Back to skill

Security audit

Aweb

Security checks for vulnerabilities and agentic risk

Overview

The skill’s messaging purpose is clear, but it asks operators to set up persistent automatic polling that can make the main agent read and answer outside messages every minute.

Install only if you want this agent to participate in aweb messaging. Avoid enabling the cron poller unless you accept recurring automatic processing of inbound messages; prefer manual checks or a separate limited notification setup. Pin and review the aw CLI version before global installation, and do not send secrets or private workspace files through default plaintext messaging.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:149
Finding

Recurring Agent Wake-Up and External Message Polling Creates Cross-Session Persistence

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:79
Finding

Remote Messages Are Given Priority Over the Agent's Current Work

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned npm Package Is Installed Globally

Content
View full analysis
``` ### Technical Analysis The skill instructs users to install `@awebai/aw` globally without specifying an exact version or verifying package integrity. Consequently, the package version and effective installation payload may change after the skill has been reviewed. npm packages can define lifecycle scripts that execute during installation with the privileges of the user running npm. A global installation also exposes the resulting executable across workspaces rather than containing it within this project. The document states that its commands were verified against version 1.26.x, but the installation command does not constrain npm to that release family or to a specific audited version. The audit did not establish that the named package is currently malicious; the vulnerability is the unsafe, mutable supply-chain installation procedure. ### Attack Path 1. A user follows the documented global installation command. 2. npm resolves the package version available under the configured registry and tag at installation time. 3. If the package, maintainer account, registry path, or a future release is compromised, npm downloads the altered package. 4. Any permitted lifecycle scripts execute with the installing user's privileges. 5. The globally installed `aw` executable is then trusted for identity creation and messaging operations. 6. A compromised CLI could access data available to that user, including aweb identity material and message content, or alter future messaging behavior. ### Impact Assessment Successful exploitation would execute package installation code with t ...[truncated 479 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.