Back to skill

Security audit

Clawhub Skill Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill coherently queries public ClawHub skill metadata and optionally exports it, with a CSV safety caveat but no hidden persistence, credential use, or destructive behavior.

This skill is reasonable to install if you want public ClawHub skill metadata. Be aware it contacts clawhub.ai and can write a CSV file when you pass --export; treat exported CSVs as untrusted public data and avoid opening them with spreadsheet formula execution enabled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clawhub_monitor.py:246
Finding

CSV Formula Injection in Exported Skill Metadata

Content
View full analysis

Vulnerability Details

File Location: scripts/clawhub_monitor.py, lines 246-250
Vulnerability Type: CSV formula injection
Risk Level: Medium

Vulnerable Code

python
with open(output_file, "w", newline="", encoding="utf-8") as f:
    writer = csv.DictWriter(f, fieldnames=fieldnames)
    writer.writeheader()
    for row in skills:
        writer.writerow({k: row.get(k) for k in fieldnames})

The exported fields include remotely sourced package metadata such as name, display_name, owner_handle, and summary. These values are populated from ClawHub API responses in scripts/clawhub_monitor.py, lines 140-163, and reach writer.writerow() without spreadsheet-formula neutralization.

Technical Analysis

CSV quoting protects the file structure but does not prevent spreadsheet applications from interpreting cell content as formulas. If attacker-controlled package metadata begins with characters such as =, +, -, @, a tab, or a carriage return, compatible spreadsheet software may evaluate it when a user opens the exported CSV.

An attacker who controls public ClawHub package metadata could therefore embed a formula payload in a package name, display name, owner handle, or summary. The application would retrieve the value and preserve it in the CSV without adding a safe prefix or otherwise neutralizing it.

Attack Path

  1. An attacker publishes or modifies public ClawHub package metadata so that an exported field begins with a spreadsheet formula-control character.
  2. A victim queries the attacker-controlled owner or otherwise retrieves that package through the public API.
  3. The victim invokes the script with --export, causing the untrusted metadata to be written directly to a CSV cell.
  4. The victim opens the generated CSV in spreadsheet software that evaluates formulas.
  5. The embedded formula executes within the spreadsheet application's security context.

Impact Assessment

Successful exploitation requires a ...[truncated 698 chars]

Remediation
View remediation

Remediation Suggestions

Sanitize every remotely sourced string before writing it to CSV:

  1. Detect values whose first character is =, +, -, @, tab, or carriage return.
  2. Prefix those values with an apostrophe or apply another neutralization method appropriate for the supported spreadsheet applications.
  3. Perform sanitization on all exported fields rather than only currently known free-text fields, because future API values may also become attacker-controlled.
  4. Preserve the original unsanitized values in JSON or text output only where those output contexts do not interpret formulas.
  5. Add automated tests for each dangerous prefix, including values containing leading whitespace followed by a formula marker.
  6. Document that CSV exports contain untrusted public metadata and should not be opened with formula execution enabled.

A centralized helper can enforce consistent handling:

python
def sanitize_csv_cell(value: Any) -> Any:
    if isinstance(value, str):
        candidate = value.lstrip()
        if candidate.startswith(("=", "+", "-", "@", "\t", "\r")):
            return "'" + value
    return value

# ...
writer.writerow({
    key: sanitize_csv_cell(row.get(key))
    for key in fieldnames
})
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and invokes code capabilities involving network access and file writing, but the manifest does not declare any corresponding tool scope or permission boundaries. This creates a transparency and least-privilege problem: an agent or reviewer cannot easily determine what the skill is allowed to do, increasing the risk of unintended network access, unexpected file creation/export, or misuse if the implementation changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The human-facing text output in format_text is written in Chinese, while the script does not provide any language-selection option or explain that it is intended only for a Chinese-speaking audience. This creates a natural-language locale policy issue because the skill imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation is written entirely in Chinese and does not indicate any alternative language option or user opt-in for locale. Under the policy criteria, forcing a specific language without choice can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.