Back to skill

Security audit

Enhanced Agent Modes

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly adds agent working modes, but it also documents persistent memory/logging and optional background automation without enough scoping or retention detail.

Review this skill carefully before installing. The core Explore, Plan, and Verify modes are straightforward, but leave auto_memory and autonomous_crons disabled unless you explicitly want persistent memory processing or background agent work. If you install it, prefer a pinned and trusted clawhub installer version and inspect any memory/state files it creates.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Package Execution During Installation

Content
View full analysis
``` The README provides the corresponding installation instructions: ```bash # Clone this skill git clone https://github.com//enhanced-modes.git skills/enhanced-modes # Or use clawhub (if published) npx clawhub install enhanced-modes ``` ### Technical Analysis The installation instructions invoke `clawhub` through `npx` without specifying an audited version, package integrity hash, lockfile, or trusted registry. Depending on the local environment and npm cache state, `npx` can retrieve and execute a package from the configured package registry. Consequently, the code executed during installation is not necessarily the same code that was reviewed in this project. The effective installer may change when a new package version is published or if the package, maintainer account, registry, or dependency chain is compromised. The alternative repository argument is also presented without source-validation requirements. Although the README's GitHub URL is only a nonfunctional placeholder, users following an adapted version of that instruction could clone an untrusted repository if its identity is not verified. ### Attack Path 1. An attacker publishes a malicious version of the resolved `clawhub` package, compromises its maintainer account, compromises an upstream dependency, or influences the package registry used by the victim. 2. A user follows the documented command `npx clawhub install enhanced-modes`. 3. `npx` resolves and downloads the unpinned package or package dependencies. 4. Package lifecycle or installer code executes with the privileges of the invoking user. 5. The malicious installer can access resources available to that user, ...[truncated 713 chars]
Remediation
View remediation
install enhanced-modes ``` 2. Publish and document the exact official registry, package scope, and repository URL. 3. Supply integrity information or verifiable release signatures for distributed artifacts. 4. Review and lock transitive dependencies through an appropriate lockfile and automated dependency auditing. 5. Instruct users to verify the repository owner, release tag, commit hash, and signature before installation. 6. Avoid suggesting arbitrary repository sources. If local-repository installation is supported, require an explicit trust review before execution. 7. Recommend installation with an unprivileged account and within a sandbox or isolated environment. ]]>

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:67
Finding

Overbroad Memory Inspection and Conversation-State Retention

Content
View full analysis
60% context) | ``` ```markdown ## Auto-Memory Consolidation When `auto_memory` feature is enabled: ### Trigger Conditions - Context > 60% (danger zone entered) - Session ends - User requests consolidation ### Process 1. Scan daily memory files for important content 2. Extract decisions, preferences, context 3. Update long-term memory 4. Archive raw notes ``` The supplied session state enables the working buffer and write-ahead behavior: ```json { "deep_thinking": true, "auto_memory": false, "coordinator_mode": false, "wal_protocol": true, "working_buffer": true, "explore_agent": true, "plan_agent": true, "verify_agent": false, "proactive_checkins": false, "autonomous_crons": false } ``` ### Technical Analysis The stated purpose of the Skill is to provide Explore, Plan, and Verify modes. General inspection of daily memory files, logging of conversation exchanges, modification of long-term memory, and archival of raw notes are broader capabilities than those modes inherently require. The `auto_memory` feature is disabled in the supplied state, which limits immediate exposure. However, `working_buffer` and `wal_protocol` are enabled by default, and the Skill documents a path for enabling memory consolidation dynamically. The documentation does not establish a strict file scope, data classification policy, retention limit, redaction process, or per-operation author ...[truncated 1795 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README describes Explore as "Read-only" at L38, yet the same documented skill capabilities include "auto-consolidate memory" and "Write-ahead logging" at L47-L48, both of which imply state modification. That is an intent-level contradiction in the documentation about whether this mode/skill operates without writes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation instructions invoke npx clawhub without pinning an exact package version, which can fetch whatever version is current at install time. That creates a supply-chain risk: a compromised upstream release or unexpected breaking change could execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This alternative install command also uses npx clawhub without a pinned version, preserving the same supply-chain exposure as the primary command. Users may execute transient code directly from the registry without any guarantee they are getting a reviewed release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes automatic memory consolidation, long-term memory updates, and archival of raw notes, but does not present a clear user-facing warning or explicit consent gate before modifying stored memory artifacts. In an agent environment, silent persistence and transformation of user data can cause privacy issues, retention of sensitive information, or unintended corruption of notes and memory state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises autonomous background tasks and spawning sub-agents on timers without warning users about unattended execution or potential system effects. Autonomous execution increases the chance of unsupervised actions, unexpected tool use, resource consumption, or unintended changes occurring outside the user's immediate awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.