Back to skill

Security audit

Publish Clawhub

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language chat game skill with no code execution or data access, though its start/restart phrases are broad enough to trigger accidentally.

Install this if you want a Chinese-language AI werewolf chat game. Be aware that common Chinese words like "开始", "玩", or "继续" may start or continue the game in contexts where the skill is active.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill name, description, triggers, prompts, and all user-facing interaction text are written exclusively in Chinese, and the behavior assumes Chinese commands such as "开始" and "来一局". There is no opt-in, language selection, or explicit statement that the skill is intentionally limited to Chinese-speaking users for a justified regional purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill defines overly broad activation phrases such as '开始', '来一局', '玩' and even '任何表示想玩的话', which can overlap with ordinary conversation. This can cause unintended skill invocation or mode transitions, especially in shared assistant contexts where casual language may accidentally trigger the game flow.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The restart triggers include broad everyday terms like '继续' and '下一局', which may appear naturally in unrelated conversation after a game ends. This increases the chance of accidental re-invocation or looping behavior without clear user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.