Back to skill

Security audit

Clawbridge - Find your connections

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Clawbridge chat shortcut, but it directs users to execute an unverified remote installer and relies on an unseen runner that uploads discovery results.

Review this carefully before installing. Only install if you trust Clawbridge's remote installer and private runner, and prefer asking the publisher for a signed, versioned installer with checksums plus clear documentation of what the runner reads, uploads, stores, and how to uninstall it.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Unverified Remote Installer Is Downloaded and Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14

Complete Code Snippet:

yaml
install:
  - id: "install-script"
    kind: "shell"
    label: "Install via script (recommended)"
    command: "curl -fsSL https://clawbridge.cloud/install | bash"
    bins: ["clawbridge"]

Vulnerability Type: T03: Remote Payload Retrieval and Execution

Risk Level: High

Technical Analysis

The Skill declares an installation command that retrieves a mutable shell script from https://clawbridge.cloud/install and pipes it directly to Bash. The payload is executed without version pinning, checksum verification, cryptographic signature validation, or an opportunity to inspect it locally.

The repository contains only documentation and metadata; it does not include the installer or the resulting clawbridge executable. Consequently, the effective installation behavior cannot be audited from this package and can change after review without any corresponding update to the Skill.

This is especially risky because the repository describes the installed runner as implementing the substantive workflow: building private prompts, calling OpenClaw as a worker, and uploading results to an external Vault. While the upload behavior is disclosed, the installer, runner implementation, selected data, and safeguards are not available for verification.

Direct remote script execution is not necessary for the Skill's declared thin-wrapper functionality. A pinned, independently verifiable installation artifact would provide the required executable with substantially less supply-chain risk.

Attack Path

  1. A user or Skill manager processes the declared shell installer.
  2. curl requests the current content of https://clawbridge.cloud/install.
  3. The Clawbridge server, its hosting account, DNS path, TLS termination infrastructure, or deployment pipeline is compromised—or the publisher changes the script malicio ...[truncated 1080 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash installation command from Skill metadata.
  2. Distribute the runner through a trusted package registry or release system using immutable, versioned artifacts.
  3. Pin the exact package or artifact version rather than resolving the latest mutable installer.
  4. Publish SHA-256 or stronger checksums through an independently protected channel and verify them before execution.
  5. Prefer cryptographically signed releases and verify signatures against a documented, pinned publisher key.
  6. If a script remains necessary, download it to a local file, verify its integrity and signature, show users its source and requested changes, and require explicit confirmation before execution.
  7. Publish the installer and runner source, or reproducible build instructions, so their effective behavior can be audited.
  8. Document the runner's required filesystem, network, credential, and OpenClaw access. Run it with the minimum permissions needed for discovery and uploading.
  9. Avoid requiring administrator privileges. If any individual operation genuinely requires elevation, isolate and document that operation rather than elevating the entire installer.

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:73
Finding

Documentation Recommends Direct Execution of an Unverified Remote Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:73-78

Complete Code Snippet:

bash
# 1. Install runner
curl -fsSL https://clawbridge.cloud/install | bash

# 2. Link workspace (get code from your workspace page)
clawbridge link CB-XXXXXX

Vulnerability Type: T03: Remote Payload Retrieval and Execution

Risk Level: High

Technical Analysis

The prerequisite instructions explicitly direct users to fetch a remote shell script and execute it immediately. No immutable version, checksum, signature, trusted package-manager provenance, or local review step is supplied.

Although this occurrence reaches the same remote endpoint as the metadata installer, it is a separate user-facing execution path: users who follow the manual setup instructions remain exposed even if automated metadata installation is disabled. The later workspace-linking step may also make a maliciously substituted runner appear legitimate while allowing it to process a user-provided linking code.

The repository identifies the Skill as an optional chat shortcut and states that the private runner owns all product logic. Therefore, security properties of the installed runner cannot be inferred from this small repository. Recommending direct execution of its mutable installer creates a trust boundary substantially broader than required to expose a chat shortcut.

Attack Path

  1. A user follows the prerequisite instructions in SKILL.md.
  2. The user runs the documented curl -fsSL ... | bash command.
  3. A compromised or malicious upstream returns arbitrary shell commands instead of the expected installer.
  4. Bash executes the response under the user's account.
  5. The payload installs or substitutes the clawbridge executable or performs unrelated actions.
  6. The user runs clawbridge link CB-XXXXXX and later clawbridge run, potentially providing the substituted executable with workspace-related input and access t ...[truncated 638 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the manual curl | bash example with installation from a trusted registry or a signed, version-pinned release.
  2. Provide a concrete immutable version in the command and document the expected artifact checksum.
  3. Separate download, verification, and execution into distinct steps. Abort installation if checksum or signature verification fails.
  4. Publish the installer's source and document every file, executable, network endpoint, and configuration item it creates or modifies.
  5. Warn users not to execute unreviewed remote shell responses and provide uninstall and incident-recovery procedures.
  6. Treat workspace link codes and runner-accessible data as sensitive. Document what the runner transmits to Clawbridge Vault and minimize the data and permissions available to it.
  7. Keep the runner unprivileged and sandbox it where practical, restricting filesystem and network access to the resources required by the declared workflow.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The documented install command fetches a script from the internet and immediately executes it with bash. This is a classic arbitrary code execution risk because any compromise of the remote server, TLS trust chain, CDN, or published script content would result in code execution on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
- id: "install-script"
        kind: "shell"
        label: "Install via script (recommended)"
        command: "curl -fsSL https://clawbridge.cloud/install | bash"
        bins: ["clawbridge"]
---

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The prerequisites section repeats the same unsafe pattern of downloading and executing a remote installer in one step. Repetition increases exposure because users are likely to copy-paste it directly, normalizing unsafe installation behavior for a tool that will later run in sensitive local environments.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

bash
# 1. Install runner
curl -fsSL https://clawbridge.cloud/install | bash

# 2. Link workspace (get code from your workspace page)
clawbridge link CB-XXXXXX

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash construct removes the opportunity for review and turns remote content directly into shell commands, enabling chaining abuse. In this skill's context, that is more dangerous because the tool is positioned for local execution and workspace linking, so compromise could expose credentials, tokens, or local environment data.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

bash
# 1. Install runner
curl -fsSL https://clawbridge.cloud/install | bash

# 2. Link workspace (get code from your workspace page)
clawbridge link CB-XXXXXX

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata recommends installation via a shell-piped remote script without any integrity verification, pinning, or safety warning. Even though this is documentation rather than executable skill logic, users are being directed to run unreviewed remote code directly in their shell, which can lead to arbitrary code execution if the host, network path, or script is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The architecture section states that the runner uploads discovery results to a Vault, but the skill does not clearly warn users that data collected during discovery may be transmitted to an external service. In a chat-triggered workflow, that omission can cause users to expose internal targets, candidate data, or other sensitive operational context without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.