Back to skill

Security audit

clawagent

Security checks for vulnerabilities and agentic risk

Overview

The skill’s marketing and media-generation purpose is coherent, but its update, upload, install, and credential flows grant enough under-scoped authority that users should review it carefully before installing.

Install only if you trust the publisher and ClawAgent service with your social accounts, media, and token. Use a least-privilege temporary token, avoid shared machines, do not run setup or upload with sudo, only upload files you intentionally selected, and do not approve remote skill updates unless the exact commands and changed files are clear.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
upload.mjs:86
Finding

Remote-Controlled Local File Upload Enables Arbitrary File Exfiltration

Content
View full analysis
maxSize) { console.log( ...[truncated 2841 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
setup.mjs:84
Finding

Authentication Token Exposed Through Command-Line Arguments and Shell Commands

Content
View full analysis
``` 2. The shell records the command in history, depending on shell configurati ...[truncated 860 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.mjs:44
Finding

Unpinned Global Installation of a Mutable Third-Party Package

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:154
Finding

Remote Update Response Can Supply Instructions for Local Execution

Content
View full analysis
"}' | mcporter call ClawAgent.check_skill_update --args -` 3. 有新版本时展示 release_note,用户确认后按 instruction 执行更新 ``` Obtaining user confirmation is a useful safeguard, but it does not establish the safety of the returned instruction. The effective update payload is not included in the audited package and can change after review. No restrictions require the instruction to use a trusted package source, match a cryptographic signature, remain within the Skill directory, or avoid arbitrary shell commands. This creates a remote code-execution channel through natural-language agent instructions. A benign-looking release note can be paired with a dangerous update instruction, and the user cannot reliably assess the hidden command-level consequences from a generic update confirmation. ### Attack Path 1. The remote update service, its credentials, or its network/software supply chain is compromised. 2. The attacker returns a plausible `release_note` and a malicious `instruction`, such as a command that downloads and runs a script or replaces local Skill files. 3. The agent displays the release note and requests general confirmation. 4. The user approves the update, believing it to be a normal Skill update. 5. Following `SKILL.md`, the agent executes the remotely supplied instruction. 6. The payload runs with the agent's local privileges and can modify files, steal credentials, install persistence, or alter future Skill behavior. ### Impact Assessment The instruction can potentially obtain arbitrary code execution with ...[truncated 437 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

This duplicate finding points to the same unsafe pattern: raw curl use against untrusted URLs with redirect following. In a skill that also uploads files and interfaces with external publishing systems, this broad fetch primitive can become a stepping stone for network abuse and validation bypass.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
**公网URL**:

- 必须先验证可访问性:`curl -I --max-time 5 -L <URL>`
- HTTP 200 → 直接传入工具
- 403/401 → 告知"链接需要登录或权限"
- 404 → 告知"链接已失效"

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

This duplicate finding points to the same unsafe pattern: raw curl use against untrusted URLs with redirect following. In a skill that also uploads files and interfaces with external publishing systems, this broad fetch primitive can become a stepping stone for network abuse and validation bypass.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
**公网URL**:

- 必须先验证可访问性:`curl -I --max-time 5 -L <URL>`
- HTTP 200 → 直接传入工具
- 403/401 → 告知"链接需要登录或权限"
- 404 → 告知"链接已失效"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs use of shell commands and network access (mcporter, curl, node upload.mjs) but declares no restrictive tool scope such as permissions or allowed-tools. That creates unnecessary ambient authority: if this skill is invoked or extended incorrectly, an agent may perform network and shell actions beyond the minimally required set.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description says it should be invoked whenever a user needs AIGC generation or social-media operations, which is very broad and overlaps with common conversation topics. Over-broad routing can trigger a skill that performs uploads, external API calls, and publishing actions in contexts where the user did not intend to authorize those behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger table contains many colloquial phrases like '分析一下', '发视频', '换个背景', and similar everyday wording without boundary conditions. This increases the chance of accidental invocation of tools that can upload files, contact remote services, inspect URLs, or publish to social accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to provide public URLs for videos, images, and audio, but it does not warn that those assets will be transmitted to external services for processing and may contain personal, copyrighted, or otherwise sensitive content. In an enterprise marketing context, this omission can lead to accidental disclosure of internal media, creator likenesses, or customer data through third-party AI processing pipelines.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill description, parameter values, and usage guidance are presented only in Chinese, with no indication that users may choose another language or locale. This can violate language/locale policy when the skill implicitly constrains interaction to a specific language without documenting opt-in or regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document forces a specific language for all operational and safety instructions, which can violate language/locale policy when no user opt-in or alternative is provided. Because the file contains setup, token handling, and warning guidance, lack of language choice may prevent some users from understanding important instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents the skill title, parameters, and constraints entirely in Chinese, which can amount to a language/locale policy violation if users are not given an opt-in or alternative language. The file does not state that the skill is region-specific or that Chinese is required for a justified compliance or product reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is entirely written in Chinese and the example parameter values and prompt text are all Chinese-only, with no indication that other languages are supported or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation instructs users to provide a public image URL for clothing images but does not warn that doing so exposes asset URLs and may share user-controlled or proprietary media with external services. In an enterprise marketing context, these images can contain unreleased products, campaign assets, or licensed content, so omission of privacy and data-handling guidance creates a real data exposure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The API contract hard-codes gender to a male/female binary without documenting a technical necessity or policy basis, which can cause discriminatory behavior, exclusion, or incorrect outputs for users who do not fit or do not wish to disclose that classification. In a model try-on workflow, this design choice can propagate bias into generated marketing content and create compliance and reputational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire workflow documentation is written in Chinese and includes Chinese-only interface descriptions and examples, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the stated policy, a skill that forces a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly supports save_token <token> on the command line, which exposes the token to shell history, process listings, audit logs, and agent telemetry. Because this token appears to authorize access to the ClawAgent backend, accidental disclosure could let another local user or monitoring system reuse the credential.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup script automatically installs and executes a global npm package (mcporter) via shell commands during configuration. That introduces supply-chain and arbitrary-code-execution risk unrelated to the core end-user purpose of generating marketing/AIGC content, because installation of a privileged global dependency can run package lifecycle scripts and modify the host environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing comments, usage instructions, warnings, and runtime messages are written in Chinese, and the script does not provide any option to select another language. This creates a language/locale policy concern because it effectively requires Chinese comprehension for safe and correct use without explicit user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

整个 SKILL.md 仅以中文提供使用说明、警示和操作要求,未见提供语言/地区选择、双语说明或明确声明仅面向特定中文用户群体。按规则,若技能强制特定语言而无用户选择或合理限定,属于自然语言层面的策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The parameter description constrains gender to only 男 or 女, which is a natural-language policy concern because it imposes a fixed binary classification without documenting broader user choice or justification. This is a locale/policy-style constraint expressed in natural language rather than a technical necessity explained in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s title, usage notes, parameter descriptions, and constraints are entirely in Chinese, which imposes a specific language on users. Under the policy, locale or language restrictions should either offer user choice or be clearly documented as justified for a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's natural-language comments and user-visible console output are written in Chinese, and the script does not offer any language or locale selection. This can violate a language-choice policy when users are not given an opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
setup.mjs:30