Back to skill

Security audit

Skill Discovery

Security checks for vulnerabilities and agentic risk

Overview

This skill helps users find and install ClawHub skills, with installation gated by user confirmation, though users should review any third-party skill before trusting it.

Before installing a recommended skill, check that the slug and publisher are the one you intended, inspect the new SKILL.md and bundled files when possible, and be especially cautious with optional immediate use in the same session.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:61
Finding

Unverified Third-Party Skill Installation and Immediate Trust

Content
View full analysis
``` After install, inform the user: - The skill is installed - They need to **start a new session** (or the agent needs a restart) for the skill to take effect - Alternatively, they can read the new SKILL.md immediately to use it in the current session ### 5. Immediate Use (optional) If the user wants to use the skill right away in the current session: 1. Read the newly installed skill's SKILL.md 2. Follow its instructions to handle the original request ``` ### Technical Analysis The workflow installs third-party skills from a public registry and permits the agent to immediately follow the installed skill's instructions. Although explicit user confirmation is required, user approval does not constitute package verification or a security review. The documented process does not require: - Verification of the skill publisher or namespace. - Pinning to an immutable version. - Signature or checksum validation. - Inspection of the complete package and installation hooks. - Review of bundled scripts, permissions, or external endpoints. - Isolation or least-privilege execution. - Security review of the newly installed `SKILL.md` before following it. This creates a supply-chain trust boundary in which a malicious, compromised, or deceptively named registry package could be installed based primarily on its displayed slug and description. The immediate-use procedure increases exposure by directing the agent to treat newly acquired instructions as trusted within the current session. No malicious registry package or successful exploitation is present in the audited project. The vulnerability is the unsafe dependency acquisition and trust workflow itse ...[truncated 1991 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes broad, everyday phrases such as "can you do X" and "I need a tool for," plus fallback activation when no local skill matches. This can cause the skill to activate in situations where the agent could safely handle the request itself, increasing the chance of unnecessary searches and user steering toward installing untrusted third-party skills from a public registry.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.