Back to skill

Security audit

Design Extractor Clawhub

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent design-documentation purpose, but it asks users or agents to run mutable external code and includes persistent agent-skill conversion steps.

Install only if you are comfortable with project scanning and generated files. Prefer a pinned, reviewed package version or commit, run it in a low-privilege workspace without sensitive environment variables, and avoid automatic conversion into `.claude/skills` unless you explicitly want that persistent agent-skill entry.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:92
Finding

Unpinned Third-Party npm Package Download and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 92–95
Vulnerability Type: Unpinned third-party package execution
Risk Level: High

Vulnerable Code

bash
# Extract from specific directory
npx design-extractor frontend/src

# Extract from current project
npx design-extractor .

Technical Analysis

The documented commands use npx to execute design-extractor without specifying an exact package version or verifying package integrity. If the package is not already installed locally, npx may retrieve the current package release from the configured npm registry and execute it immediately.

Consequently, the code executed during extraction can differ from the content reviewed when this Skill was published. The project does not include a lockfile, integrity hash, vendored implementation, or executable source that would constrain or permit review of the effective payload. This is an insecure dependency pattern; it does not establish that the current upstream package is malicious.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or the relevant package-distribution channel.
  2. The attacker publishes a modified package version containing a malicious installation hook or runtime payload.
  3. A user or AI agent follows the Skill instructions and runs npx design-extractor ..
  4. npx downloads the mutable package version and executes it with the invoking process's privileges.
  5. The package can inspect the current project and potentially read, modify, or delete any other files accessible to that account. It can also initiate network connections or launch child processes unless separately sandboxed.

Impact Assessment

Successful exploitation would provide code execution under the account running npx. The reachable scope may include the complete target repository, environment variables available to the process, developer credentials stored in accessible ...[truncated 309 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an exact, reviewed version, such as npx --no-install design-extractor after a controlled installation from a lockfile.
  • Commit an npm lockfile containing registry-resolved integrity hashes and use npm ci for reproducible installation.
  • Do not permit npx to download packages automatically during Skill execution.
  • Vendor or include the extractor implementation in the audited Skill package so its effective behavior can be reviewed.
  • Verify package provenance using registry signatures, trusted publishing metadata, and checksum or integrity validation.
  • Run extraction in a sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and no elevated privileges.
  • Review package lifecycle scripts and disable them where they are unnecessary, for example through an appropriately assessed --ignore-scripts installation policy.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:80
Finding

Mutable Git Repository Used as an Unverified Installation and Publishing Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 80–82
Vulnerability Type: Unpinned repository dependency
Risk Level: Medium

Vulnerable Code

bash
# Or manually clone
git clone https://github.com/moyubox/design-extractor.git
clawhub skill publish ./design-extractor

Technical Analysis

The installation instructions clone the repository's mutable default branch without pinning a reviewed commit or release and then supply the resulting directory to a publishing command. Future repository contents are outside the audited artifact and can change without any corresponding change to this SKILL.md.

No commit identifier, signed tag requirement, checksum, or post-clone verification step is provided. An upstream repository compromise, maintainer-account compromise, or malicious later update could therefore cause users to retrieve and publish content that was not included in this audit.

Attack Path

  1. An attacker gains the ability to modify the upstream repository or redirects access through a compromised source-control account or distribution channel.
  2. The attacker adds malicious Skill instructions, scripts, dependencies, or lifecycle behavior to the default branch.
  3. A user follows the documented git clone command and receives the modified repository state.
  4. The user runs clawhub skill publish ./design-extractor without verifying the retrieved tree.
  5. The unreviewed content is submitted to the publishing workflow and may subsequently affect systems or users that install or invoke the published Skill.
  6. If the fetched repository also contains code that is executed during packaging, installation, or invocation, that code runs with the privileges available to the relevant process.

Impact Assessment

The immediate impact is a supply-chain integrity failure: unreviewed, attacker-controlled content could be republished and distributed under an apparently legitimate Skill ide ...[truncated 403 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable clone instruction with a checkout of a specific, reviewed commit hash or cryptographically signed release tag.
  • Publish expected commit identifiers and artifact checksums through a trusted channel.
  • Verify commit and tag signatures before installation or publication.
  • Review the complete fetched tree, including scripts, dependency manifests, lockfiles, lifecycle hooks, and Skill instructions, before passing it to clawhub skill publish.
  • Separate installation from publication; ordinary users should install a verified artifact rather than publish a freshly cloned repository.
  • Use protected branches, mandatory review, signed commits, least-privilege maintainer accounts, and multifactor authentication for upstream maintenance.
  • Perform publication in an isolated environment with restricted credentials, filesystem access, and network permissions.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
91% confidence
Finding

The embedded conversion script writes directly into .claude/skills/design-extractor/skill.md, which is an agent configuration directory. Modifying agent skill/config paths is dangerous because it can persist behavior changes, plant instructions for future agent runs, or overwrite trusted local configuration. Even if framed as compatibility tooling, this is a high-risk primitive in agent environments.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
#!/bin/bash
          # Auto-convert ClawHub SKILL.md to Claude Code format
          mkdir -p .claude/skills/design-extractor
          cat > .claude/skills/design-extractor/skill.md << 'CLAUDE_EOF'
          # Design Extractor
          
          ## Name

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
const skillContent = fs.readFileSync('SKILL.md', 'utf8');

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
aiCompatibility:
      claudeCode:
        format: "markdown-headers"
        location: ".claude/skills/design-extractor/skill.md"
        conversionSteps:
          - "Copy SKILL.md content to .claude/skills/design-extractor/skill.md"
          - "Remove YAML frontmatter (--- section)"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
aiCompatibility:
      claudeCode:
        format: "markdown-headers"
        location: ".claude/skills/design-extractor/skill.md"
        conversionSteps:
          - "Copy SKILL.md content to .claude/skills/design-extractor/skill.md"
          - "Remove YAML frontmatter (--- section)"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
aiCompatibility:
      claudeCode:
        format: "markdown-headers"
        location: ".claude/skills/design-extractor/skill.md"
        conversionSteps:
          - "Copy SKILL.md content to .claude/skills/design-extractor/skill.md"
          - "Remove YAML frontmatter (--- section)"

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
script: |
          #!/bin/bash
          # Auto-convert ClawHub SKILL.md to Claude Code format
          mkdir -p .claude/skills/design-extractor
          cat > .claude/skills/design-extractor/skill.md << 'CLAUDE_EOF'
          # Design Extractor

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger condition includes broad activation language such as requests involving design extraction, which can cause the skill to run in contexts the user did not explicitly intend. Overbroad triggering is risky here because the skill scans project files and generates outputs, so accidental activation expands data access and side effects.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
78% confidence
Finding

The skill instructs users/agents to run npx design-extractor without pinning a version. This allows execution of whatever package version is current in the registry at run time, creating a supply-chain risk if the package is updated maliciously or unexpectedly. In a skill context, this is more dangerous because the command is presented as the normal way to use the tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
78% confidence
Finding

This second unpinned npx design-extractor invocation has the same supply-chain exposure: it resolves and executes the latest available package rather than a reviewed version. Because the skill is designed for automation, users may run it in trusted repositories and unintentionally grant code execution to an unverified package version.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill behavior includes recursive project scanning and creation of output files, but the description does not prominently warn about these side effects. That omission can mislead users or agents into invoking it without understanding that repository contents will be read and files like DESIGN-EXTRACTED.md and JSON artifacts will be written.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.