Back to skill

Security audit

Clawddocs Zc

Security checks for vulnerabilities and agentic risk

Overview

This is a Clawdbot documentation helper with mostly static guidance and simple shell stubs, but users should treat its copied gateway and credential examples carefully.

Before installing or using this skill, understand that its helper scripts are stubs and may not deliver the full documentation-search behavior advertised. If you copy its examples, keep provider tokens secret, protect WhatsApp session files, and prefer binding the gateway to localhost unless you intentionally need remote access and have strong network protections in place.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
snippets/common-configs.md:37
Finding

Gateway Configuration Exposes the Service on All Network Interfaces

Content
View full analysis

Vulnerability Details

File Location: snippets/common-configs.md, lines 37–45
Vulnerability Type: Insecure network exposure
Risk Level: Medium

Vulnerable Code

json
{
  "gateway": {
    "host": "0.0.0.0",
    "port": 8080
  }
}

Technical Analysis

The project presents this snippet as a ready-to-use gateway configuration. Setting the host to 0.0.0.0 causes the gateway to listen on every available network interface rather than restricting access to the local machine.

The example does not include authentication, TLS, firewall restrictions, or a warning that remote exposure must be intentional. A user who copies the snippet may therefore expose the gateway to a local network, container network, cloud network, or the public Internet, depending on the surrounding infrastructure.

The vulnerability is a failure of secure-by-default configuration and least network exposure. Whether exploitation succeeds ultimately depends on external controls and protections implemented by the gateway itself.

Attack Path

  1. A user copies the documented gateway configuration.
  2. The gateway binds to all interfaces on TCP port 8080.
  3. Network routing, container port publication, or permissive firewall rules make the port reachable by an untrusted party.
  4. The attacker scans for or otherwise discovers the exposed service.
  5. The attacker connects to gateway endpoints.
  6. If those endpoints lack independent authentication and authorization, the attacker accesses exposed gateway functionality or data.

Impact Assessment

The immediate impact is an expanded network attack surface. An attacker may gain remote access to any gateway endpoints that are reachable and insufficiently protected. The exact privileges obtainable cannot be established from this repository because the gateway implementation and its authentication controls are not included.

Potential scope includes ...[truncated 260 chars]

Remediation
View remediation

Remediation Suggestions

  • Change the default binding to localhost:

    json
    {
      "gateway": {
        "host": "127.0.0.1",
        "port": 8080
      }
    }
    
  • Clearly state that 0.0.0.0 must only be used when remote access is explicitly required.

  • Require strong authentication and authorization before permitting non-local access.

  • Restrict inbound traffic with host, cloud, or container firewall rules and allow only trusted source networks.

  • Use TLS for non-local connections, preferably through a securely configured reverse proxy.

  • Document container port-publication and cloud security-group implications.

  • Provide separate local-only and hardened remote-access examples so users do not unintentionally choose an exposed default.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad documentation assistant with multiple capabilities, but the supplied code chunk only prints a URL based on a provided path. While this is loosely related to documentation access, it does not implement most of the described behavior and even its stated fetch capability is not realized in code. This is a material description-to-behavior mismatch due to the much narrower and simpler actual functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a comprehensive Clawdbot documentation expert with several concrete capabilities. The actual code chunk is only a minimal shell script that echoes a recent-docs message based on a day parameter. It does not implement the declared search, navigation, fetching, version tracking, or snippet functionality. Because the provided behavior is materially narrower than the declared primary purpose, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

The declared description presents a broad documentation expert with multiple capabilities, but the supplied code chunk only contains a minimal search script stub. It validates an argument and echoes a message, with a comment stating that real search exists only in the full version. There is no implementation for decision-tree navigation, fetching documentation, tracking versions, or producing configuration snippets. Because the actual code is only a narrow placeholder and does not substantively realize the declared primary purpose, this is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction 'Use this skill to help users navigate, understand, and configure Clawdbot' and the surrounding quick-start triggering language imply the skill should activate whenever a user 'asks about Clawdbot,' which is a broad condition without explicit limits or exclusions. The file does not provide negative examples or narrow context boundaries, increasing the chance of unintended invocation for general Clawdbot mentions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file shows provider setup snippets using environment-backed tokens for Discord and Telegram and a local session path for WhatsApp, but it does not include any warning about safeguarding credentials or session artifacts. For markdown files, SQP-2 applies when descriptions omit warnings about behavior that could affect privacy or system integrity, and these snippets touch authentication material and persisted session data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.