Back to skill

Security audit

Clawd Modifier

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to customize a mascot, but it edits installed Claude Code program files in ways that can break or alter the CLI beyond a cosmetic change.

Install only if you are comfortable with a cosmetic skill modifying your Claude Code installation files. Use dry-run first, avoid custom untrusted color values, keep backups enabled, prefer a user-local Claude Code install, and be prepared to restore or reinstall Claude Code if the patch corrupts the CLI.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/patch_color.py:89
Finding

Unvalidated color arguments allow JavaScript source injection into Claude Code

Content
View full analysis
Remediation
View remediation
str: parts = value.split(",") if len(parts) != 3: raise ValueError("RGB must contain exactly three components") values = [int(part, 10) for part in parts] if any(value < 0 or value > 255 for value in values): raise ValueError("RGB components must be between 0 and 255") return f"rgb({values[0]},{values[1]},{values[2]})" ``` 2. Restrict ANSI values to an explicit allowlist of supported color identifiers. For example: ```python ALLOWED_ANSI = { "ansi:black", "ansi:red", "ansi:green", "ansi:yellow", "ansi:blue", "ansi:magenta", "ansi:cyan", "ansi:white", "ansi:blackBright", "ansi:redBright", "ansi:greenBright", "ansi:yellowBright", "ansi:blueBright", "ansi:magentaBright", "ansi:cyanBright", "ansi:whiteBright", } ``` 3. Reject quotation marks, backslashes, control characters, line breaks, and every value outside the expected grammar. 4. Use safe serialization when generating JavaScript string literals instead of direct interpolation. 5. Verify that each replacement produces the exact expected syntax and occurrence count before writing the result. 6. Write to a temporary file, validate the generated bundle, and atomically replace the original only after validation succeeds. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/patch_art.py:99
Finding

Global replacement of short art fragments can corrupt unrelated bundled code

Content
View full analysis
0: code = code.replace(old, new) total_replacements += count ``` The same unrestricted replacement strategy is used for custom and restoration operations: ```python for old, new in replacements.items(): count = code.count(old) code = code.replace(old, new) total += count ``` ```python for modified, original in reverse_map.items(): count = code.count(modified) code = code.replace(modified, original) total += count ``` Several replacement keys are very short and structurally generic: ```python 'replacements': { '" ▐"': '"╱▐"', '"▌")': '"▌╲")', } ``` ### Technical Analysis `str.replace()` modifies every occurrence in the complete minified Claude Code bundle. The code does not limit replacement to a known mascot-rendering function, validate nearby tokens, require a supported Claude Code version, or enforce an exact expected occurrence count. Patterns such as `" ▐"` and `"▌")` are not sufficiently unique to guarantee that they only identify Clawd artwork. A future or different bundle version could contain the same sequence in another user-interface component, string constant, or code path. The restoration routine has the same weakness and may replace naturally occurring diagonal-art fragments that were not introduced by this script. ### Attack Path 1. The user runs `patch_art.py` against a Claude Code version that contains one of the short patterns outside the intended mascot component. 2. The script counts all occurrences but does not reject unexpected counts. 3. `code.replace()` modifies every occurrence throughout the bundle. 4. The entire modified bundle is written over th ...[truncated 1065 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/patch_binary.py:193
Finding

Unscoped binary-wide byte replacement can corrupt the Claude Code executable

Content
View full analysis
0: if not dry_run: data = data.replace(search, replace) total_patches += count patch_details.append({ 'count': count, 'description': patch.get('description', 'Unknown') }) ``` The modified byte sequence is then written directly over the executable: ```python if not dry_run: binary_path.write_bytes(data) ``` Multiple patch definitions use the global path because they do not specify contextual restrictions: ```python { 'search': b'body"}," \\u2588', 'replace': b'body"}," \\u2572', 'description': 'Large Clawd left arm up' }, { 'search': b'\\u2588 ")', 'replace': b'\\u2571 ")', 'description': 'Large Clawd right arm up' }, ``` ### Technical Analysis For patches without a `context` field, the implementation replaces every matching byte sequence in the executable. It does not verify: - The Claude Code release or binary format - A known cryptographic hash - Exact expected offsets - Surrounding bytes - An exact occurrence count - Whether all required patch components were found - The validity of the resulting executable Byte strings that identify artwork in one binary version may appear in unrelated constants or compiled data in another version. Replacing all occurrences can therefore alter content beyond the intended mascot. The executable is overwritten directly rather than through a validated temporary file and atomic rename. A failure or interruption during the write can leave it partially written or unusable. ### Attack Path 1. A user runs `patch_binary.py` against an unsupported Claude Code release or supplies another existing file through `- ...[truncated 1318 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill instructs users to read and modify a system-installed CLI file but does not declare corresponding permissions. This creates a transparency and governance gap: an agent could perform filesystem actions the user or platform did not expect, especially against a globally installed package under /opt. In this context, undeclared file write capability is risky because the stated workflow explicitly patches executable application code rather than a user-scoped config file.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill claims to customize a mascot, but the documented behavior directly patches the compiled/installed CLI implementation and extracts internal definitions from cli.js. That mismatch is dangerous because it understates the scope of system modification, making users more likely to approve actions that alter executable code, affect updates, or break the CLI. Security-sensitive tooling should not conceal code-patching behavior behind a cosmetic description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest uses broad trigger phrases such as requests to 'customize the mascot' or 'make Clawd [color],' which can cause the skill to activate in ambiguous contexts. Overbroad invocation matters here because the skill's actual behavior includes file modification of a system CLI, so accidental triggering could escalate a harmless conversational request into code-patching guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill identifies a concrete system CLI path under /opt and then provides workflows to patch it without a prominent user-impact warning. Directing edits to globally installed application files can break the tool, affect other users on the system, or be abused as a stepping stone for unauthorized code tampering if the agent has elevated access. The risk is amplified because the change target is executable code, not a disposable asset file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manual workflow recommends destructive in-place editing with sed against cli.js and only lightly mentions backups, without clearly warning about corruption, failed pattern matches, or unintended broad replacements. In-place modification of installed code is hazardous because a bad substitution can render the CLI unusable or introduce unintended behavior, and the examples normalize editing production code directly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.