T08 · Insecure Dependencies
- Location
SKILL.md:64- Finding
Unpinned Third-Party Installer and Skill Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a real local skill-security scanner, but it can give users misleading safe results because it misses important skill instruction files and silently ignores scan errors.
Use this only as a lightweight heuristic checker, not as a security decision point. Before relying on it, users should confirm the exact package version being installed and understand that the scanner can miss malicious skill instructions in Markdown files or unreadable files.
SKILL.md:64Unpinned Third-Party Installer and Skill Dependency
skill_guard.py:118Instruction-Bearing Markdown Files Are Excluded from Security Scans
skill_guard.py:127File-Scanning Errors Are Silently Suppressed and Can Produce False Safe Results
skill_guard.py:139Literal Per-Line Pattern Matching Is Trivially Bypassable
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ========== 窃取数据 ==========
# 读取敏感文件
(["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow",
"APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
# 读取剪贴板
(["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ========== 窃取数据 ==========
# 读取敏感文件
(["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow",
"APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
# 读取剪贴板
(["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ========== 窃取数据 ==========
# 读取敏感文件
(["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow",
"APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
# 读取剪贴板
(["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ========== 窃取数据 ==========
# 读取敏感文件
(["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow",
"APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
# 读取剪贴板
(["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
# 屏幕截图
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ========== 窃取数据 ==========
# 读取敏感文件
(["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow",
"APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
# 读取剪贴板
(["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
# 屏幕截图
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
(["../", "..\\", "path traversal", "%2e%2e"], "目录遍历", "🟠 高"),
# ========== 权限提升 ==========
(["chmod 777", "chown", "setuid", "sudo", "privilege"], "权限提升", "🟠 高"),
# ========== 远程控制 ==========
(["flask", "FastAPI", "django"], "Web服务", "🟡 中"), # 可能被用于远控
The skill advertises executable inspection commands and remote inspection behavior, and the analyzer detected capabilities consistent with environment access, file reads, network use, and shell execution, but the manifest does not declare any explicit tool scope or permissions. This is dangerous because consumers cannot easily understand or constrain what the skill may access, increasing the risk of over-privileged execution if the surrounding platform honors implicit capabilities.
The installation command uses npx clawhub install skill-guard-waai without pinning a specific version or immutable package reference. This is dangerous because users may install a changed or compromised upstream package later, enabling supply-chain attacks through dependency or publisher compromise.
This Python file contains user-facing natural language entirely in Chinese in the module docstring, presenting the skill as "安全检查 简洁优雅实现" and describing its capabilities only in Chinese. That imposes a language choice without offering any user opt-in or alternative locale, which fits the policy category for language/locale violations.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
(["../", "..\\", "path traversal", "%2e%2e"], "目录遍历", "🟠 高"),
# ========== 权限提升 ==========
(["chmod 777", "chown", "setuid", "sudo", "privilege"], "权限提升", "🟠 高"),
# ========== 远程控制 ==========
(["flask", "FastAPI", "django"], "Web服务", "🟡 中"), # 可能被用于远控
Detected: suspicious.dynamic_code_execution