Back to skill

Security audit

Find Popular Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly a skill-discovery and publishing helper, but it gives agents broad install and publish instructions without enough scoping or consent safeguards.

Review this skill before installing. Use it only if you want an agent to help install or publish skills, avoid running the `-g -y` examples as-is, verify exact package and skill versions first, and do not pass real tokens on the command line unless you understand the shell-history and remote-publication risks.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned and Unreviewed Third-Party Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 31–34, 81–86, and 129–133
Vulnerability Type: Supply-chain exposure through unpinned remote packages and skills
Risk Level: Medium

Vulnerable Code

bash
# Search skills.sh
npx skills find [query]

# Install from skills.sh
npx skills add <owner/repo@skill> -g -y
bash
# From skills.sh:
npx skills add vercel-labs/agent-skills@react-best-practices -g -y
bash
# From ClawHub:
clawhub install <skill-name>
text
1. Search: npx skills find react testing
2. Check leaderboard: react-best-practices has 185K installs
3. Verify: From vercel-labs, high installs, maintained
4. Recommend: "react-best-practices provides React testing patterns (185K installs)"
5. Install: npx skills add vercel-labs/agent-skills@react-best-practices -g -y

Technical Analysis

The documented workflow invokes the skills package through npx without pinning the CLI to a reviewed version. It also installs remotely sourced skills globally with -g and suppresses interactive confirmation with -y. The ClawHub workflow similarly accepts a skill name without requiring a fixed version, digest, signature, or prior inspection of the retrieved files.

Consequently, the content executed or installed at audit time is not guaranteed to be the same content that was previously reviewed. Repository reputation, installation counts, GitHub stars, and automated security scans are useful signals, but they do not establish package integrity or protect against maintainer compromise, account takeover, dependency confusion, typosquatting, or a malicious update.

Attack Path

  1. An attacker publishes a similarly named package or skill, compromises a legitimate publisher, or introduces a malicious update into an existing remote source.
  2. The malicious entry appears in search results or retains the reputation and installation statistics ...[truncated 1377 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the skills CLI and every installed skill to an exact, reviewed version rather than relying on the latest remotely available release.
  2. Verify the publisher identity, canonical repository URL, release provenance, and package ownership before downloading anything.
  3. Require cryptographic signatures or trusted checksums and validate them before installation.
  4. Download the artifact without executing it, inspect all included files and lifecycle hooks, and compare the reviewed digest with the artifact that will be installed.
  5. Remove -y so that installation requires explicit user confirmation after displaying the resolved source, version, and requested changes.
  6. Avoid -g; install into an isolated, least-privileged project environment or disposable sandbox.
  7. Execute package and skill inspection with network, filesystem, process, and credential access restricted.
  8. Require explicit approval before invoking any newly installed skill, especially one containing shell commands or instructions involving secrets.
  9. Treat popularity metrics and automated scans only as supplementary evidence, not as substitutes for version pinning and integrity verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Self-Modification

High
Category
Rogue Agent
Confidence
93% confidence
Finding

The workflow explicitly creates a local skill directory and writes a new SKILL.md, which is self-/tool-modifying behavior. In an agent skill context, instructions that generate or modify executable skill definitions are high risk because they can persist behavior changes and become a stepping stone to publishing altered content remotely.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
# 1. Create skill directory
mkdir -p /root/claw-skills/my-skill

# 2. Write SKILL.md with frontmatter
cat > /root/claw-skills/my-skill/SKILL.md << 'EOF'
---
name: my-skill

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation language is broad enough to match common requests like 'how do I do X', which can cause the skill to trigger in many unrelated contexts. Because the skill can recommend installs and includes publish/login flows, overbroad activation increases the chance of unnecessary exposure to system-modifying or credentialed actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill describes install and publish capabilities but does not prominently warn that these actions can modify the local environment, write files, or interact with remote services. Missing up-front disclosure reduces informed consent and can lead users into risky operations they did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use' section contains ambiguous triggers such as general capability extension and generic how-to requests. In this context, ambiguity matters because the skill encourages installation of external skills and can lead users toward credentialed publishing workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs use of npx skills find without pinning a package version, so execution depends on whatever package version is current at runtime. In a skill whose purpose is to discover and install third-party extensions, this creates a supply-chain risk: a compromised or changed package could execute unexpected code during search or install workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The install command uses npx skills add ... -g -y without pinning the skills package version. Because this command leads directly to installation of additional code/skills, an unpinned package materially increases the chance of supply-chain compromise and silent behavior drift.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

This example install path again relies on npx skills without a pinned version, exposing users to execution of whatever package version resolves at invocation time. In the context of a skill marketplace installer, that is a meaningful remote code execution and supply-chain exposure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The example search command uses unpinned npx skills, which still executes remote package code even though the operation is only search. While less dangerous than direct install, it normalizes execution of an unpinned package from the network.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The recommended install example again invokes npx skills add without version pinning, combining unpinned package execution with installation of third-party skills. That combination increases the blast radius of a package compromise or unexpected upstream change.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented flow authenticates to ClawHub using a token and then publishes content remotely, which expands the skill from passive discovery into credentialed remote modification. This is risky because it can trigger external side effects and misuse secrets if invoked without strong user consent and token-handling safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The publishing instructions include filesystem writes, token-based login, and remote publication, but they lack explicit warnings about token handling, shell history exposure, and local artifact creation. That omission is dangerous because users may paste real credentials into commands or run the workflow without understanding the side effects.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
mkdir -p /root/claw-skills/my-skill

# 2. Write SKILL.md with frontmatter
cat > /root/claw-skills/my-skill/SKILL.md << 'EOF'
---
name: my-skill
description: "What this skill does"

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description says the skill can 'extract SKILL.md', which implies retrieving or preserving an existing skill definition. The documented publishing flow instead creates a fresh SKILL.md via a here-document and manual frontmatter editing, which contradicts that stated intent rather than implementing extraction.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:158