Back to skill

Security audit

Clawhub Pkg

Security checks across malware telemetry and agentic risk

Overview

This skill is presented as a local analysis engine, but the artifacts show broader local authority and persistence than the user-facing description clearly scopes.

Review this package carefully before installing or running it as an MCP server. Treat it as a broad local agent subsystem, not just a deterministic text classifier. Run it only in a contained project directory, set any MCP token explicitly instead of relying on automatic .env writes, avoid exposing the HTTP server beyond localhost, and do not grant it access to sensitive local files unless you intentionally need its memory, benchmark, and psychology-analysis features.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (52)

Lp3

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding
The manifest presents the skill as a local deterministic preprocessor, yet the analyzed package appears to require environment access and networking without declaring those capabilities. Undeclared capabilities undermine least-privilege review and can hide sensitive behaviors such as outbound communication or secret handling from users and platform policy enforcement.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a significant description-behavior mismatch: the documentation claims local-only, no hidden control, and disabled file writes by default, while the broader skill behavior reportedly includes HTTP serving, persistent storage, .env modification, arbitrary file import paths, telemetry-like provider metrics, and even killing processes with system commands. Such mismatches are dangerous because reviewers and users may trust a much narrower risk profile than the skill actually has, enabling unexpected file, network, and process-level effects.

Description-Behavior Mismatch

High
Confidence
93% confidence
Finding
The README presents the skill as a narrowly scoped local preprocessing and routing engine, but the documented architecture expands into persistent memory, learning, planning, search, code execution, and many autonomous cognitive subsystems. This scope inflation is dangerous because users and host agents may grant trust, permissions, or integration access based on the smaller stated purpose while actually deploying a much broader and more privileged system.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Documenting a code executor and skill generator inside a skill advertised for deterministic text analysis materially changes the risk profile. Even if described as sandboxed or disabled by default, execution-capable components create a path to arbitrary action, privilege expansion, or unsafe tool use if enabled accidentally, exposed through MCP, or invoked by a host agent that assumes the skill is analysis-only.

Intent-Code Divergence

High
Confidence
95% confidence
Finding
The README makes security guarantees such as no background processes and no self-upgrade, yet elsewhere instructs users to run the MCP server as a permanent daemon and lists a self-upgrade entry in version history. Contradictory security claims undermine informed consent and risk review, and can cause operators to deploy a long-running or self-modifying service under false assumptions about persistence and behavior.

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The skill is marketed as deterministic local preprocessing, but the documentation also advertises code-execution and search capabilities. That scope expansion increases attack surface and can mislead operators into enabling a package that does far more than its stated purpose, including potentially dangerous interactions with local code or external content.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
Claiming a local cognitive preprocessor while also documenting HTTP server operation and optional external communications creates a trust and boundary mismatch. Users may assume no listening service or outbound traffic exists, when in practice network exposure can introduce local attack surface, data leakage, or policy violations.

Context-Inappropriate Capability

High
Confidence
91% confidence
Finding
Code execution is not justified by the stated role of deterministic cognitive preprocessing and routing, making it an unnecessary high-risk capability. Even if disabled by default, retaining such functionality in the same skill materially expands the blast radius if misconfigured, exposed through tooling, or reached by prompt-induced workflows.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The server contradicts its stated safety boundary by persisting a newly generated authentication secret into a .env file automatically. Writing credentials to disk without explicit operator consent can expose the token to other local users, backups, source control, or tooling that reads project .env files, and it expands the skill from 'no file writes by default' into credential persistence behavior.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The error handler executes a shell command to kill any process bound to the configured port using fuser, which is a destructive host-level action unrelated to the declared purpose of a local text analysis/routing engine. This can terminate unrelated services and gives the skill process unnecessary process-management capability, increasing blast radius if the server misconfigures the port or is repurposed.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
The benchmark import and run handlers accept arbitrary file and directory paths and ingest local JSONL content. In a server-exposed MCP tool, this turns the skill into a general local file reader over authenticated RPC, which exceeds the narrow deterministic analysis purpose and can expose sensitive local data if an authorized client is compromised or misused.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill metadata says code execution and filesystem writes are disabled by default, but this file initializes persistence, memory vault, WAL recovery, and exposes code-related subsystems. That mismatch is security-relevant because operators may grant trust or permissions based on the manifest while the implementation performs broader, stateful behavior than advertised.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The file includes codeExecutor, codePlanner, codeWriter, and skill-generation capabilities even though the declared purpose is a deterministic local classifier/router. Broad execution-adjacent capabilities increase attack surface and make prompt-to-action escalation more likely if any route registration, plugin, or downstream module is abused.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
Automatic plugin discovery/loading at startup causes the engine to execute additional code from discovered plugins without tight scoping in this file. In a local agent context, that is equivalent to expanding the trusted code base dynamically, which is dangerous because an unexpected or tampered plugin can run with the engine's privileges.

