Back to skill

Security audit

Deep Research Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent research workflow skill with some broad activation and installation-risk caveats, but no evidence of hidden, destructive, or deceptive behavior.

Install through ClawHub when possible. If using the npm CLI path, pin and verify the installer first. Expect the skill to use web sources and, for deep research, to produce workspace report files; ask the agent to confirm before writing or overwriting files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:23
Finding

Unpinned Global Installation of a Third-Party npm CLI

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 23–28
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code

bash
# Via agentskills-cli
npm install -g @jahonn/agentskills-cli
agentskills install ./research-agent-skill -t all

# Via ClawHub
clawhub install research-agent

Technical Analysis

The documented installation procedure instructs users to install @jahonn/agentskills-cli globally without specifying an exact version or verifying package integrity. npm will therefore resolve the registry version associated with the default distribution tag at installation time.

The audited project does not include the CLI source, a lockfile, an integrity hash, or provenance information that would allow users to reproduce or verify the installed artifact. In addition, npm installation can execute package lifecycle scripts unless explicitly disabled. A compromised package account, registry release, or transitive dependency could consequently execute arbitrary commands with the privileges of the user running the installation.

Using -g increases exposure by installing an executable into the user's global npm environment. This does not inherently grant administrative privileges, but any malicious installation behavior receives all filesystem, process, network, credential, and configuration access already available to that user.

The clawhub install alternative is also unpinned, but the available project contents do not establish its package-resolution or integrity-verification behavior. Therefore, the confirmed finding is specifically based on the npm installation command.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, package contents, or a dependency used by @jahonn/agentskills-cli.
  2. The attacker publishes a malicious version under the package's active distribution tag.
  3. A user follows the README and runs `npm install -g @j ...[truncated 1303 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a reviewed exact version rather than relying on a mutable distribution tag:

    bash
    npm install -g @jahonn/agentskills-cli@X.Y.Z
    
  2. Prefer a project-local, lockfile-controlled installation over a global installation. Commit the resulting lockfile so dependency versions and integrity hashes are reproducible.

  3. Publish and verify package provenance, checksums, signatures, or registry attestations before installation.

  4. Audit the package's lifecycle scripts, bundled files, executable entry points, and transitive dependency graph before recommending it.

  5. Where compatible, suppress lifecycle scripts during installation:

    bash
    npm install --ignore-scripts @jahonn/agentskills-cli@X.Y.Z
    

    Only invoke reviewed package functionality afterward.

  6. Run installation and CLI operations in a least-privileged, isolated environment without unnecessary credentials or access to sensitive repositories.

  7. Document the expected publisher, exact package version, integrity-verification procedure, and upgrade-review process.

  8. Pin or otherwise authenticate the ClawHub artifact as well if that ecosystem supports versions, digests, signatures, or provenance verification.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises extremely broad trigger phrases such as "what is," "tell me about," "analyze," and "compare," which commonly appear in ordinary conversation. This can cause unintended activation of the skill in contexts where the user did not explicitly request deep research behavior, increasing the chance of unnecessary web access, subagent use, or file creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises very broad trigger phrases such as "what is," "tell me about," "analyze," and "compare," which are common in ordinary conversation and could cause this skill to activate unintentionally. In an agent ecosystem, over-broad invocation increases the chance that the skill is selected for unrelated prompts, leading to unnecessary tool use, expanded data access, or prompt-routing surprises even though the content here is not overtly malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The mode table reinforces activation on vague phrases like "What is X?" and "X or Y?" without requiring an explicit research intent. In context, this broadens the chance of accidental routing into a higher-cost or more invasive workflow, though the impact is somewhat limited because the table is illustrative rather than executable logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Deep Dive workflow instructs the agent to write RESEARCH.md but does not warn that the skill may modify the workspace. Silent file creation can surprise users, overwrite existing work, or leave artifacts in repositories, especially when activation is already broad.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Output Files section normalizes creation of RESEARCH.md and possibly LANDSCAPE.md without disclosing workspace-modification risk or obtaining consent. In a tool-using agent environment, undocumented file writes are a meaningful safety issue because they can alter project state unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.