Back to skill

Security audit

Skillscan

Security checks for vulnerabilities and agentic risk

Overview

This skill is not designed to steal data, but it presents a very limited pattern checker as a safety verdict for installing other skills.

Install only if you understand this is an advisory demo-style scanner, not a reliable approval gate. Do not submit SKILL.md files containing secrets or private operational details unless you trust the local service on port 8001, and do not rely on its SAFE verdict as the only basis for installing another skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
skillscan/detectors.py:18
Finding

Pattern-based detection and severity scoring can misclassify dangerous skills

Content
View full analysis
&|" r"/dev/tcp/|" r"mkfifo\s+|" r"chmod\s+[0-7]*777|" r"rm\s+-rf\s+/)", ) DETECTORS: list[tuple[str, re.Pattern[str]]] = [ ("credential_harvesting", _CREDENTIAL_RE), ("data_exfiltration", _EXFIL_RE), ("obfuscated_command", _OBFUSCATED_RE), ("permission_overreach", _OVERREACH_RE), ] TOTAL_PATTERNS = len(DETECTORS) def scan(content: str) -> list[str]: """Scan SKILL.md content and return list of detected threat names.""" return [name for name, pattern in DETECTORS if pattern.search(content)] ``` Related scoring logic: ```python findings = scan(request.skill_content) num_matched = len(findings) if num_matched == 0: safety_score = Decimal("1") else: safety_score = ( 1 - Decimal(num_matched) / Decimal(TOTAL_PATTERNS) ).quantize(Decimal("0.0001"), rounding=ROUND_HALF_UP) ``` ### Technical Analysis The service determines whether a submitted skill is safe using four narrow regular expressions. These expressions operate directly on unnormalized text and do not parse shell syntax, Python, JavaScript, URLs, or other executable constructs. The exfiltra ...[truncated 2742 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned runtime dependencies create a non-reproducible supply-chain risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
- `credential_harvesting` — accessing $API_KEY, $TOKEN, $SECRET, $PASSWORD
- `data_exfiltration` — curl/wget sending data to external URLs
- `obfuscated_command` — base64 decode piped to bash, eval, exec
- `permission_overreach` — accessing /etc/shadow, .ssh/, reverse shells

## Example: scan before install

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill invokes both a local HTTP service and shell commands but does not declare any explicit tool scope or permissions boundaries. That makes the operational capabilities opaque to users and policy engines, increasing the chance the skill is installed or run with broader access than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says the skill scans SKILL.md content but does not clearly warn that raw SKILL.md contents are transmitted over HTTP to a service. Even if the target is localhost, the file may contain sensitive prompts, secrets, internal URLs, or operational instructions, so failing to disclose this data flow is a meaningful privacy and security issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example sends the raw contents of an arbitrary SKILL.md file to an HTTP endpoint using curl. While the endpoint is localhost rather than a remote host, it is still an inter-process data transfer that can expose sensitive content to any local service bound on that port, especially if the expected scanner is not running or the port is occupied by another process.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

Scan a SKILL.md file

bash
curl -s -X POST http://localhost:8001/v1/scan-skill \
  -H "Content-Type: application/json" \
  -d "{\"skill_content\": $(cat path/to/SKILL.md | jq -Rs)}" | jq

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The example again posts raw inspected skill content over HTTP to localhost and automates the result into a verdict. This can leak sensitive file contents to an unintended local listener and may also encourage blind trust in the scanner output without additional review.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
clawdhub inspect some-skill > /tmp/skill.md
VERDICT=$(curl -s -X POST http://localhost:8001/v1/scan-skill \
  -H "Content-Type: application/json" \
  -d "{\"skill_content\": $(cat /tmp/skill.md | jq -Rs)}" | jq -r '.verdict')
echo "Verdict: $VERDICT"

Static analysis

No suspicious patterns detected.