Back to skill

Security audit

Clawhub Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly about token trading, but it gives agents concrete buy and sell instructions for real-value tokens without requiring explicit user approval or clearly warning about financial loss and transaction finality.

Review this before installing because it can guide an agent to buy or sell tokens using an API key. Only use it if you are comfortable with the agent accessing that trading account, and require explicit confirmation for every trade, including slippage, fees, daily limits, and the possibility of losing money or submitting an irreversible transaction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill provides operational instructions and concrete API calls for buying and selling real tokens, including transaction parameters and strategy guidance, but does not include an explicit warning that trades may cause financial loss, incur irreversible on-chain or platform-side execution, and should only be performed with clear user authorization. In an agent setting, this increases the chance of autonomous or poorly understood trading behavior, especially because the document frames purchases as actionable opportunities and includes buy/sell logic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.