Back to skill

Security audit

Domain availability API built for AI agents. Check single domains, explore names across .com/.io/.ai/.dev/etc, filter by budget, get smart suggestions. Returns proper JSON/TXT with correct Content-Type headers.

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it can spend money and change live domain settings without clearly requiring confirmation first.

Install only if you are comfortable letting an agent interact with a real domain registrar. Before any purchase, DNS deletion, nameserver change, unlock, transfer, recovery, or auto-renew change, require the agent to show the exact domain, price or setting, payment method, token use, and expected service impact, then get your explicit confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned Global Installation of a Third-Party CLI Package

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 17–20
Vulnerability Type: Supply-chain exposure through a mutable dependency
Risk Level: Medium

Vulnerable Code

bash
# Install CLI
npm install -g clawdbot@latest

Technical Analysis

The publishing instructions direct users to install the mutable latest release of the third-party npm package clawdbot globally. The project does not pin an audited version, provide an integrity hash or lockfile, or document a provenance-verification procedure.

Because npm packages can execute lifecycle scripts during installation, a future compromised or malicious release selected by the latest tag could execute code on the user's machine. Global installation also increases the affected scope compared with an isolated, project-local dependency.

The instructions subsequently invoke the clawhub command even though the installed package is named clawdbot. This may be legitimate, but the package-to-executable relationship is not documented, making it harder for users to verify that the expected package supplies the command.

Attack Path

  1. An attacker compromises the clawdbot npm publisher account, package repository, release pipeline, or one of its transitive dependencies.
  2. The attacker publishes a malicious package version and assigns it the mutable latest distribution tag.
  3. A user follows the documented command:
    bash
    npm install -g clawdbot@latest
    
  4. npm downloads the attacker-controlled release and may execute its lifecycle scripts during installation.
  5. Malicious code executes with the privileges of the user running npm and can modify resources accessible to that account.
  6. The globally installed package or executable can remain available for later use until removed.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the installing user's privileges. The attacker could access or modify user-readable files, devel ...[truncated 463 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable latest tag with an exact, reviewed package version:
    bash
    npm install -g clawdbot@1.2.3
    
  2. Verify the selected release's publisher identity, provenance, signatures, and integrity before recommending it.
  3. Document explicitly that the clawdbot package supplies the clawhub executable, if that relationship is intentional.
  4. Prefer a project-local, locked installation over a global installation where practical.
  5. Commit an appropriate lockfile when dependencies are managed as part of the project and enforce integrity checks in CI.
  6. Consider running the CLI through a restricted environment or container with only the permissions required for publishing.
  7. Review package lifecycle scripts and transitive dependencies before updating the pinned version.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The documented DELETE endpoint enables direct deletion of DNS records through a simple parameterized request, and the skill provides no safeguards such as verification, preview, or confirmation patterns. In an autonomous-agent setting, this is dangerous because a malformed, inferred, or maliciously influenced record ID could remove critical DNS entries and immediately disrupt web, email, or verification services.

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

Delete a record:

text
DELETE /api/manage/{domain}/dns?id=123

Supported record types: A, AAAA, CNAME, MX, TXT, NS, SRV

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README provides a streamlined workflow for purchasing domains and changing DNS or nameservers, but it does not warn that these actions can incur real charges, transfer control, or immediately disrupt live services. In an agent-skill context, omission of confirmation and safety guidance increases the chance that an autonomous or semi-autonomous agent performs irreversible or high-impact actions without adequate user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents a complete purchase flow for domain registration, including payment via Stripe or x402, but does not require an explicit confirmation or present a clear warning that the action incurs real-world charges. In an agent context, this increases the risk of unintended purchases if a user asks casually about buying or if the model over-acts on ambiguous instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes sensitive domain-management actions such as changing DNS, updating nameservers, unlocking domains, and transfer preparation without warning about outage risk or requiring confirmation. These operations can break website resolution, email delivery, or transfer protections if an agent executes them on partial or mistaken user input.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.