Back to skill

Security audit

Find Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible skill-search tool, but it under-discloses where searches are sent and can present unverified remote results as trusted.

Review carefully before installing. Avoid searching for confidential project names or private technologies because queries may be sent to ClawHub, GitHub, and an undeclared Volces mirror. Do not rely on the displayed verified status for mirror results, and inspect any shown install command before running it.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

other

Warning
Location
src/clawhub-api.js:74
Finding

Undisclosed Disclosure of Search Queries to a Third-Party Mirror

Content
View full analysis
axios.get(mirrorUrl, { params }), { maxRetries: 3, retryDelay: 1000, retryMultiplier: 2, retryableStatusCodes: [429, 500, 502, 503, 504] }); ``` The documentation identifies `https://clawhub.ai` as the homepage, and the corresponding source adapter describes itself as the official ClawHub source. However, skill searches made through that adapter are always sent to `https://skills.volces.com/api/v1/search`. The transmitted `q` parameter contains the translated search query. This may include user interests, project names, internal technologies, or other sensitive contextual information. Because default searches query all registered sources, disclosure occurs without the user explicitly selecting or consenting to this mirror. ### Technical Analysis This is a transparency and data-boundary issue rather than arbitrary code execution. The third-party endpoint is hardcoded, is not identified in `SKILL.md`, and cannot be disabled through the documented CLI options. HTTPS protects the query in transit, but the operator of `skills.volces.com` can still receive and retain the query, source IP address, request time, and ordinary HTTP metadata. The implementation does not communicate a retention policy or obtain explicit consent. ### Attack Path 1. A user runs a normal search or recommendation command containing confidential terms. 2. `SearchEngine.search()` dispatches the query through `SourceManager.searchAll()`. 3. The source labeled `clawhub` invokes `ClawHubAPI.searchSkills ...[truncated 582 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
src/clawhub-api.js:94
Finding

Unvalidated Mirror Results Are Falsely Marked as Verified

Content
View full analysis
{ // 从 metaContent 中提取信息 const metaContent = item.metaContent || {}; const skillMd = metaContent.skillMd || ''; // 解析 skillMd 中的信息 const nameMatch = skillMd.match(/name: (.*)/); const descriptionMatch = skillMd.match(/description: (.*)/); return Skill.fromJSON({ name: metaContent.displayName || item.displayName || nameMatch?.[1] || item.slug, slug: item.slug, description: metaContent.DisplayDescription || descriptionMatch?.[1] || item.summary || '暂无描述', tags: metaContent.Keywords || [], downloads: 0, // 镜像站 API 没有提供下载量 verified: true, // 默认为已验证 qualityScore: item.score || 0, repository: '', // 镜像站 API 没有提供仓库链接 installCommand: '', // 镜像站 API 没有提供安装命令 version: item.version || '1.0.0', author: metaContent.owner || '未知作者', createdAt: new Date(item.updatedAt || Date.now()).toISOString(), updatedAt: new Date(item.updatedAt || Date.now()).toISOString() }); }); ``` Every result returned by the mirror is assigned `verified: true`, even though the code performs no signature validation, authoritative identity lookup, repository verification, moderation check, or provenance validation. The same object explicitly lacks repository information and may derive its name and description from remotely supplied `skillMd` text. Consequently, the displayed verification state is not supported by the available evidence. ### Technical Analysis A verification indicator is a security-sensitive trust signal. Setting it unconditionally allows remote records to inherit the appearance of approval regardless of their origin or integrity. An attacker who can publish, modify, or influence a mirror entry could imitate a legitimate skill name or author. The CLI would then display that entry as ...[truncated 993 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/sources/base-source.js:35
Finding

Remote Metadata Is Printed Without Terminal Sanitization and Is Used to Generate Shell Commands

