T08 · Insecure Dependencies
- Location
README.md:25- Finding
Inconsistent and Unpinned Installation Source Exposes Users to Unaudited Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The research workflow is mostly coherent, but the install and CLI documentation points users toward unaudited external code from an inconsistent source.
Review the install source before using this skill. The core SkillBoss search workflow is understandable, but do not run the advertised scripts/research CLI unless you verify which GitHub repository is authoritative and inspect the script contents. Avoid sending secrets, internal URLs, or sensitive investigations as research queries unless you trust SkillBoss API Hub's handling of that data.
README.md:25Inconsistent and Unpinned Installation Source Exposes Users to Unaudited Code
The README advertises web search and scraping through SkillBoss API Hub but does not warn that user queries and target URLs are transmitted to a third-party service. In a research skill, prompts may contain sensitive business, personal, or investigative data, so undisclosed external transmission creates a meaningful privacy and data-handling risk.
The instruction says to use this workflow 'when the user asks for research on any topic,' which is extremely broad and overlaps with common user requests. The file does not define clearer trigger boundaries, exclusions, or negative examples to distinguish when this skill should activate versus a normal answer flow.
The phrase 'just research it' is a generic everyday instruction and could match many ambiguous situations. Without additional scope constraints, it increases the risk of unintended invocation of this deep-research workflow.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
timeout=60
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
timeout=60
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Web search
result = requests.post(
"https://api.heybossai.com/v1/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json={"type": "search", "inputs": {"query": "<sub-question keywords>"}, "prefer": "balanced"},
timeout=60
The skill directs automatic creation of local files under a home-directory path without warning or obtaining user consent. Unexpected persistence can expose sensitive researched topics, clutter the filesystem, or create opportunities for abuse if the path or slug is influenced by untrusted input.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
sessions_spawn(
task: "Run deep research on [TOPIC]. Follow the deep-research-pro SKILL.md workflow.
Read /home/clawdbot/clawd/skills/deep-research-pro/SKILL.md first.
Goal: [user's goal]
Specific angles: [any specifics]
Save report to ~/clawd/research/[slug]/report.md
This markdown file advertises that the skill can save output to files, which affects local user data, but it does not include any warning or caution about file creation or possible overwrites. Under the markdown-specific SQP-2 criteria, user-facing documentation should disclose behaviors that can affect data or system state.
The manifest description limits the skill to searching, synthesizing, and delivering cited reports. The documented workflow additionally includes creating directories and writing a report under ~/clawd/research/[slug], which is a persistence behavior not mentioned in the manifest description.
A deep research agent obviously needs network access to search and scrape sources, but writing to ~/clawd/research is an extra capability beyond researching and delivering results in chat. The manifest does not state that the skill persists outputs locally, so this capability is not clearly justified from the declared purpose alone.
No suspicious patterns detected.