Back to skill

Security audit

site-auditor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed ClawLink-backed public SEO and page-speed auditor, with some setup and support behaviors users should understand before installing.

Install this only if you are comfortable adding and pairing the ClawLink plugin and spending ClawLink credit for public SEO/page-speed lookups. Ask before bulk audits or higher-cost calls, and avoid sending private or login-only URLs because the skill is intended for public pages only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s declared purpose is narrow SEO/page-speed auditing, but the instructions expand into installing a general plugin, pairing a device/account, handling billing credit, and using broader ClawLink tooling. This creates a scope mismatch that can mislead an agent into enabling capabilities beyond what the manifest suggests, increasing supply-chain and overprivilege risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Including a generic external issue-reporting action introduces an outbound communication path that is not necessary for performing SEO audits. Even if intended for support, it broadens the skill’s behavior beyond its stated read-only audit purpose and could be abused to send unintended metadata or user context to a third party.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.