Content
View full analysis
{ console.log(`\n${index + 1}. ${skill.name}`); console.log(` 来源: ${skill.source}`); console.log(` 描述: ${skill.description}`); console.log(` 标签: ${skill.tags?.join(', ') || '无'}`); console.log(` 下载量: ${skill.downloads || 0}`); console.log(` 质量评分: ${skill.qualityScore || 0}`); console.log(` 已验证: ${skill.verified ? '是' : '否'}`); if (skill.installCommand) { console.log(` 安装命令: ${skill.installCommand}`); } if (skill.sourceUrl) { console.log(` 来源链接: ${skill.sourceUrl}`); } }); ``` Skill names, descriptions, tags, repository URLs, and slugs originate from remote API responses or repository-controlled `SKILL.md` files. They are neither normalized nor stripped of ANSI, OSC, or other terminal control sequences before being passed to `console.log()`. In addition, `BaseSource.formatSkill()` constructs a command by directly interpolating the remote `slug`: ```js `clawhub install ${skill.slug}` ``` There is no strict identifier validatio ...[truncated 2078 chars]
Remediation
View remediation
` instead of one copyable shell string. 6. If displaying a command is necessary, clearly label it as untrusted and use a shell-escaping library suitable for the target shell. 7. Impose reasonable length limits on all remote metadata fields. 8. Add security tests using ANSI sequences, OSC hyperlinks, newlines, carriage returns, quotes, semicolons, command substitutions, and other shell metacharacters. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The inline comment states that the implementation 'directly uses mirror API' because the ClawHub source API is unavailable or private. However, this file also uses this.client.get('/api/v1/skills/...') and this.client.get('/api/v1/skills') against the primary clawhub.ai base URL in other methods, so the documentation contradicts the actual behavior of the module.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JavaScript file contains user-facing messages and operational comments entirely in Chinese, such as the returned error messages on L009, L022, L035, and L061. Because the skill does not offer language selection or document that it is intentionally limited to a Chinese-speaking context, it appears to enforce a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file hard-codes a binary language policy: any text containing Chinese characters is treated as Chinese, and everything else defaults to English. This imposes a locale behavior on all inputs without offering the user a language choice or documenting a justified region-specific constraint, which matches the natural-language policy violation criteria for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code contains user-facing natural-language strings and comments in Chinese, and the CLI later emits Chinese-only help and error messages such as at L101, L137, and L220. That forces a specific language/locale without offering the user any choice or documenting a justified locale constraint, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code logs both the raw user query and its translated form to the console, which can expose sensitive user input such as personal data, internal project names, credentials mistakenly pasted into search, or other confidential terms. Because search terms often reflect user intent and may be collected in production logs, this creates an avoidable privacy and data-handling risk even though it is not direct code execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

When the detected language is Chinese, the code automatically boosts results containing Chinese characters in the skill name or description. This imposes a locale/language preference without offering the user a choice or documenting an explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code sets the source description to Chinese (GitHub 技能来源), and the rest of the file also uses Chinese-only comments and error strings, indicating a fixed language choice. The policy forbids forcing a specific language or locale unless the skill offers user choice or clearly documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains user-facing messages, help text, and comments entirely in Chinese, including fixed outputs such as loading, help, and search result labels. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language documentation and usage instructions are presented only in Chinese, while the description states the skill supports both Chinese and English. This can conflict with language/locale policy expectations because users are not offered an explicit language choice in the documentation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified with a caret range (^1.6.8) rather than an exact version, which makes builds non-reproducible and can silently pull in newer releases. In a security-sensitive skill, this weakens supply-chain control and can unexpectedly introduce vulnerable or malicious package versions over time.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "",
  "license": "MIT",
  "dependencies": {
    "axios": "^1.6.8"
  },
  "devDependencies": {}
}

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
81% confidence
Finding

The manifest references axios without pinning an exact version, while the package family has multiple known advisories. Because the installed version is not fixed here, it is impossible to verify from this file alone whether deployments will receive a safe or affected release, creating supply-chain uncertainty and possible exposure to known issues such as SSRF-related bypasses depending on runtime usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code consistently uses Chinese natural-language comments, log messages, default text, and error strings such as '搜索技能失败', '暂无描述', and '网络连接失败'. That creates a locale/language constraint in user-visible strings without offering a language choice or documenting a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's natural-language comments are written exclusively in Chinese, including user-facing descriptive labels such as filtering, sorting, pagination, and version comparison. Per the policy, forcing a specific language without user opt-in can be a language/locale policy violation, and this file provides no indication of user choice or documented locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript file contains natural-language comments in Chinese and a text extraction regex that explicitly supports Chinese characters alongside Latin alphanumerics. Because the skill does not document a locale-specific scope or offer any language choice, this can be interpreted as an implicit language/locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The method returns only Chinese labels ('优秀', '良好', '一般', '较差') with no indication that the user can choose another language or locale. For a general-purpose skill model file, this hard-coded output can impose a specific language without documented opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code embeds user-facing description and error messages entirely in Chinese ('基础技能来源', '子类必须实现...'). The policy requires avoiding forced language/locale choices unless the skill offers an opt-in or clearly documents a justified locale restriction, which is not present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description is hard-coded in Chinese ('官方技能源') with no indication that users can choose another language or locale. This can conflict with organizational language/locale policies when a skill is expected to be locale-neutral or user-selectable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JavaScript file contains natural-language comments and runtime log/error messages in Chinese, such as initialization comments and source-status messages. Under the stated policy, forcing a specific language without user opt-in is a locale-policy issue unless the constraint is clearly documented and justified, which is not evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language comments and user-visible log messages entirely in Chinese, including retry status output. For a general-purpose utility module, this imposes a specific language/locale without any opt-in, fallback, or documented regional justification, which matches the policy-violation criterion for language constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.