Back to skill

Security audit

Share use case

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but its OAuth flow handles credential data too broadly while preparing a public submission from recent chat context.

Install only if you are comfortable with the assistant reviewing recent conversation context to draft a public use case and sending the approved content to clawusecase.com. Use anonymous submission if you do not need attribution, and avoid sharing sensitive project details, secrets, internal URLs, or private customer information in the draft. If using OAuth attribution, be aware the current scripts handle a raw credential response in command output/tool logs rather than only allowlisted public profile fields.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
get-credential.js:78
Finding

OAuth Polling Token and Credential Object Exposed Through Process Arguments and Standard Output

Content
View full analysis

Vulnerability Details

File Location: get-credential.js:78-116, poll-credential.sh:10-27, SKILL.md:127-168
Vulnerability Type: Sensitive authentication material exposure
Risk Level: Medium

Vulnerable Code

get-credential.js:78-116:

javascript
async function main() {
  const args = parseArgs();
  
  if (!args.token) {
    console.error('❌ Missing --token argument');
    console.error('Usage: node get-credential.js --token abc123');
    process.exit(1);
  }
  
  try {
    console.error('🔍 Retrieving OAuth credential...');
    
    const result = await queryConvex('oauth:getToken', { token: args.token });
    
    if (!result.value) {
      console.error('❌ Token not found or expired');
      process.exit(1);
    }
    
    if (!result.value.credential) {
      console.error('⏳ Authentication not yet completed');
      console.error('Make sure the user has clicked the OAuth link and authorized the app.');
      process.exit(1);
    }
    
    // Output credential as JSON
    console.log(JSON.stringify(result.value.credential, null, 2));
    
  } catch (err) {
    console.error('❌ Failed to retrieve credential:', err.message);
    process.exit(1);
  }
}

main();

poll-credential.sh:10-27:

bash
TOKEN=$1
MAX_ATTEMPTS=${2:-24}  # Default: 24 attempts (2 minutes at 5s intervals)

if [ -z "$TOKEN" ]; then
  echo "Error: Missing token argument" >&2
  echo "Usage: $0 TOKEN [MAX_ATTEMPTS]" >&2
  exit 2
fi

for i in $(seq 1 $MAX_ATTEMPTS); do
  # Try to get credential
  RESULT=$(node "$(dirname "$0")/get-credential.js" --token "$TOKEN" 2>/dev/null)
  
  if [ $? -eq 0 ]; then
    # Success! Output credential and exit
    echo "$RESULT"
    exit 0
  fi

SKILL.md:127-168 also directs the agent to place the token in a command argument and retain the complete credential in a shell variable:

bash
RESULT=$(
...[truncated 3305 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove secrets from command-line arguments

    • Read the polling token from protected standard input.
    • Alternatively, use a mode-0600 temporary file or inherited file descriptor.
    • Avoid placing tokens in environment variables when process environments may be observable.
  2. Do not return the complete credential object

    • Extract only the fields required for submission, such as a validated username, platform, display handle, and public profile URL.
    • Construct a new allowlisted output object instead of serializing the remote response directly.
    • Explicitly discard access tokens, refresh tokens, session identifiers, and provider response metadata.
  3. Avoid credential propagation through shell variables and stdout

    • Replace CREDENTIAL="$RESULT" with parsing that retains only approved public fields.
    • Ensure agent tool output and application logs never contain the raw token or credential response.
    • Add centralized redaction for token-shaped values and known sensitive property names.
  4. Harden polling-token lifecycle controls

    • Use cryptographically random, single-use polling tokens.
    • Bind each token to the initiating session and intended OAuth provider.
    • Apply a short expiration and atomically invalidate the token immediately after successful retrieval.
    • Prevent repeated retrieval of an already-consumed credential.
  5. Validate the remote response

    • Enforce a strict schema and reject unexpected credential properties.
    • Verify that the returned identity corresponds to the current OAuth session.
    • Return a generic failure message without embedding remote response bodies that may contain sensitive data.
  6. Update the Skill instructions

    • Remove the recommendation to store the full response in CREDENTIAL.
    • Instruct the agent to handle only allowlisted public attribution fields.
    • Document that OAuth tok ...[truncated 112 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to analyze recent work and automate submission, but the actual workflow depends on shell commands, explicit CLI parameters, and outbound submission behavior that is not cleanly disclosed in permissions or metadata. This kind of description-behavior mismatch can trick users into authorizing data access or network operations under a narrower perceived purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to analyze recent work and automate submission, but the actual workflow depends on shell commands, explicit CLI parameters, and outbound submission behavior that is not cleanly disclosed in permissions or metadata. This kind of description-behavior mismatch can trick users into authorizing data access or network operations under a narrower perceived purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to analyze recent work and automate submission, but the actual workflow depends on shell commands, explicit CLI parameters, and outbound submission behavior that is not cleanly disclosed in permissions or metadata. This kind of description-behavior mismatch can trick users into authorizing data access or network operations under a narrower perceived purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims to analyze recent work and automate submission, but the actual workflow depends on shell commands, explicit CLI parameters, and outbound submission behavior that is not cleanly disclosed in permissions or metadata. This kind of description-behavior mismatch can trick users into authorizing data access or network operations under a narrower perceived purpose.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

md
- `SKILL.md` - This file (instructions)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 129)May include surrounding context.

md
### Good 👍
**Title**: "Email notifications for Pro subscriptions"
**Hook**: "Automatically sends welcome emails when users upgrade"
**Problem**: "Users upgrading to Pro weren't receiving confirmation emails, leading to support tickets"
**Solution**: "Built a Resend email integration with React Email templates, connected to Stripe webhooks..."

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 321)May include surrounding context.

md
### Good 👍
**Title**: "Email notifications for Pro subscriptions"
**Hook**: "Automatically sends welcome emails when users upgrade"
**Problem**: "Users upgrading to Pro weren't receiving confirmation emails, leading to support tickets"
**Solution**: "Built a Resend email integration with React Email templates, connected to Stripe webhooks..."

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs use of local scripts, polling, OAuth credential retrieval, and likely environment/network-backed operations, but declares no explicit tool scope or permissions. This weakens enforcement and transparency, increasing the chance the skill can access capabilities beyond what a user would reasonably expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to match normal conversation such as 'I want to share this use case,' which could invoke the skill unintentionally. In this context, accidental activation is more dangerous because the skill then analyzes recent conversation history and may initiate external submission or auth flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to inspect the last 50-100 messages or past few hours of conversation to draft a public submission, but does not require a prominent privacy warning or scoped consent first. This creates a meaningful privacy risk because sensitive project details, credentials, internal URLs, or personal information from prior context could be repurposed into a public post.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.