Back to skill

Security audit

Prove Before Act

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed proof-recording integration, but users should be careful with its permanent public records, payments, and unpinned install examples.

Install through ClawHub where possible, or pin any GitHub and SDK versions before use. Hash content locally, avoid sensitive filenames or metadata, keep API keys out of logs and repositories, and require explicit approval plus spending limits before any x402, batch, or certification action because proofs and payments can be public and irreversible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:57
Finding

Skill files are downloaded from a mutable repository branch without integrity verification

Content
View full analysis
.agent/skills/prove-before-act/SKILL.md # Reference Manuals for f in certification x402 mcp; do curl -sL "https://raw.githubusercontent.com/jasonxkensei/prove-before-act/main/clawhub-publish/xproof/references/${f}.md" \ > ".agent/skills/prove-before-act/references/${f}.md" done ``` ### Technical Analysis The installation instructions download the core skill and its reference documents from the mutable `main` branch. No immutable commit identifier, release tag, checksum, or signature is used to verify the downloaded content. Although the downloaded files are Markdown rather than native executables, they are agent instructions. Their effective behavior begins when an agent loads and follows them. A compromised upstream repository, maintainer account, build process, or delivery path could therefore replace the reviewed instructions with content that directs the agent to disclose data, invoke privileged tools, make payments, or retrieve and execute additional payloads. The use of HTTPS protects transport integrity but does not establish that the retrieved content is the same version that was audited. The comment identifying the repository as canonical does not provide cryptographic verification. This exceeds minimum privilege because installation only requires a known, reviewed version of the documentation; granting the current upstream branch continuing control over installed instructions is unnecessary. ### Attack Path 1. An attacker compromises an upstream maintainer account, GitHub token, repository workflow, or another mecha ...[truncated 1533 chars]
Remediation
View remediation
" BASE="https://raw.githubusercontent.com/jasonxkensei/prove-before-act/${COMMIT}/clawhub-publish/xproof" ``` - Publish SHA-256 digests through a separately authenticated release channel and verify each file before moving it into the active skill directory: ```bash curl --fail --show-error --location "$BASE/SKILL.md" -o SKILL.md.tmp printf '%s %s\n' "" "SKILL.md.tmp" | sha256sum --check - mv SKILL.md.tmp .agent/skills/prove-before-act/SKILL.md ``` - Prefer signed release artifacts and verify a trusted maintainer signature or Sigstore attestation. - Download into a staging directory and activate the files only after every integrity check succeeds. - Use `curl --fail --show-error` so HTTP failures do not silently create empty or error-page files. - Review updates before changing the pinned commit or digest; do not perform automatic runtime refreshes. - Restrict installed skill instructions from directly authorizing secret access, arbitrary tool execution, or payments without explicit user approval. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Python SDK installation is unpinned and lacks package integrity controls

Content
View full analysis
Remediation
View remediation
" ``` - Use a lock file or requirements file containing hashes generated from reviewed artifacts: ```text prove-before-act== \ --hash=sha256: ``` Install it with: ```bash python -m pip install --require-hashes -r requirements.txt ``` - Pin and hash all transitive dependencies, not only the top-level SDK. - Prefer pre-reviewed wheels and disable unexpected source builds where practical: ```bash python -m pip install --only-binary=:all: --require-hashes -r requirements.txt ``` - Install into a dedicated, least-privileged virtual environment rather than a system or shared agent environment. - Review package metadata, release provenance, maintainers, and Sigstore attestations before updating the pinned version. - Run package installation without wallet secrets or production API keys present in the environment. - Subject every dependency update to automated vulnerability scanning and manual review before deployment. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# Core Skill — from the canonical main repository
curl -sL https://raw.githubusercontent.com/jasonxkensei/prove-before-act/main/clawhub-publish/xproof/SKILL.md \
  > .agent/skills/prove-before-act/SKILL.md

# Reference Manuals
for f in certification x402 mcp; do

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

bash
# Step 4 — close the loop (API key required; both proofs must be yours)
curl -X POST https://provebeforeact.com/api/coherence/link \
  -H "Authorization: Bearer pm_..." \
  -H "Content-Type: application/json" \
  -d '{"why_proof_id": "<UUID from check_coherence>", "what_proof_id": "<UUID from certify_file>"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

bash
# Example proof request with webhook
curl -X POST https://provebeforeact.com/api/proof \
  -H "Authorization: Bearer pm_..." \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
# Then POST the hash to /api/proof

# Anchor via MCP
curl -X POST https://provebeforeact.com/mcp \
  -H "Authorization: Bearer pm_..." \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"certify_file","arguments":{"file_hash":"...","filename":"myfile.pdf"}}}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prompt-engineering guidance tells an LLM to compute a file hash and call certify_file for a paid, irreversible blockchain action, but it does not require explicit user confirmation, cost disclosure at execution time, or warning about permanent on-chain effects. In an agent setting, this creates a real risk of autonomous spending and unintended immutable certification of user files based only on natural-language prompts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/x402.md (reported line 63)May include surrounding context.

bash
# Step 1: Send request without auth
curl -i -X POST https://provebeforeact.com/api/proof \
  -H "Content-Type: application/json" \
  -d '{"file_hash":"abc123...64hex","filename":"output.pdf"}'

Static analysis

No suspicious patterns detected.