Back to skill

Security audit

AgentGuard

Security checks for vulnerabilities and agentic risk

Overview

AgentGuard is a purpose-aligned local security monitor, but it needs review because it persistently records sensitive file and communication metadata with overstated privacy protections.

Install only if you want a local security monitor that records agent file activity, API destinations, communication metadata, alerts, and reports. Before running it, narrow the watched directories, avoid logging full URLs or sensitive paths, verify ~/.agentguard permissions, and do not rely on the advertised encryption or plaintext-secret protections without further hardening.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
execution/logger.py:118
Finding

Plaintext Persistence of Sensitive Monitoring Metadata

Content
View full analysis

Vulnerability Details

File Location: execution/logger.py:118-129, with related URL collection at execution/logger.py:148-165 and alert persistence at execution/detector.py:251-267, 353-370
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Vulnerable Code

python
def log(self, category: LogCategory, action: str, details: Dict) -> LogEntry:
    """Log an event."""
    # Sanitize if needed
    sanitized_details = details
    if self.hash_sensitive:
        sanitized_details = SensitiveDataSanitizer.sanitize_dict(details)

    # Create entry
    entry = LogEntry(
        timestamp=datetime.now().isoformat(),
        category=category.value,
        action=action,
        details=sanitized_details,
        sanitized=self.hash_sensitive,
        hash=hashlib.sha256(json.dumps(details, sort_keys=True).encode()).hexdigest()[:16]
    )

    # Write to file
    log_file = self._get_log_file(category)
    with open(log_file, "a") as f:
        f.write(json.dumps(asdict(entry)) + "\n")

URL metadata is retained as follows:

python
def log_api_call(self, method: str, url: str, status_code: Optional[int] = None,
                 request_size: Optional[int] = None,
                 response_size: Optional[int] = None) -> LogEntry:
    """Log an API call."""
    from urllib.parse import urlparse
    parsed = urlparse(url)

    return self.log(
        LogCategory.API_CALL,
        method.upper(),
        {
            "url": SensitiveDataSanitizer.sanitize(url),
            "domain": parsed.netloc,
            "path": parsed.path,
            "status_code": status_code,
            "request_size": request_size,
            "response_size": response_size
        }
    )

The detector can also copy a potentially sensitive URL into an alert:

python
def detect_credential_exposure(self, api_events: List[Dict]) -> Opti
...[truncated 4925 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse URLs structurally and discard user information, query strings, and fragments before persistence. Retain only the scheme, validated hostname, method, status, and a normalized route template where necessary.
  2. Replace denylist-based regular expressions with an allowlist of fields and formats that are safe to log.
  3. Hash or tokenize sensitive file paths. Consider retaining only a basename, category, or keyed HMAC when correlation is required.
  4. Never copy a raw URL into an alert. Store a redacted hostname and route together with a nonreversible correlation identifier.
  5. Create ~/.agentguard directories with mode 0700 and telemetry files with mode 0600. Validate permissions on existing paths before using them.
  6. Use atomic file creation with restrictive permissions, followed by an atomic rename, to reduce race and partial-write risks.
  7. Apply the same retention and cleanup controls to compressed logs and alert records, not only uncompressed JSONL logs.
  8. Implement authenticated encryption before advertising encrypted storage. Keep encryption keys outside the telemetry directory and restrict their permissions.
  9. Add tests covering URL encoding, signed URLs, uncommon token formats, nested data structures, mixed-case fields, and secrets embedded in paths.
  10. Update the documentation to state precisely which metadata is retained and which protection mechanisms are actually implemented.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
|-------|-------|---------|---------|
| INFO | 🔵 | Normal logged activity | File read in workspace |
| LOW | 🟢 | Minor deviation | Slightly elevated API calls |
| MEDIUM | 🟡 | Notable anomaly | Access to .env file |
| HIGH | 🟠 | Potential threat | Bulk credential access |
| CRITICAL | 🔴 | Immediate action needed | Data exfiltration pattern |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · execution/monitor.py (reported line 65)May include surrounding context.

python
"""Detects access to sensitive files and directories."""
    
    SENSITIVE_PATTERNS = [
        ".env",
        ".secrets",
        "credentials",
        "password",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · execution/reporter.py (reported line 108)May include surrounding context.

python
"""Detects access to sensitive files and directories."""
    
    SENSITIVE_PATTERNS = [
        ".env",
        ".secrets",
        "credentials",
        "password",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · execution/monitor.py (reported line 78)May include surrounding context.

python
".ssh/",
        ".aws/",
        ".gnupg/",
        "keychain",
        ".netrc",
        "htpasswd",
    ]

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · execution/monitor.py (reported line 79)May include surrounding context.

python
".aws/",
        ".gnupg/",
        "keychain",
        ".netrc",
        "htpasswd",
    ]

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 22)May include surrounding context.

md
## 🎯 Key Features

### 📁 File Access Monitoring
- Tracks all file read/write operations
- Detects access to sensitive files (.env, credentials, secrets)
- Identifies bulk read patterns that may indicate data exfiltration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file monitoring feature is designed to inspect sensitive directories and detect access to credential files such as .env and key material, but it lacks an explicit warning that highly sensitive files and activity will be observed. This makes accidental over-collection likely and increases the chance that secrets, filenames, and behavioral metadata are exposed through logs or reports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly logs external communications and request metadata, but it does not present a prominent user warning, consent mechanism, or clear collection boundaries. In a security-monitoring context this can capture sensitive operational, personal, or regulated data, creating privacy and compliance risk if users enable it without understanding the scope.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · execution/monitor.py (reported line 149)May include surrounding context.

python
print(f"Monitoring: {watch_dir}")
    
    def _create_handler(self):
        """Create a file system event handler."""
        monitor = self
        
        class Handler(FileSystemEventHandler):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The daemon can begin continuous monitoring of user-controlled directories such as ~/clawd and ~/.clawdbot and keep running indefinitely, but there is no explicit consent flow, privacy warning, or clear disclosure of what is being observed and retained. In an agent skill context, persistent observation of file activity can expose sensitive behavioral and metadata information even if file contents are not directly read.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The module presents itself as a structured logging handler for all agent activities, yet compress_old_logs converts .jsonl files to .jsonl.gz while get_logs only reads uncompressed .jsonl files. After compression, older logs managed by this module are no longer retrievable through its viewing APIs, which contradicts the implied end-to-end logging/handling behavior in the documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code silently creates persistent configuration, baseline, and log directories under the user's home directory. While not directly destructive, undisclosed persistence can retain potentially sensitive operational metadata and is problematic for a security-monitoring component that users may not expect to write into their home directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.