Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md `description`. A directory is a skill if it contains `SKILL.md`,
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed guide for using the Skills Manager CLI to manage skill links, with real filesystem changes that users should approve before applying.
Install only if you want an agent or terminal workflow to manage Skills Manager state across your AI tools. Before running mutating commands, especially adopt, fix --yes, enable, disable, or init, preview affected paths where possible and confirm the target tool and skill IDs.
Referenced artifact was not completely inspected
`description`. A directory is a skill if it contains `SKILL.md`,
MCP server references in the skill manifest without version pinning are a rug-pull risk.
The description says to use this skill whenever a user or agent needs to manage skills from a terminal, SSH session, CI job, or headless machine, and also when a skill is missing in many supported tools. This activation guidance is broad and open-ended rather than tied to a narrow trigger phrase or explicit constraints, which could cause unintended invocation in common troubleshooting contexts.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
[**Skills Manager**](https://skillsmanager.freeourdays.com) — a desktop app
(macOS / Windows / Linux) that installs one copy of a skill into a central hub
and symlinks it into every AI coding tool you use (Claude Code, Codex, Cursor,
Gemini, and ~30 more), so you write a skill once and it shows up everywhere.
If you found this skill on ClawHub but don't have Skills Manager yet, that is
the missing piece: `skm` is not a standalone binary you `npm install`. Get it
The skill later documents that adopt moves real directories into the hub and that fix --yes performs write/repair operations, but the top-level workflow guidance does not foreground these destructive side effects before presenting the commands. In an agent setting, insufficiently prominent warnings can cause unexpected file moves, symlink rewrites, or state changes on disk without clear user awareness.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
`init` on an already-initialized config returns
`{"already_initialized": true, ...}` and does nothing else. If
`config.json` exists but cannot be parsed, `init` refuses to overwrite it
— move or fix the file, then retry.
### Make an existing hub skill available to a tool
The documentation states that skm adopt --json without --yes still applies changes because the confirmation prompt is skipped. In an automation-oriented skill, users and agents commonly infer that --json is a safe machine-readable mode rather than an implicit authorization to mutate state, so this can cause unintended filesystem changes or skill adoption without explicit operator consent.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## Concurrency
Write commands lock `~/.skills-manager/config.json` with
`try_lock_exclusive` (fail fast). Read-only `list`, `doctor`, and `fix`
without `--yes` take no lock. The GUI does not participate — last writer
wins against the app.
No suspicious patterns detected.