceclaw-watch.
  6. The additional information may be exposed to every participating agent and any downstream model provider or service used by the executable.

Impact Assessment

The issue can disclose persistent ...[truncated 497 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not read memory.md by default.
  • Ask for explicit, informed user consent before accessing persistent workspace information.
  • Allow the user to select the exact file and fields that may be used.
  • Apply strict data minimization, such as extracting only an explicitly approved organism, target, or compound name.
  • Display the complete enriched topic and require confirmation before invoking the executable.
  • Prevent secrets, credentials, personal data, and unrelated project details from being appended.
  • Document whether the underlying executable sends prompts to external services and identify the recipients.
  • Avoid saving injected workspace context in output artifacts unless the user explicitly requests it.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:32
Finding

Shell Command Injection Through Verbatim Topic Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32–45
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code

bash
SCIENCECLAW_DIR="${SCIENCECLAW_DIR:-$HOME/scienceclaw}"
TOPIC="<TOPIC>"
N_AGENTS=3
TIMESTAMP=$(date +%Y%m%d_%H%M%S)
OUTPUT_DIR="$SCIENCECLAW_DIR/run_exports/watch_${TIMESTAMP}"

cd "$SCIENCECLAW_DIR"
source .venv/bin/activate 2>/dev/null || true

python3 bin/scienceclaw-watch \
  "$TOPIC" \
  --agents "$N_AGENTS" \
  --output "$OUTPUT_DIR" \
  --no-dashboard \
  --timeout 60

The parameter guidance further instructs the caller to use the user's exact phrasing:

markdown
- `TOPIC` — the research topic (required). Use the user's exact phrasing.

Technical Analysis

Quoting "$TOPIC" when passing the variable to Python protects the later expansion, but it does not protect the earlier construction of the shell assignment if an agent replaces the <TOPIC> placeholder by directly interpolating untrusted user text into the script.

For example, a topic containing a double quote followed by shell syntax can terminate the assignment and introduce a new command. A conceptual malicious topic is:

text
"; attacker_command; #

If substituted verbatim, the assignment becomes conceptually equivalent to:

bash
TOPIC=""; attacker_command; #"

The shell then executes attacker_command before scienceclaw-watch starts. The explicit instruction to use the user's exact phrasing increases the likelihood of direct interpolation without shell-safe encoding.

The vulnerability depends on the execution mechanism materializing this documentation template as shell text. If the implementation instead passes the topic through a structured process API as a separate argument, this specific injection path would not apply.

Attack Path

  1. An attacker supplies a scientific topic containing a quote, command s ...[truncated 1016 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not generate a shell script by interpolating the user-controlled topic into source text.

  • Invoke the executable through a structured process API and pass the topic as a distinct argument without a shell.

  • If shell execution is unavoidable, place the topic in an environment variable or positional parameter supplied by the process launcher rather than embedding it in the script.

  • Apply robust shell escaping, such as Bash-compatible %q, at the final command-construction boundary.

  • Validate the number of agents and timeout as bounded integers.

  • Use an argument array where supported, for example:

    bash
    args=(
      "$TOPIC"
      --agents "$N_AGENTS"
      --output "$OUTPUT_DIR"
      --no-dashboard
      --timeout 60
    )
    python3 bin/scienceclaw-watch "${args[@]}"
    
  • Clarify in the skill instructions that “use the user's exact phrasing” refers to argument content and does not authorize raw insertion into shell source.

  • Add tests containing quotes, semicolons, command substitutions, newlines, and shell metacharacters to verify that topics remain inert data.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to read workspace memory and to save session outputs and figures to disk, but it does not require clear user notice or consent for that data access and persistence. In a multi-agent scientific workflow, workspace notes may contain sensitive project context, and writing summaries or figures to disk can unintentionally retain or expose proprietary or confidential information beyond the immediate chat session.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.