Back to skill

Security audit

Skills Manager CLI

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide for using the Skills Manager CLI to manage skill links, with real filesystem changes that users should approve before applying.

Install only if you want an agent or terminal workflow to manage Skills Manager state across your AI tools. Before running mutating commands, especially adopt, fix --yes, enable, disable, or init, preview affected paths where possible and confirm the target tool and skill IDs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
`description`. A directory is a skill if it contains `SKILL.md`,

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

MCP server references in the skill manifest without version pinning are a rug-pull risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says to use this skill whenever a user or agent needs to manage skills from a terminal, SSH session, CI job, or headless machine, and also when a skill is missing in many supported tools. This activation guidance is broad and open-ended rather than tied to a narrow trigger phrase or explicit constraints, which could cause unintended invocation in common troubleshooting contexts.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
[**Skills Manager**](https://skillsmanager.freeourdays.com) — a desktop app
(macOS / Windows / Linux) that installs one copy of a skill into a central hub
and symlinks it into every AI coding tool you use (Claude Code, Codex, Cursor,
Gemini, and ~30 more), so you write a skill once and it shows up everywhere.

If you found this skill on ClawHub but don't have Skills Manager yet, that is
the missing piece: `skm` is not a standalone binary you `npm install`. Get it

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill later documents that adopt moves real directories into the hub and that fix --yes performs write/repair operations, but the top-level workflow guidance does not foreground these destructive side effects before presenting the commands. In an agent setting, insufficiently prominent warnings can cause unexpected file moves, symlink rewrites, or state changes on disk without clear user awareness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
`init` on an already-initialized config returns
`{"already_initialized": true, ...}` and does nothing else. If
`config.json` exists but cannot be parsed, `init` refuses to overwrite it
— move or fix the file, then retry.

### Make an existing hub skill available to a tool

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that skm adopt --json without --yes still applies changes because the confirmation prompt is skipped. In an automation-oriented skill, users and agents commonly infer that --json is a safe machine-readable mode rather than an implicit authorization to mutate state, so this can cause unintended filesystem changes or skill adoption without explicit operator consent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/json.md (reported line 233)May include surrounding context.

md
## Concurrency

Write commands lock `~/.skills-manager/config.json` with
`try_lock_exclusive` (fail fast). Read-only `list`, `doctor`, and `fix`
without `--yes` take no lock. The GUI does not participate — last writer
wins against the app.

Static analysis

No suspicious patterns detected.