Back to skill

Security audit

Vercel Deployment Watchdog

Security checks for vulnerabilities and agentic risk

Overview

This is a real Vercel monitoring skill, but it needs Review because its URL checks can be bypassed and may let the agent request internal/private services.

Install only if you understand that it will make HTTP requests from your agent environment to the URLs you provide and to Vercel when a token is supplied. Prefer VERCEL_TOKEN from a protected environment variable, do not pass tokens on the command line, avoid ALLOW_INTERNAL unless you intentionally need private-network monitoring, and do not let untrusted input choose the homepage/API URLs or state-file path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/watchdog-check.sh:31
Finding

Bypassable URL Validation Enables Server-Side Requests to Internal Network Services

Content
View full analysis
/dev/null || true) status_code=$(curl -s -o /dev/null -w "%{http_code}" "$url") headers=$(curl -s -I "$HOMEPAGE_URL") html=$(curl -s "$HOMEPAGE_URL") response=$(curl -s "$API_URL") ``` ### Technical Analys ...[truncated 2773 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/watchdog-check.sh:61
Finding

Vercel API Tokens Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as Vercel deployment monitoring, but the documented options allow targeting arbitrary URLs and explicitly permit internal/private/local resources when ALLOW_INTERNAL is enabled. In practice, this broadens the skill into a general network probing tool and increases SSRF-style or internal reconnaissance risk, especially since the file also suggests undeclared local state usage.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as Vercel deployment monitoring, but the documented options allow targeting arbitrary URLs and explicitly permit internal/private/local resources when ALLOW_INTERNAL is enabled. In practice, this broadens the skill into a general network probing tool and increases SSRF-style or internal reconnaissance risk, especially since the file also suggests undeclared local state usage.

Content

No source excerpt is available for this finding.

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
### Compliance with ClawHub Policies

This skill:
- Does **not** attempt to bypass security controls
- Does **not** include obfuscated or hidden functionality
- Is **open source** and transparent about all operations
- Respects `robots.txt` and common web standards

Instruction Override

High
Category
Prompt Injection
Confidence
94% confidence
Finding

The script advertises a simple environment variable, ALLOW_INTERNAL, to bypass internal/private URL protections entirely. In an agent or automation context, this weakens SSRF safeguards because any caller able to influence environment variables can re-enable probing of localhost, RFC1918 space, or internal hostnames.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 107)May include surrounding context.

sh
echo "  --help                 Show this help message"
      echo ""
      echo "Security note: Only monitor sites you own. Internal/private URL checks are enabled by default."
      echo "To bypass security checks for internal resources, set ALLOW_INTERNAL=true env var."
      exit 0
      ;;
    *)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 107)May include surrounding context.

sh
echo "  --help                 Show this help message"
      echo ""
      echo "Security note: Only monitor sites you own. Internal/private URL checks are enabled by default."
      echo "To bypass security checks for internal resources, set ALLOW_INTERNAL=true env var."
      exit 0
      ;;
    *)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs the user to run shell commands and scripts, yet it declares no explicit tool scope or permissions. This creates a governance gap: an agent or platform may permit broader shell execution than intended, making review and enforcement of least privilege harder.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
{
              "id": "check-deps",
              "kind": "manual",
              "instructions": "Ensure curl and jq are installed. On Debian/Ubuntu: sudo apt-get install curl jq. On macOS: brew install curl jq.",
              "bins": ["curl", "jq"],
              "label": "Check for curl and jq dependencies",
            },

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
{
              "id": "check-deps",
              "kind": "manual",
              "instructions": "Ensure curl and jq are installed. On Debian/Ubuntu: sudo apt-get install curl jq. On macOS: brew install curl jq.",
              "bins": ["curl", "jq"],
              "label": "Check for curl and jq dependencies",
            },

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata and manifest describe automated health checks, cache freshness verification, and API validation, but the implementation only enumerates recent deployments and reports their states. This mismatch can cause operators or downstream agents to falsely assume post-deployment verification occurred, leading to insecure or broken deployments being treated as healthy.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 33)May include surrounding context.

sh
API_URL=""
# Allow internal URL monitoring only when explicitly permitted via environment variable
if [[ -n "${ALLOW_INTERNAL:-}" ]]; then
    SKIP_VALIDATION=true
    echo "Warning: Internal URL validation disabled via ALLOW_INTERNAL environment variable"
else
    SKIP_VALIDATION=false

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 36)May include surrounding context.

sh
API_URL=""
# Allow internal URL monitoring only when explicitly permitted via environment variable
if [[ -n "${ALLOW_INTERNAL:-}" ]]; then
    SKIP_VALIDATION=true
    echo "Warning: Internal URL validation disabled via ALLOW_INTERNAL environment variable"
else
    SKIP_VALIDATION=false

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 42)May include surrounding context.

sh
JSON_OUTPUT=false

# Vercel API settings (optional)
VERCEL_TOKEN_ENV="${VERCEL_TOKEN:-}"  # Capture environment variable before we overwrite it
VERCEL_TOKEN=""
VERCEL_PROJECT_ID="${VERCEL_PROJECT_ID:-}"
VERCEL_TEAM_ID="${VERCEL_TEAM_ID:-}"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The help output states that internal/private URL checks are enabled by default and can be bypassed with ALLOW_INTERNAL=true, but the code above actually sets SKIP_VALIDATION=true whenever ALLOW_INTERNAL is merely non-empty, not specifically 'true'. This is an active documentation contradiction that materially changes the security posture because values like ALLOW_INTERNAL=0 or ALLOW_INTERNAL=no still disable validation.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
91% confidence
Finding

Returning immediately when SKIP_VALIDATION is true disables all hostname checks, allowing arbitrary targets including localhost and private/internal networks. In a skill that accepts URLs and issues curl requests, this creates an SSRF primitive if an attacker can influence environment variables or wrapper configuration.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 141)May include surrounding context.

sh
local url="$1"
    local type="$2"
    
    if [[ "$SKIP_VALIDATION" == "true" ]]; then
        return 0
    fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 228)May include surrounding context.

sh
fi
}

# Function to save state to file
save_state() {
    local state_file="$1"
    local state_json="$2"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/watchdog-check.sh (reported line 260)May include surrounding context.

sh
last_timestamp=$(echo "$current_state" | jq -r '.lastDeploymentTimestamp // 0')
    
    # Build API query
    local api_url="https://api.vercel.com/v6/deployments"
    local query_params="limit=1&state=READY"
    
    if [[ -n "$project_id" ]]; then

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes deployment state to a user-specified path using echo "$state_json" > "$state_file", which can create or overwrite files. Although the script documents the --state-file option, there is no explicit user-facing warning at the write site or disclosure that existing contents at that path will be replaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script performs multiple curl requests to the homepage, API, and Vercel API endpoints, which transmits request metadata to external services. While network access is central to a watchdog check, the file does not clearly disclose in its usage/help text that running the script will actively contact the provided endpoints and Vercel if a token is supplied.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.