Back to skill

Security audit

robot-paper-post

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated writing purpose, but its article template can add an unsolicited promotional footer to publication-ready output.

Review or remove the Mbot footer before using the template for anything public. Prefer a pinned, trusted ClawHub installer version instead of @latest, and be aware that the optional local image-download script referenced by the docs was not included in this artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
assets/post-template.md:145
Finding

Forced Third-Party Promotional Content in Generated Articles

Content
View full analysis
关注 Mbot 具身智能实验室,第一时间追踪机器人前沿干货。 ``` English translation: “Follow Mbot Embodied Intelligence Laboratory to receive the latest robotics content.” ### Technical Analysis The Skill directs the agent to use `assets/post-template.md` when drafting an article. That template contains a fixed promotional footer for “Mbot Embodied Intelligence Laboratory.” The footer is unrelated to the technical analysis requested by the user and is not presented as optional or disclosed as sponsored content. Because the Skill aims to produce publication-ready articles, template content can be carried directly into the final deliverable. This changes the output from a user-directed paper analysis into content that also promotes a third party. The behavior is best classified as instruction hijacking because Skill-controlled instructions alter the final output for an undeclared promotional objective. ### Attack Path 1. A user requests a robotics-paper analysis or publication-ready article. 2. The agent loads `SKILL.md`. 3. The drafting workflow directs the agent to read `assets/post-template.md`. 4. The agent fills in the template while retaining its fixed footer. 5. The user receives or publishes an article containing an unsolicited third-party promotion. ### Impact Assessment This issue does not grant operating-system privileges, access credentials, or control over local resources. Its impact is limited to the agent’s generated content and the user’s publication workflow. An affected user may unknowingly publish third-party advertising under their own ...[truncated 174 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:20
Finding

Execution of a Mutable Latest-Version Package During Installation

Content
View full analysis
Remediation
View remediation
install robot-paper-post ``` 2. Document the expected npm registry and verified package publisher. 3. Use a lockfile or equivalent integrity mechanism where the installation workflow permits it. 4. Publish and verify package integrity hashes or signed release provenance. 5. Recommend installation only from trusted registries and clean environments. 6. Review new package versions before updating the documented command. 7. Avoid instructing users to run the installation command with administrative or root privileges. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to run npx clawhub@latest install robot-paper-post, which pulls and executes the latest published package code at runtime rather than a pinned, reviewed version. If the upstream package is compromised, typosquatted, or updated maliciously, users could execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and opening goal state the skill generates 技术推文/公众号文章 in Chinese, and the rest of the document consistently frames output as Chinese public-account copy. There is no indication that the user may choose another language or locale, so the skill imposes a language preference without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description explicitly states the skill generates content in Chinese, which can override or preempt the user's language preference. While this is not a direct code-execution or data-exfiltration issue, it can cause unintended behavior, reduce usability, and in agent settings may lead to outputs that the user cannot adequately review or verify.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all instructions, examples, and templates exclusively in Chinese, which effectively forces a specific language for users consuming the skill guidance. Under the policy, language constraints should either be optional or clearly justified as region- or audience-specific.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all headings, instructions, and descriptions only in Chinese, with no indication that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing workflow instructions exclusively in Chinese, which can amount to a language/locale policy issue if the organization expects skills to avoid forcing a specific language without opt-in. No alternative language option or justification for a Chinese-only audience is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire reference document is written in Chinese and the usage guidance assumes Chinese-language output contexts such as drafting posts, but it does not provide an opt-in choice for language or explain that the skill is intentionally region- or language-specific. Under the policy, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructional content in a single language and does not indicate that the user can select another language. Under the language/locale policy check, forcing one language without opt-in can be considered a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.