Back to skill

Security audit

keyword-miner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed keyword-research helper that installs and pairs a ClawLink plugin for paid public-data lookups, with minor documentation ambiguity around support reporting.

Before installing, understand that this skill depends on the ClawLink plugin, one-time device pairing, and paid third-party public-data calls. It should not be used for private account actions. If troubleshooting asks to report an issue, review or ask what details will be sent to ClawLink first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file states that the tools only read public information and that nothing is posted or changed, but later instructs use of an issue-reporting capability that clearly sends data externally. This contradiction can mislead an agent or user into treating all actions as read-only, reducing scrutiny around a tool that performs outbound transmission.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill introduces clawlink_report_issue, which sends data to the ClawLink team and is outside the core keyword-research function. Even if intended for support, it creates an outbound communication path that could transmit user prompts, tool arguments, errors, or other context to a third party without being framed as a separate consented action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description frames the skill as a keyword research capability, but the file instructs the agent to install a separate plugin, initiate user-device pairing, and rely on an external service account before any research can occur. Those operational behaviors go beyond the plain-language description of a keyword tool, even though they are related to enabling it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.