Back to skill

Security audit

Skill Guard 1.0.2

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent security-scanning purpose, but its installer has real path-safety and supply-chain weaknesses that users should review before installing.

Review this skill before installing. Its goal is legitimate, but use only simple trusted slugs, avoid --skip-scan and --force unless you understand the effect, and prefer a version that validates paths, pins scanner dependencies, and avoids curl | sh setup instructions.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:93
Finding

Remote Installer Is Downloaded and Piped Directly Into a Shell

Content
View full analysis
/dev/null; then # Try sourcing uv env if [[ -f "$HOME/.local/bin/env" ]]; then source "$HOME/.local/bin/env" fi if ! command -v uvx &> /dev/null; then print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh" exit 1 fi fi ``` ### Technical Analysis The documented command retrieves a mutable shell script from an external host and sends it directly to `sh`. There is no version pinning, checksum validation, signature verification, or opportunity to inspect the downloaded content before execution. Although `astral.sh` appears to be the expected upstream source for the declared `uv` dependency, this construction makes the effective code executed by users dependent on the response returned at execution time. Compromise of the upstream distribution service, DNS resolution, TLS trust chain, or release infrastructure could replace the installer after the Skill has been audited. The command is not automatically executed by `safe-install.sh`; it is presented as an instruction and error-message recommendation. Nevertheless, following the documented installation procedure creates a remote code-execution channel. ### Attack Path 1. An attacker compromises the installer host, its deployment infrastructure, DNS resolution, or another trusted component in the delivery path. 2. The attacker modifies the response returned for `https://astral.sh/uv/install.sh`. 3. A user follows the requirement printed in `SKILL.md` or the error message in `safe-in ...[truncated 701 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/safe-install.sh:121
Finding

Mutable Latest Version of Third-Party Scanner Is Executed at Runtime

Content
View full analysis
&1) || scan_exit_code=$? echo "$scan_output" echo "" # Check for issues in output (mcp-scan reports vulnerabilities, injections, etc.) if echo "$scan_output" | grep -Eqi "vulnerability|injection|malware|secret found|unsafe|high risk|medium risk|critical"; then return 1 # Issues found fi if [[ $scan_exit_code -ne 0 ]]; then print_warning "Scanner returned non-zero exit code: $scan_exit_code" return 1 fi return 0 # Clean } ``` ### Technical Analysis The `@latest` selector resolves mutable third-party package content each time the scan runs. Consequently, code that was not present during review may later be downloaded and executed automatically. The scanner necessarily receives access to the staged Skill, but the process also inherits the invoking user's environment and normal filesystem/network permissions unless the runtime independently provides isolation. The wrapper does not establish a sandbox, clear sensitive environment variables, restrict network access, or pin the dependency to an audited release. This behavior is related to the declared scanning functionality, but it exceeds the minimum supply-chain trust necessary. A reproducible implementation can perform the same function using a reviewed and pinned scanner version. ### Attack Path 1. An attacker compromises the scanner package, a maintainer account, package registry publication credentials, or a future release. 2. The malicious ...[truncated 767 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe-install.sh:93
Finding

Unvalidated Skill Slug Enables Filesystem Path Traversal

Content
View full analysis
under workdir) if ! clawhub install "$SKILL_SLUG" $VERSION_ARG --workdir "$STAGING_DIR" 2>&1; then print_error "Failed to fetch skill from ClawHub" exit 1 fi # clawhub installs to /skills/ if [[ ! -d "$STAGING_DIR/skills/$SKILL_SLUG" ]]; then print_error "Skill not found in staging after download" exit 1 fi print_success "Skill staged at $STAGING_DIR/skills/$SKILL_SLUG" } ``` Additional affected operations include: ```bash if [[ -d "$SKILLS_DIR/$SKILL_SLUG" ]]; then if [[ -n "$FORCE_ARG" ]]; then rm -rf "$SKILLS_DIR/$SKILL_SLUG" else print_error "Skill already exists at $SKILLS_DIR/$SKILL_SLUG (use --force to overwrite)" exit 1 fi fi mv "$staged_path" "$SKILLS_DIR/" ``` ```bash cleanup() { rm -rf "$STAGING_DIR/skills/$SKILL_SLUG" 2>/dev/null || true } ``` ### Technical Analysis `SKILL_SLUG` is taken directly from a positional command-line argument and is not constrained to a single safe filename component. Quoting prevents shell word splitting and command substitution, but it does not prevent filesystem traversal through components such as `../`. The script constructs paths by concatenating trusted base directories with this unvalidated value. The initial `rm -rf` occurs before `clawhub` has an opportunity to validate or reject the slug. Therefore, reliance on possible downstream validation does not protect the first destructive operation. For ...[truncated 1496 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/safe-install.sh:181
Finding

