Back to skill

Security audit

skill-distributor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its distribution purpose, but it handles GitHub publishing and credentials in ways that users should review before installing.

Install only if you are comfortable with a skill that can write distribution files and help publish externally. Do not paste a GitHub token into chat or allow it to be stored in a remote URL; use GitHub CLI or a credential helper instead. Review diffs before overwriting README.md or pushing, and pin or preinstall the ClawHub CLI before running validation or publish commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/validate-skill.sh:91
Finding

Unpinned npm Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/validate-skill.sh:91-102; related instructions in SKILL.md:184-199 and distro/platforms/clawhub-publish.md:11-15
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code

bash
# Check clawhub CLI
if command -v npx >/dev/null 2>&1; then
    echo "✅ npx available (clawhub CLI)"
else
    echo "⚠️  npx unavailable; install Node.js"
fi

# Check login status
if npx clawhub whoami >/dev/null 2>&1; then
    echo "✅ Logged in to ClawHub"
else
    echo "⚠️  Not logged in to ClawHub; run: clawhub login"
fi

The associated installation and publication instructions use:

bash
npm install -g clawhub
clawhub login

npx clawhub --workdir . skill publish . \
  --name "<skill-name>" \
  --version "1.0.0" \
  --changelog "Initial release"

Technical Analysis

The Skill executes clawhub through npx without specifying an audited package version. If the package is not already installed locally, npx can retrieve and execute package code from the configured npm registry. The documented global installation command also installs the latest package release without a version or integrity constraint.

Consequently, the code that executes is not fixed to the version reviewed with this Skill. A compromised npm account, malicious replacement release, registry compromise, dependency compromise, or unexpected upstream update could alter the effective executable payload after the Skill has passed review.

The validation script makes this risk less apparent because a nominal login-status check can initiate third-party package resolution and execution. A validation operation should not implicitly install or execute mutable remote code.

Attack Path

  1. An attacker compromises the clawhub package, one of its dependencies, or the package publication account, and publishes a malicious ...[truncated 1173 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a reviewed version, for example:

    bash
    npx --yes clawhub@<reviewed-version> whoami
    
  2. Prefer a preinstalled, verified executable during validation:

    bash
    if command -v clawhub >/dev/null 2>&1; then
        clawhub whoami
    else
        echo "clawhub is not installed"
    fi
    
  3. Use npx --no-install where supported so validation cannot download a missing package.

  4. Require explicit user approval before any dependency installation or remote package execution.

  5. Pin transitive dependencies through a lockfile for locally managed installations.

  6. Verify package provenance, checksums, signatures, and publisher identity before installation.

  7. Run publishing tools in a constrained environment with minimal filesystem access and only the credentials needed for that publication.

  8. Document the exact supported CLI version instead of recommending an unconstrained global installation.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:289
Finding

GitHub Token Embedded in Persistent Git Remote URL

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:289-305
Vulnerability Type: Plaintext credential exposure and insecure authentication handling
Risk Level: High

Vulnerable Instructions

markdown
### Step 8: GitHub push (when a Token is provided)

**Prerequisites**: The user provides a GitHub Token and username

**Operations**:
1. Copy distro/github/README.md to the repository root
   ```bash
   cp distro/github/README.md README.md
   ```
2. Initialize a Git repository if needed
3. Set remote: `https://github.com/<username>/<repo>.git`
4. Add the Token to the URL:
   `https://<token>@github.com/<username>/<repo>.git`
5. Git add → commit → push
6. Output the repository URL

Technical Analysis

Placing an access token in a Git remote URL stores the credential as part of repository configuration when that URL is assigned through git remote add or git remote set-url. The plaintext token may consequently appear in .git/config, git remote -v output, diagnostic reports, filesystem backups, terminal history, process arguments, Agent logs, or copied repository metadata.

The workflow also instructs the user to provide the GitHub token to the Agent. Unless the surrounding platform supplies a protected secret-input mechanism, the credential may become part of conversation history or execution logs. This conflicts with the later warning not to expose the token in logs or conversation.

A GitHub token is a bearer credential. Anyone obtaining it can perform operations permitted by its scopes without knowing the account password.

Attack Path

  1. The user provides a GitHub token to the Agent as requested by the Skill.
  2. The Agent constructs a remote URL containing that token.
  3. The credential-bearing URL is assigned to the Git remote and persists in .git/config, or is exposed through command history, process inspection, or logs.
  4. Another local us ...[truncated 1034 chars]
Remediation
View remediation

Remediation Suggestions

  1. Never embed a token in a Git remote URL. Keep the remote credential-free:

    bash
    git remote set-url origin https://github.com/<username>/<repo>.git
    
  2. Authenticate with GitHub CLI or an operating-system credential helper:

    bash
    gh auth login
    gh auth setup-git
    git push origin main
    
  3. Obtain credentials through the hosting platform's protected secret store rather than conversation text, command-line arguments, or ordinary environment output.

  4. Prefer short-lived, fine-grained tokens restricted to the target repository and minimum required permissions.

  5. Prevent commands, URLs, and environment variables containing secrets from being printed or logged.

  6. After any accidental use of a credential-bearing remote, immediately replace the remote URL, revoke and rotate the token, and inspect logs and backups for residual copies.

