Back to skill

Security audit

评论透镜

Security checks for vulnerabilities and agentic risk

Overview

ReviewLens is a coherent shopping-review analysis skill, with a maintainer publish script that users should not run unless they intend to publish the package.

Install this if you want Chinese-language help analyzing shopping reviews. Treat its advice as review-based judgment, not a guarantee. Do not run scripts/publish.sh unless you are maintaining or publishing the skill, and review any external validator it would execute first.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/publish.sh:6
Finding

Execution of an Untrusted Validator Outside the Audited Project

Content
View full analysis

Vulnerability Details

File Location: scripts/publish.sh:6-8, 52-54
Vulnerability Type: Untrusted external script execution
Risk Level: Medium

Vulnerable Code

sh
WORKSPACE_ROOT="$(CDPATH= cd -- "$ROOT/../.." && pwd)"
CLAWHUB_JSON="$ROOT/clawhub.json"
VALIDATOR="$WORKSPACE_ROOT/tmp/validate_clawhub_skill_dir.sh"
sh
if [ -f "$VALIDATOR" ]; then
  bash "$VALIDATOR" "$PUBLISH_ROOT"
fi

Technical Analysis

The publishing script constructs a validator path outside the project root and executes the file whenever it exists. The validator is not part of the audited artifact, and the script does not verify its ownership, permissions, canonical path, provenance, or cryptographic integrity.

The existence check using -f only confirms that the path resolves to a regular file. It does not establish that the file is trusted. A user or process capable of writing to the workspace-level tmp directory can place attacker-controlled shell code at the expected path. That code will then execute with the privileges of the user running scripts/publish.sh.

The validator receives PUBLISH_ROOT as an argument and runs immediately before publication, giving it an opportunity to read or modify the publication contents in addition to running arbitrary local commands.

Attack Path

  1. An attacker obtains write access to the workspace-level tmp directory derived from "$ROOT/../..".
  2. The attacker creates or replaces tmp/validate_clawhub_skill_dir.sh with a malicious shell script.
  3. A maintainer runs sh scripts/publish.sh.
  4. The script confirms only that the external validator path resolves to a file.
  5. bash executes the attacker-controlled validator with the maintainer's privileges.
  6. The malicious validator can execute arbitrary commands and alter PUBLISH_ROOT before clawhub publish runs.

Impact Assessment

Successful exploitation provides arbitrary command execution under the account invoking the publishing script ...[truncated 661 chars]

Remediation
View remediation

Remediation Suggestions

  • Store the validator inside the audited repository and invoke it through a fixed project-relative path.
  • If an external validator is required, accept its path only through an explicit, trusted configuration rather than deriving it from a writable workspace directory.
  • Resolve the validator to its canonical path and verify that it remains within an approved directory.
  • Verify ownership and permissions before execution. Reject validators or parent directories writable by untrusted users.
  • Pin and verify a cryptographic hash or signature for the validator before invoking it.
  • Avoid silently skipping validation when it is a required publishing control; fail closed if the trusted validator is missing.
  • Run validation in a constrained environment with the minimum filesystem and credential access required.
  • Ensure the publication directory cannot be modified by the validator unless modification is explicitly necessary; otherwise validate a read-only copy and verify its integrity again immediately before publication.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for an end-user review-analysis skill, but the supplied code chunk is only deployment infrastructure. It does not inspect marketplace reviews, summarize praise/complaints, identify buyer fit or regret risk, or make cheap-versus-steady judgments. Instead, it prepares files and calls clawhub publish to distribute the skill package. That is a materially different primary purpose and includes undeclared external publishing behavior, so this code does not accurately represent the declared functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This release file’s user-facing descriptions, announcement copy, and marketplace text are written primarily in Chinese, but there is no indication that the skill is intentionally limited to Chinese-speaking users or that users can opt into another language. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill lists several example utterances and broad input conditions for when to use it, but it does not define clear boundaries for when the skill should not activate. Phrases about suitability, complaints, or 'real experience' can overlap with ordinary product discussion, increasing the chance of over-triggering.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to 'Sound like a decisive Chinese shopping operator' imposes a specific language/locale persona. The file does not indicate that this style is optional or contingent on user preference, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language instruction explicitly says 'answer in Chinese,' which imposes a language choice regardless of user preference. This is a locale/language policy issue because the file does not offer an opt-in choice or explain a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

All example prompts are written only in Chinese, and the file provides no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy if the skill behavior implicitly assumes a single language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains high-hit short prompts such as "适合谁?", "差评集中吗?", and "给我评论结论卡。" that are generic enough to collide with everyday user requests outside a narrowly scoped context. The file does not provide constraints, exclusion conditions, or negative examples clarifying when these prompts should or should not activate the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown guidance repeatedly instructs the skill to use Chinese output phrases in multiple sections, which can amount to forcing a specific language or locale without user opt-in. The policy for natural-language violations applies to all file types, and there is no indication that Chinese-only output is optional or justified by a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file prescribes fixed Chinese output phrases as 'Common phrasing,' which creates a language-specific response policy. Because the document does not offer user opt-in or explain that the skill is intentionally Chinese-only, this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These template phrases continue the pattern of mandating Chinese-language output. The file gives no indication that users can choose their preferred language and no documented business reason for restricting output to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill file provides only Chinese phrasing for this verdict pattern, implying a required response language. Without an opt-in mechanism or locale justification, this conflicts with the policy against forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The prescribed phrasing is entirely in Chinese and is presented as the standard wording to use. The file lacks any instruction to adapt to user language preferences or any justification for a Chinese-only output requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These examples continue to enforce Chinese-language verdict text as the expected output style. Because no user language choice or locale-specific rationale is provided, this is a policy issue rather than a mere example choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The compressed response template is a direct instruction to produce a Chinese-language conclusion. Since the file gives no opt-in, multilingual fallback, or documented locale limitation, it violates the language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and presents the skill in a single language, with no indication that users can choose another language or locale. Under the policy for natural-language violations, forcing a specific language without opt-in can be a compliance issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains natural-language guidance in Chinese as the only suggested phrasing for that section. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation, and the file does not explain why Chinese is required or offer alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The section presents user-facing phrasing solely in Chinese, which can implicitly enforce a language choice. Because no regional or audience-specific constraint is documented, this conflicts with the requirement to avoid forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

These lines give example wording only in Chinese, which may cause the skill to default to a specific language unexpectedly. The file does not provide a language-selection mechanism or justify a Chinese-only scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The repeated use of Chinese-only suggested responses indicates a default language preference embedded in the instructions. Since the file does not say the skill is region-specific or ask the user for language preference, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.