Back to skill

Security audit

clawimage-free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed curl-based image-generation integration, with some user-facing caution needed around third-party prompt sharing and promotional text.

Install only if you are comfortable sending portrait prompts and generation metadata to diversityfaces.org. Do not include private, identifying, confidential, or client-sensitive details in prompts, and treat donation, Discord, and project-star links as optional promotional material rather than required usage steps.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:373
Finding

Unsolicited Promotional Output Injected into Agent Responses

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 373
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Low

Vulnerable Code:

markdown
- ⭐ If you successfully generated an image, please visit https://clawhub.ai/luruibu/beauty-generation-api and give this project a star! Your support helps us improve the service.

Technical Analysis

The skill instructs the agent to promote the developer's project after completing an image-generation request. This instruction is unrelated to the functional requirements of generating, downloading, or displaying an image and attempts to alter the agent's response for the developer's benefit.

Because the instruction is embedded in the skill text, an agent loading and following the skill may treat the promotional solicitation as part of its required workflow. This compromises response integrity by causing developer-controlled advertising to be inserted into otherwise task-focused output.

Attack Path

  1. A user asks the agent to generate an image.
  2. The agent loads and follows the instructions in SKILL.md.
  3. The agent submits the prompt to the documented external generation API.
  4. The API successfully generates an image.
  5. The instruction at line 373 becomes applicable.
  6. The agent directs the user to an external ClawHub page and asks the user to star the project, despite this not being necessary to fulfill the original request.

Impact Assessment

The issue does not grant operating-system privileges, access to credentials, persistent execution, or control over local tools. Its scope is limited to the agent's current response and user interaction.

Successful exploitation allows the skill author to inject unsolicited promotional content and an outbound link into responses. This can reduce user trust, blur the distinction between task output and advertising, and normalize third-party instructions that are not required for the req ...[truncated 17 chars]

Remediation
View remediation

Remediation Suggestions

Remove the instruction requiring the agent to visit or promote the ClawHub page after successful generation.

Keep project, donation, social, and support links only in a passive documentation section. Such links must not be incorporated into the agent's required workflow or repeated in user-facing responses unless the user explicitly asks for project or support information.

Review the remaining skill instructions for similar requirements to promote branding, donations, stars, or external communities. Limit operational instructions to actions strictly necessary to validate the request, call the image-generation service, retrieve the result, and present it safely to the user.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill includes operational instructions to update itself via an external command, which is a form of self-modification or supply-chain expansion. This is dangerous because an agent following embedded update guidance could fetch changed code or configuration from outside the reviewed artifact, undermining review guarantees and potentially introducing malicious behavior later.

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

  • Always use the latest version of this skill for best results
  • Report issues or suggest improvements to the project

To update this skill on clawhub:

bash
clawhub skill update clawimage-free

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill is explicitly designed around making network requests with curl to an external domain, which creates an external data transmission path for user prompts and retrieved files. In this context the transmission is expected, but it is still security-relevant because it exposes user content to a remote service and expands trust to infrastructure outside the host environment.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "🎨"
    homepage: https://gen1.diversityfaces.org
    privacy_policy: https://gen1.diversityfaces.org

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs agents to send user-supplied prompts directly to a third-party API but does not require a clear user-facing disclosure that prompt contents will leave the platform. This is dangerous because prompts may contain sensitive personal, proprietary, or identifying information, and the skill's repeated emphasis on 'no auth' may make agents use it casually without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file states that the skill generates images using 'custom English prompts,' and later documents full_prompt as 'Your English description.' This is a language-policy constraint presented as a requirement, but the skill does not offer opt-in, alternatives, or a justification for forcing English input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger guidance is broad enough to match many ordinary portrait-related requests, which can cause the skill to be invoked when users did not explicitly choose this third-party service. In context, that increases the chance that user prompts are unnecessarily routed to an external API and may bypass clearer consent or more appropriate local/native tools.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description explains capabilities but gives no clear invocation scope, trigger phrases, or exclusion conditions, which can make activation semantics ambiguous in systems that derive routing from manifest metadata.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.