Back to skill

Security audit

GLM-Master-Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only GLM skill catalog, but it directs users and agents toward unpinned installer commands that can fetch current remote code and bulk-install many skills.

Install only after deciding you trust the ClawHub installer and the downstream GLM skills. Prefer a pinned `clawhub` version, inspect each downstream skill before installing it, avoid the bulk-install command unless you need all listed skills, and do not expose unnecessary credentials while running installer commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:70
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
``` Examples: ```bash npx clawhub@latest install glmocr npx clawhub@latest install glmv-caption npx clawhub@latest install glm-image-gen ``` The document also recommends bulk installation: ```bash npx clawhub@latest install glmocr glmocr-table glmocr-formula glmocr-handwriting glmocr-sdk glm-image-gen glmv-caption glmv-prompt-gen glmv-resume-screen glmv-grounding glmv-doc-based-writing glmv-pdf-to-ppt glmv-pdf-to-web glmv-prd-to-app glmv-stock-analyst glmv-web-replication ``` ### Technical Analysis The recommended installation procedure invokes `npx` with the mutable `@latest` package tag. This causes npm to resolve and execute whichever version of `clawhub` is designated as the latest release at invocation time. The document does not specify an audited version, integrity hash, lockfile, provenance requirement, or mandatory review step. Consequently, the effective executable code can change after this skill has been reviewed. A compromise of the package publisher, npm account, registry delivery path, or a future package release could cause users and agents following these instructions to execute attacker-controlled code. The risk is amplified by the bulk-installation command because it introduces numerous additional downstream skills in one operation without requiring individual inspection. Line 144 explicitly instructs an agent to recommend this installation method, making execution of the mutable dependency part of the intended workflow. Although the artifact contains no executable scripts of its own, the statement that it “does not execute scripts” may give users an incomplete understanding of the operational risk: following its primary installation i ...[truncated 1708 chars]
Remediation
View remediation
install ``` 2. Document the expected package version and integrity information. Where supported, verify package provenance, registry signatures, or published checksums before execution. 3. Avoid automatically executing newly downloaded packages. Prefer a workflow that downloads or inspects package metadata and contents before installation. 4. Require each downstream skill to be reviewed individually before installation, particularly before using the bulk-installation command. 5. Run installation in a sandbox, container, or otherwise restricted environment with: - No unnecessary credentials in environment variables. - Minimal filesystem permissions. - Restricted network access. - No administrative or root privileges. 6. Clarify the documentation language to distinguish between the absence of bundled local scripts and the execution of externally downloaded installer code. 7. Establish a trusted-version update process so that upgrades occur only after the new package version and downstream skill changes have been reviewed. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Then follow that skill's own `SKILL.md` for exact setup steps.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

md
Then follow that skill's own `SKILL.md` for exact setup steps.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation instructs users to execute npx clawhub@latest install <skill-name>, which fetches and runs the latest package version at install time. Because the version is not pinned, a compromised upstream package, malicious update, or supply-chain takeover could cause users to run unexpected code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This example command again directs users to run npx clawhub@latest, which implicitly trusts whatever code is current in the registry. Even though this skill is documentation-only, it still facilitates execution of unpinned remote code by downstream users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The command sample uses an unpinned npx package reference, exposing users to supply-chain risk if the package changes between review and execution. Documentation that normalizes @latest increases the chance users will run unreviewed code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This installation example repeats the same unpinned remote execution pattern via npx clawhub@latest. If an attacker controls or poisons the published package, users following the docs may execute malicious code locally.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The bulk-install command magnifies the same risk: it invokes npx clawhub@latest and may install many downstream skills in one step. This increases blast radius because users may execute unpinned tooling and then immediately pull multiple additional components.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
> **Security best practices:**
>
> - Create a **limited-scope** API key with only the permissions needed for the skills you plan to use.
> - Store the key in environment variables only — **never hardcode** it in source files or commit it to version control.
> - Add `ZHIPU_API_KEY` to your `.gitignore` if storing it in a `.env` file.
> - Rotate the key periodically and revoke unused keys at https://bigmodel.cn/usercenter/proj-mgmt/apikeys.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The agent usage guidance tells agents to recommend npx clawhub@latest install <skill-name> first, operationalizing unpinned remote code execution as the preferred path. This is risky because automated agents may propagate the unsafe command widely without human review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.