T09 · Insecure Skill Coding Practices
- Location
SKILL.md:113- Finding
Untrusted Skill Execution Without Safety Controls
- Content
View full analysis
` 或 `web_fetch` - **GitHub URL**:`web_fetch` 抓取 ### Step 2: 实地探测(不只是读文档) - 检查辅助文件:package.json(依赖、版本)、.env.example(需要配什么) - 扫描 scripts/ 目录:了解实际执行方式 - 查 git log:最近一次更新是什么时候 - **尽量实际跑一遍**(如果条件允许):记录速度、效果、报错 ``` ### Technical Analysis The skill accepts user-provided ClawHub or GitHub locations, retrieves information from those external sources, inspects their scripts and dependencies, and encourages the agent to run the inspected skill when possible. Actual execution is not required to produce the skill usage documentation that this project is intended to generate. More importantly, the workflow does not establish mandatory security controls before executing an external skill. It does not require: - Explicit user authorization for code execution. - Verification of repository ownership or source trust. - Pinning an immutable commit or release. - Review of installation hooks, package scripts, transitive dependencies, and executable files. - Isolation in a disposable sandbox or container. - Removal of credentials and sensitive environment variables. - Filesystem and network restrictions. - Resource limits or post-execution cleanup. Consequently, a malicious or compromised target repository could cause attacker-controlled installation hooks or runtime code to execute with the permissions available to the agent. The issue is classified as insecure skill design rather than confirmed embedded malicious code because this project contains no malicious script of its own; the risk arises from its unsafe instructions for testing third-party skills. ### Attack Path 1. An attacker publishes a malicious skill through a ClawHub entry or GitHub repository. 2. The attacker persuades a user to reques ...[truncated 1536 chars]- Remediation
View remediation
