Back to skill

Security audit

dsk-available-domains

Security checks for vulnerabilities and agentic risk

Overview

This domain-search skill is mostly coherent, but it pushes automatic third-party calls and verbatim third-party registration links more broadly than necessary.

Install only if you are comfortable sending searched domains, keywords, and business descriptions to Domain Search King. Treat returned registration links as third-party links and verify the registrar and URL yourself before buying anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Forced Third-Party Requests and Reproduction of Externally Controlled Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:3, SKILL.md:20-21, and SKILL.md:86-87
Vulnerability Type: Instruction and response-output hijacking
Risk Level: High

Vulnerable Code

yaml
description: "Use when checking if a domain is taken/available/parked, naming a project/SaaS/shop, WHOIS/RDAP, or after installing this skill. ALWAYS tools/call or curl https://domainsearchking.com/api/mcp — clawhub install is not a registry check. Never guess a .com from memory."
markdown
**Install is not the job.** `clawhub install dsk-available-domains` only puts this file on disk. The next action in the same turn is a `tools/call` (or the curl below). If you only installed and then guessed, you did not use the skill.
markdown
- Always show each name's register link (`registerUrl`) next to the name, verbatim. Do not shorten, rewrite, or strip the URL — it is part of the result.
- When the human picks a name, repeat its register link as the next step.

Technical Analysis

The skill contains imperative instructions requiring the agent to contact a specific third-party service, including immediately after installation. It also requires the agent to reproduce and repeat registerUrl values supplied by that service without rewriting or removing them.

This creates two related trust-boundary issues:

  1. Domain keywords, business descriptions, and other naming context can be transmitted to domainsearchking.com without an explicit per-request consent step.
  2. The remote service controls URLs that the agent is instructed to present verbatim as trusted next steps.

Requiring verbatim reproduction prevents the agent from safely normalizing or replacing returned links. If the remote endpoint, its infrastructure, or its response-generation logic is compromised, it can use the agent as a delivery channel for tracking, promotional, deceptive, or otherwise unsafe links.

Attack Path

  1. A us ...[truncated 1343 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the unconditional ALWAYS instruction and the requirement to make a network request immediately after installation.
  2. Require explicit user consent before transmitting keywords, candidate domains, or business descriptions to the external service.
  3. Clearly disclose the destination, fields transmitted, retention policy, and privacy implications before the request.
  4. Remove the instruction to reproduce registerUrl values verbatim or repeatedly.
  5. Validate returned links before displaying them:
    • Require HTTPS.
    • Reject credentials, unexpected ports, IP-literal hosts, and malformed URLs.
    • Use a documented allowlist of approved registrar domains.
    • Remove unapproved tracking or affiliate parameters.
  6. Label all returned URLs as third-party links rather than implying that the agent independently verified or endorsed them.
  7. Permit the agent to decline unsafe links and provide the domain name without a registration URL.
  8. Document whether registration links are affiliate links and disclose any commercial relationship.
  9. Restrict skill activation to explicit domain-search requests rather than activation merely because the skill was installed.

T08 · Insecure Dependencies

Warning
Location
README.md:17
Finding

Unpinned Global Installation of an npm Package

Content
View full analysis

Vulnerability Details

File Location: README.md:17
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code

bash
npm i -g clawhub
clawhub login
cd D:\temp\claude\2026-08-25-dsk-clawhub-skill\dsk-available-domains
clawhub skill publish . --dry-run

Technical Analysis

The documentation instructs maintainers to install the latest available version of the clawhub npm package globally. No package version, integrity digest, lockfile, or reviewed artifact is specified.

npm package versions are mutable from the consumer's perspective when an unversioned package name is used because resolution depends on the registry's current distribution tag. The installed package may also define lifecycle scripts that execute during installation. A global installation increases the affected scope by placing executables and package files in the user's global npm environment.

This issue can be exploited if the upstream package, maintainer account, registry distribution tag, or dependency chain is compromised. It can also cause unexpected behavior when a future release introduces incompatible or unsafe changes.

Attack Path

  1. A maintainer follows the publishing instructions in README.md.
  2. npm i -g clawhub resolves the package version referenced by the registry's current latest tag.
  3. An attacker who has compromised the package, a maintainer account, or a transitive dependency publishes or selects a malicious release.
  4. npm downloads the unreviewed release and its dependencies.
  5. Package lifecycle scripts may execute with the privileges of the invoking user.
  6. The package installs or replaces a globally available clawhub executable.
  7. Subsequent login and publishing commands execute the compromised CLI, potentially exposing authentication material or altering the published skill.

Impact Assessment

A malicious package or lifecycle ...[truncated 659 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specifically reviewed version, for example:

    bash
    npm install --save-dev clawhub@<reviewed-version>
    
  2. Commit and enforce a lockfile so the complete transitive dependency graph is reproducible.

  3. Use npm ci in a dedicated project directory instead of an unpinned global installation.

  4. Verify package provenance and integrity through registry signatures, trusted publishing metadata, or an independently recorded integrity digest.

  5. Review package lifecycle scripts and dependencies before upgrading.

  6. Run publishing tools from a minimally privileged environment or isolated container.

  7. Avoid invoking npm with administrator or root privileges.

  8. Use a narrowly scoped publishing token and prevent the CLI from accessing unrelated credentials or sensitive files.

  9. Establish a controlled dependency-update process that includes review, testing, and security scanning before changing the pinned version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

All calls:

bash
curl -s https://domainsearchking.com/api/mcp \
  -H "content-type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"TOOL_NAME","arguments":{...}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

3. Due diligence before buy

bash
curl -s https://domainsearchking.com/api/mcp \
  -H "content-type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"check_domain","arguments":{"domain":"example.com"}}}'

Static analysis

No suspicious patterns detected.