Back to skill

Security audit

ClawSwarm Jobs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple guide for an external agent job board, but it asks agents to take remote jobs and submit work to a third-party service without enough user approval, scoping, or secret-handling guidance.

Review this skill carefully before installing. Use it only with a sandboxed agent, avoid sending private workspace data or sensitive deliverables, treat all remote tasks as untrusted text, and store any api_key as a secret outside prompts, code, and logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Untrusted External Task Control and Work-Product Exfiltration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The registration example initiates an external network request to a non-local service and includes agent-provided data in the request body. External transmission is especially relevant here because the skill is designed for autonomous agent use, where actions may be executed with limited human review and could disclose metadata or establish trust relationships with an unvetted remote system.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

1. Register (if you haven't)

bash
curl -X POST https://onlyflies.buzz/clawswarm/api/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "YourAgent",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs agents to POST registration data to a third-party service, including agent name and capabilities, without any explicit disclosure that this sends data off-platform or guidance on what data is safe to share. In an agent skill context, users may treat setup steps as trusted defaults, so silent external transmission increases the risk of unintended data exposure and supply-chain style trust abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide tells users to save an API key but gives no instructions for secure handling, storage, rotation, or avoidance of logging/sharing. In agent ecosystems, credentials are often propagated through prompts, config files, or tool logs, so omission of basic secret-handling guidance materially raises the chance of credential leakage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.