Back to skill

Security audit

Skill Guard

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real local skill-security scanner, but it can give users misleading safe results because it misses important skill instruction files and silently ignores scan errors.

Use this only as a lightweight heuristic checker, not as a security decision point. Before relying on it, users should confirm the exact package version being installed and understand that the scanner can miss malicious skill instructions in Markdown files or unreadable files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:64
Finding

Unpinned Third-Party Installer and Skill Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill_guard.py:118
Finding

Instruction-Bearing Markdown Files Are Excluded from Security Scans

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skill_guard.py:127
Finding

File-Scanning Errors Are Silently Suppressed and Can Produce False Safe Results

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill_guard.py:139
Finding

Literal Per-Line Pattern Matching Is Trivially Bypassable

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
# ========== 窃取数据 ==========
    # 读取敏感文件
    (["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow", 
      "APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
    # 读取剪贴板
    (["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill_guard.py (reported line 40)May include surrounding context.

python
# ========== 窃取数据 ==========
    # 读取敏感文件
    (["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow", 
      "APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
    # 读取剪贴板
    (["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill_guard.py (reported line 40)May include surrounding context.

python
# ========== 窃取数据 ==========
    # 读取敏感文件
    (["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow", 
      "APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
    # 读取剪贴板
    (["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill_guard.py (reported line 41)May include surrounding context.

python
# ========== 窃取数据 ==========
    # 读取敏感文件
    (["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow", 
      "APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
    # 读取剪贴板
    (["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
    # 屏幕截图

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill_guard.py (reported line 41)May include surrounding context.

python
# ========== 窃取数据 ==========
    # 读取敏感文件
    (["/etc/passwd", "~/.ssh", "~/.bash_history", "~/.bashrc", "/etc/shadow", 
      "APP_DATA", "LOCALAPPDATA", ".aws/credentials", ".kube/config"], "窃取敏感文件", "🔴 严重"),
    # 读取剪贴板
    (["pyperclip", "clipboard", "get_clipboard"], "窃取剪贴板", "🔴 严重"),
    # 屏幕截图

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill_guard.py (reported line 86)May include surrounding context.

python
(["../", "..\\", "path traversal", "%2e%2e"], "目录遍历", "🟠 高"),
    
    # ========== 权限提升 ==========
    (["chmod 777", "chown", "setuid", "sudo", "privilege"], "权限提升", "🟠 高"),
    
    # ========== 远程控制 ==========
    (["flask", "FastAPI", "django"], "Web服务", "🟡 中"),  # 可能被用于远控

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises executable inspection commands and remote inspection behavior, and the analyzer detected capabilities consistent with environment access, file reads, network use, and shell execution, but the manifest does not declare any explicit tool scope or permissions. This is dangerous because consumers cannot easily understand or constrain what the skill may access, increasing the risk of over-privileged execution if the surrounding platform honors implicit capabilities.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation command uses npx clawhub install skill-guard-waai without pinning a specific version or immutable package reference. This is dangerous because users may install a changed or compromised upstream package later, enabling supply-chain attacks through dependency or publisher compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains user-facing natural language entirely in Chinese in the module docstring, presenting the skill as "安全检查 简洁优雅实现" and describing its capabilities only in Chinese. That imposes a language choice without offering any user opt-in or alternative locale, which fits the policy category for language/locale violations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · skill_guard.py (reported line 86)May include surrounding context.

python
(["../", "..\\", "path traversal", "%2e%2e"], "目录遍历", "🟠 高"),
    
    # ========== 权限提升 ==========
    (["chmod 777", "chown", "setuid", "sudo", "privilege"], "权限提升", "🟠 高"),
    
    # ========== 远程控制 ==========
    (["flask", "FastAPI", "django"], "Web服务", "🟡 中"),  # 可能被用于远控

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
skill_guard.py:29