Back to skill

Security audit

Skill Release

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-built for publishing skills, but its CI template runs an unpinned remote installer in release jobs that can access publishing secrets.

Review before installing or copying the CI template. Prefer replacing the SkillHub curl-to-bash installer with a pinned, checksum-verified CLI install, keep GitHub Environment approval for publish jobs, scope secrets to release environments, and add an explicit expected SkillHub publisher check before formal Tencent publishing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tainted flow: 'request' from os.environ.get (line 199, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · assets/github-actions/clawhub_target.py (reported line 204)May include surrounding context.

python
headers={"Authorization": f"Bearer {token}", "Accept": "application/json"},
    )
    try:
        with urllib.request.urlopen(request, timeout=20) as response:
            payload = json.loads(response.read().decode("utf-8"))
    except (urllib.error.URLError, TimeoutError, UnicodeError, json.JSONDecodeError) as exc:
        raise TargetError("ClawHub whoami request failed") from exc

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
- 手动或 Tag 模式只处理用户明确指定的 Skill 目录;目录根部必须有 `SKILL.md`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- 手动或 Tag 模式只处理用户明确指定的 Skill 目录;目录根部必须有 `SKILL.md`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- 手动或 Tag 模式只处理用户明确指定的 Skill 目录;目录根部必须有 `SKILL.md`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
- 手动或 Tag 模式只处理用户明确指定的 Skill 目录;目录根部必须有 `SKILL.md`。

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The skill includes a curl-to-bash installation pattern that fetches and immediately executes a remote script. Even with user consent and an 'official' URL, this is a high-risk supply-chain pattern because any compromise of the host, transport, or script content results in arbitrary code execution on the user's machine or CI runner.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

CLI 缺失时,展示官方安装命令并征得执行许可:

bash
curl -fsSL https://skillhub.cn/install/install.sh | bash -s -- --cli-only

SKILLHUB_KEY 未配置时,读取 SkillHub 发布事实 的“身份、认证与 Token”。先问用户是在本机终端发布还是配置 GitHub Actions,再一次只给一个操作:引导完成网页注册、实名认证、API Token 创建,以及隐藏输入或 GitHub Secret 配置。团队发布改用已完成团队认证的团队密钥。不要只说“自行配置”,也不要让用户把 Token 粘贴到对话或命令参数文本中。

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

This workflow downloads and immediately executes a remote shell script with curl ... | bash during CI, without pinning content, verifying a checksum, or using a signed release artifact. If the remote server, DNS/TLS path, or upstream install script is compromised, arbitrary code would run on the GitHub runner; in this job that can tamper with build outputs, exfiltrate repository contents, and affect subsequent publishing decisions.

Content

Scanner excerpt · assets/github-actions/changed-skill-release.yml (reported line 90)May include surrounding context.

yaml
- uses: actions/checkout@v4
      - name: Install SkillHub CLI
        run: |
          curl -fsSL https://skillhub.cn/install/install.sh | bash -s -- --cli-only
          echo "$HOME/.local/bin" >> "$GITHUB_PATH"
      - name: Dry-run Tencent SkillHub
        run: |

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

This publish job also executes a remote installer via curl ... | bash, but here it runs in a job that has access to the SKILLHUB_KEY secret and performs authenticated publication. A compromise of the fetched script would enable arbitrary code execution with access to credentials and release privileges, allowing secret theft, malicious publication, or supply-chain compromise of released skills.

Content

Scanner excerpt · assets/github-actions/changed-skill-release.yml (reported line 205)May include surrounding context.

yaml
run: test -n "$SKILLHUB_KEY"
      - name: Install SkillHub CLI
        run: |
          curl -fsSL https://skillhub.cn/install/install.sh | bash -s -- --cli-only
          echo "$HOME/.local/bin" >> "$GITHUB_PATH"
      - name: Verify Tencent SkillHub identity
        run: |

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

The document instructs users to install the CLI by piping a remotely fetched script directly into bash. This is dangerous because any compromise of the download endpoint, TLS trust chain, DNS, or upstream script contents would result in immediate arbitrary code execution on the user's machine with the user's privileges, without an opportunity to inspect the script first.

Content

Scanner excerpt · references/skillhub-release.md (reported line 97)May include surrounding context.

教程提供的 CLI-only 安装命令:

bash
curl -fsSL https://skillhub.cn/install/install.sh | bash -s -- --cli-only

安装前要向用户说明这是远程脚本执行,并获得执行许可。安装后检查:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly instructs actions involving environment variables, file reads/writes, shell commands, and network access, but it does not declare any explicit tool scope or permissions boundary. That makes the skill harder to sandbox, review, and safely authorize, increasing the chance that an agent could overreach and perform sensitive operations without clear user-visible constraints.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/github-actions/detect_changed_skills.py (reported line 53)May include surrounding context.

python
def git_bytes(repository: Path, *args: str) -> bytes:
    return subprocess.run(
        ["git", "-C", str(repository), *args],
        check=True,
        stdout=subprocess.PIPE,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/github-actions/detect_changed_skills.py (reported line 316)May include surrounding context.

python
def run_git(repository: Path, *args: str) -> str:
    return subprocess.run(
        ["git", "-C", str(repository), *args],
        check=True,
        stdout=subprocess.PIPE,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The string 请粘贴 ClawHub Token(输入不会显示) hard-codes a Chinese prompt for user interaction. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · assets/github-actions/detect_changed_skills.py (reported line 300)May include surrounding context.

python
"target_commit": target_commit,
        "matrix": {"include": changed},
        "removed": [
            {key: getattr(before[name], key) for key in ("name", "version", "path", "digest")}
            for name in sorted(before.keys() - after.keys())
        ],
    }

Static analysis

No suspicious patterns detected.