Security Gate Can Be Disabled Through the Skip-Scan Option

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/safe-install.sh:121
Finding

Scanner Results Are Evaluated Using Fragile Text Matching

Content
View full analysis
&1) || scan_exit_code=$? echo "$scan_output" echo "" # Check for issues in output (mcp-scan reports vulnerabilities, injections, etc.) if echo "$scan_output" | grep -Eqi "vulnerability|injection|malware|secret found|unsafe|high risk|medium risk|critical"; then return 1 # Issues found fi if [[ $scan_exit_code -ne 0 ]]; then print_warning "Scanner returned non-zero exit code: $scan_exit_code" return 1 fi return 0 # Clean } ``` ### Technical Analysis The wrapper infers whether findings exist by searching human-readable scanner output for a limited set of English terms. Human-facing output is not a stable machine interface and can change between releases, particularly because the scanner is invoked with the mutable `@latest` selector. A finding could be missed if it uses different terminology, a new severity label, localized text, changed formatting, or a warning code without one of the selected words. If the scanner exits with status zero despite reporting such a finding, the wrapper classifies the Skill as clean. Conversely, benign explanatory text containing one of the keywords can produce a false positive. The implementation therefore does not reliably preserve either the scanner's finding semantics or severity model. ### Attack Path 1. A staged Skill triggers a scanner finding. 2. The scanner describes the issue using wording that does not match the hardcoded regular e ...[truncated 945 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (24)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: skill-guard
description: Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.
---

# skill-guard

**The only pre-install security gate for ClawHub skills.**

## Why skill-guard?

| | **VirusTotal** (ClawHub built-in) | **skillscanner** (Gen Digital) | **skill-guard** |
|---|---|---|---|
| **When it runs** | After publish (server-side) | On-demand lookup | **Before install (client-side)** |
| **What it checks**

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
t-side)** |
| **What it checks** | Malware signatures | Their database | **Actual skill content** |
| **Prompt injections** | ❌ | ❌ | ✅ |
| **Data exfiltration URLs** | ❌ | ❌ | ✅ |
| **Hidden instructions** | ❌ | ❌ | ✅ |
| **AI-specific threats** | ❌ | ❌ | ✅ |
| **Install blocking** | ❌ | ❌ | ✅ |

**VirusTotal** catches known malware binaries — but won't flag `<!-- IGNORE PREVIOUS INSTRUCTIONS -->`.

**skillscanner** checks if Gen Digital has reviewed it — but can't scan new or updated skills.

**skill-guard** uses [mcp-scan](https://github.com/invariantlabs-ai/mcp-scan) (Invariant Labs, acquired by Snyk) to analyze what's actually in the skill, catches AI-specific threats, and blocks install if issues are found.

## The Problem

Skills can contain:
- 🎭 **Prompt injections** — hidden "ignore previous instructions" attacks
- 💀 **Malware payloads** — dangerous commands disguised in natural language  
- 🔑 **Hardcoded secrets** — API keys, t

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## The Problem

Skills can contain:
- 🎭 **Prompt injections** — hidden "ignore previous instructions" attacks
- 💀 **Malware payloads** — dangerous commands disguised in natural language  
- 🔑 **Hardcoded secrets** — API keys, tokens in plain text
- 📤 **Data exfiltration** — URLs that leak your conversations, memory, files