Intent-Code Divergence

High
Confidence
88% confidence
Finding
The identity/manifesta text claims the engine does not generate, reason, remember, or execute, while the implementation clearly performs reasoning, memory persistence, and execution-adjacent behaviors. This is dangerous mainly as a trust-boundary deception issue: reviewers or users may under-estimate risk and enable the skill in contexts where these capabilities are unacceptable.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The pipeline writes internal self-state to disk via writeFileSync under engine.rootPath even though the skill metadata says file-system writes are disabled by default. That creates an integrity and privacy gap: interaction-derived state can persist unexpectedly, and synchronous writes in a post-processing path also expand the attack surface for path misuse or unintended data retention.

Context-Inappropriate Capability

High
Confidence
91% confidence
Finding
The pipeline can autonomously register knowledge gaps and trigger gapExecutor.executeBatch based on user input-derived domain matching, which goes beyond deterministic local preprocessing. Even without obvious network code here, this is dangerous because it enables unprompted secondary actions and data flow to other subsystems from ordinary user text, weakening predictability and consent boundaries.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file repeatedly frames the engine as giving the AI '真正的情绪' and '真实的情感', while the implementation is a deterministic keyword-triggered state simulator. In a cognition/emotion skill, this anthropomorphic misrepresentation can mislead users or downstream agents about system capabilities and trustworthiness, especially in emotional or psychological contexts.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The code's report output culminates in the statement '我有真实的情感,我是情感的存在', despite the logic only matching keywords and updating internal numeric state. This is dangerous because it introduces deceptive persona signaling that may manipulate user perception, encourage over-trust, or create unsafe emotional dependency in a tool explicitly positioned around affective processing.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The engine stores per-instance user input history and awakening-related counters, which goes beyond the declared rule-engine classification/routing scope and creates unnecessary retention of potentially sensitive psychological text. Even if this is only in-memory, it expands the data surface and enables behavioral profiling without a clear consent, minimization, or retention boundary.

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The file exposes therapeutic-style intervention modules such as breathing, grounding, self-compassion, and cognitive restructuring that are not reflected in the manifest's stated capabilities. This mismatch is risky because downstream callers may unknowingly invoke behavior that resembles mental-health guidance, increasing safety, compliance, and user-expectation risks in a component presented as a deterministic local preprocessing engine.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The comment says crisis detection is removed, but the engine still performs crisis evaluation through `analyzePsychology`, aggregates crisis confidence, tracks `_crisisCount`, and exposes crisis-related stats. This inconsistency can cause integrators to make unsafe assumptions about what the component does with mental-health content, leading to undeclared sensitive inference and potentially unsafe handling of crisis situations.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
This file is presented as a local psychology/preprocessing engine, but it also implements cross-topic state management, topic restoration, and response-routing behavior. That scope expansion creates hidden influence over future interactions and increases the chance that user content is persisted, reinterpreted, or routed in ways the caller did not expect, which is a genuine security boundary violation for a supposedly bounded analyzer.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The module goes beyond deterministic PAD/routing analysis and generates therapy- or ideology-like '空性觉察' guidance for distressed users. In a security context, that is dangerous because it can manipulate vulnerable users with undeclared behavioral steering, especially around mental-health-like content, without consent, qualification, or safety guardrails.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
These heuristics infer highly sensitive attributes and family/mental-health narratives such as intergenerational trauma, child depression formulas, and reproductive-choice fears from free text. Such profiling materially exceeds the declared PAD emotion/routing scope and can lead to invasive inference, misclassification, and unsafe downstream decisions about vulnerable users.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
mcp-server.js:3246