  7. Add an automated preflight check that rejects remotes containing credentials:

    bash
    if git remote get-url origin | grep -Eq 'https://[^/@]+@'; then
        echo "Refusing to use a credential-bearing Git remote URL"
        exit 1
    fi
    
  8. Update the Skill instructions so users are never asked to paste GitHub tokens into the conversation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior does not match the actual described/observed actions, including environment or login-state checks and references to tooling/platform validation not clearly declared in the summary. Behavior-description mismatch is dangerous because users may grant file access, shell access, or credentials under false assumptions about what the skill will do.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
读取目标目录下的 `SKILL.md`,验证以下必填字段:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes one-click generation and optional GitHub pushing across many platforms, but does not warn users about potential disclosure of repository contents, generated marketing text based on private material, or filesystem side effects in the distro/ directory. In an agent setting, missing consent and disclosure boundaries can lead users to unintentionally expose sensitive skill metadata or overwrite local outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example invocation "帮我分发这个 Skill:/path/to/your-skill/" describes activation in natural language without clearly constraining the exact trigger phrase or distinguishing it from ordinary conversational requests. The README does not provide explicit trigger boundaries, alternative accepted forms, or negative examples, which could lead to unintended invocation in general chat.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are broad natural-language requests such as '一键发布' and '帮我发到各平台', which are likely to match ordinary user intent beyond this specific skill. Over-broad triggers can cause accidental activation in unrelated contexts, leading to unintended file writes, shell usage, or credential solicitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill asks the user to provide a GitHub token for automated push, but does not present a strong user-facing warning about secret handling, scope minimization, storage, or exposure risks. In this context the danger is heightened because the same skill also has Bash and Write capabilities, so a token could be exposed in shell history, process lists, logs, generated files, or remote URLs if handled unsafely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs use of npx clawhub without pinning a specific package version, which can fetch whatever version is current at execution time. This creates a supply-chain risk: a compromised or breaking upstream release could execute unexpected code or alter publishing behavior when the user runs the command.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions explicitly copy distro/github/README.md over the repository root README.md and emphasize that it 'must' overwrite, without requiring confirmation or warning about destroying existing user content. This can cause unintended data loss, repository defacement, or accidental replacement of curated documentation in the target project.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example trigger phrase is broad enough to resemble ordinary user conversation, which can cause the skill to activate unintentionally or in contexts the user did not clearly intend. In a distribution-oriented skill that can read a skill directory, generate files, and optionally push to GitHub, accidental invocation increases the risk of unintended file processing or publication workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template promotes extracting colleagues' AI-usage information from WeChat group text and screenshots into CSV without any mention of consent, minimization, legal basis, or privacy safeguards. This creates a real privacy and surveillance risk because it encourages collection and processing of potentially sensitive employee behavioral data in a workplace context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs the user to run a publish command that releases the skill to an external platform and relies on prior authentication, but it does not clearly warn that local package contents, metadata, and possibly repository-linked information will be uploaded. In a distribution skill, this omission is material because users may execute the command assuming it is a local packaging step rather than a public release action.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script emits all user-facing status and error messages in Chinese and includes Chinese-only inline guidance, but there is no indication that the skill is region-specific or that users can opt into a locale. That creates a natural-language policy concern because the skill effectively forces a specific language for interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A local validation script should primarily inspect the skill contents, but this code also performs an external login-state check against ClawHub. That expands the trust boundary, causes network-dependent side effects, and may unexpectedly execute third-party tooling or leak environment/account context when users only intended an offline content validation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The script invokes npx clawhub whoami without pinning a specific package version, so execution may fetch and run whatever package/version is currently resolved from the registry. In a validation script, this creates supply-chain risk and unexpected remote code execution during what should be a local pre-publish check.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents the skill description and usage entirely in Chinese, including the example invocation, without indicating that other languages are supported or that Chinese is a deliberate opt-in requirement. This can conflict with language-choice expectations when the skill is distributed on broader platforms.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents all usage instructions, headings, and support text exclusively in Chinese. Under the policy rule, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents the skill description and usage entirely in Chinese, including a slogan that implies the expected interaction mode, without stating that other languages are supported or optional. Under the language/locale policy, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
61% confidence
Finding

The file presents the template and embedded skill description entirely in Chinese, including the required description format, without indicating whether other languages are supported or whether Chinese is required for a specific regional context. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern unless the locale restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains user-facing content exclusively in Chinese, and there is no indication that users may choose another language or that the skill is explicitly limited to a Chinese-speaking audience. Under the natural-language policy rule, forcing a specific language without user opt-in can be a locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written as a fixed Chinese-language promotional template, with no indication that users may choose another language or that the locale restriction is intentional and justified. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

SQP-3 适用于所有文件。该文档全部以中文编写,且未说明这是仅面向中文使用者的区域化文档,也未提供其他语言选项;若该规范作为通用平台格式说明使用,可能构成未声明的语言/locale 限制。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该 markdown 文件适用 SQP-1。L015 在 description 示例中仅写明“触发词:关键词1、关键词2”,属于泛化的触发词占位说明,没有约束触发词应如何避免与日常表达冲突,也没有给出负例或限定上下文,容易导致后续技能作者编写出过于宽泛的触发条件。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The inline documentation at L090 describes a CLI availability check, but after merely warning when npx is unavailable, the script still proceeds to run npx clawhub whoami. This creates a mismatch between the documented intent of staged validation and the actual behavior of attempting command execution even when the prerequisite is missing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.