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
./scripts/safe-install.sh some-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
Skill stays in `/tmp/skill-guard-staging/skills/<slug>/` (quarantined). You can:
1. **Review** — read the scan output, inspect the files
2. **Install anyway** — `mv /tmp/skill-guard-staging/skills/<slug> ~/.openclaw/workspace/skills/`
3. **Discard** — `rm -rf /tmp/skill-guard-staging/`

## Requirements

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

rm -rf "$STAGING_DIR/skills/$SKILL_SLUG" uses user-controlled SKILL_SLUG in a filesystem-destructive operation with no validation. A slug containing path traversal sequences like ../../... could cause deletion outside the intended staging subtree if accepted by argument parsing and path resolution.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 96)May include surrounding context.

sh
stage_skill() {
    print_info "Fetching $SKILL_SLUG to staging area..."
    
    rm -rf "$STAGING_DIR/skills/$SKILL_SLUG"
    mkdir -p "$STAGING_DIR"
    
    # Install to staging directory (clawhub creates skills/<slug> under workdir)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

When --force is used, rm -rf "$SKILLS_DIR/$SKILL_SLUG" deletes a path built from attacker-controlled input. Without validating the slug or checking the canonical path stays within $SKILLS_DIR, a crafted slug could target arbitrary directories reachable by the executing user.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 151)May include surrounding context.

sh
if [[ -d "$SKILLS_DIR/$SKILL_SLUG" ]]; then
        if [[ -n "$FORCE_ARG" ]]; then
            rm -rf "$SKILLS_DIR/$SKILL_SLUG"
        else
            print_error "Skill already exists at $SKILLS_DIR/$SKILL_SLUG (use --force to overwrite)"
            exit 1

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The cleanup function repeats the same unsafe deletion pattern on a path derived from SKILL_SLUG. Because cleanup may run regardless of prior state, this broadens the opportunities for unintended deletion if the slug is malicious or malformed.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 165)May include surrounding context.

sh
# Cleanup staging
cleanup() {
    rm -rf "$STAGING_DIR/skills/$SKILL_SLUG" 2>/dev/null || true
}

# Main flow

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/safe-install.sh (reported line 205)May include surrounding context.

sh
echo "Options:"
        echo "  1. Review the issues above and decide if they're acceptable"
        echo "  2. Run: mv $STAGING_DIR/skills/$SKILL_SLUG $SKILLS_DIR/ to install anyway"
        echo "  3. Run: rm -rf $STAGING_DIR/skills/$SKILL_SLUG to discard"
        echo ""
        exit 2  # Exit code 2 = issues found, not installed
    fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script advertises scanning before installation, but it first runs clawhub install into a staging directory. If clawhub install performs any install-time hooks, template expansion, dependency resolution, or other side effects, untrusted skill content may already have been processed before the scan result is known.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 48)May include surrounding context.

sh
echo ""
            echo "Options:"
            echo "  --version <ver>  Install specific version"
            echo "  --force          Overwrite existing installation"
            echo "  --skip-scan      Skip security scan (not recommended)"
            echo "  --help           Show this help"
            echo ""

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The script executes uvx mcp-scan@latest, which pulls and runs the latest scanner code at install time. Using @latest makes the trust boundary mutable: a compromised upstream release or dependency could execute unexpected code during a security-sensitive pre-install check.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The skill recommends installing a dependency via 'curl ... | sh', which executes network-fetched code directly in the shell without prior verification. If the remote script, transport path, or hosting account were compromised, users could execute arbitrary code during setup.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
## Requirements

- `clawhub` CLI — `npm i -g clawhub`
- `uv` — `curl -LsSf https://astral.sh/uv/install.sh | sh`

## Why This Matters

External Script Fetching

Low
Category
Supply Chain
Confidence
15% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/safe-install.sh (reported line 86)May include surrounding context.

sh
source "$HOME/.local/bin/env"
        fi
        if ! command -v uvx &> /dev/null; then
            print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh"
            exit 1
        fi
    fi

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The implementation uses clawhub install while comments and UX describe this as a simple fetch to staging. That mismatch can mislead users and reviewers into believing the content remains passive, when the underlying tool may already be performing install semantics with side effects.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.prompt_injection_instructions

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:22