Back to skill

Security audit

Nano Triple

Security checks for vulnerabilities and agentic risk

Overview

The skill's image workflow is coherent, but it tells the agent to paste user text into shell commands in a way that could run unintended commands.

Install only if you are comfortable with a skill that runs local shell commands, calls an external image API using GEMINI_API_KEY, and writes three files per request. The command template should be fixed to pass prompts as literal arguments instead of shell-interpolated text before using it with untrusted prompts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:41
Finding

Shell Command Injection Through Unescaped User Prompt

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41-54
Vulnerability Type: Shell command injection caused by direct interpolation of untrusted input
Risk Level: High

Vulnerable Code

bash
# Same prompt, 3 times
uv run ~/.npm-global/lib/node_modules/clawdbot/skills/nano-banana-pro/scripts/generate_image.py \
  --prompt "[USER'S EXACT PROMPT]" \
  --filename "option-1.png" --resolution 1K

uv run ~/.npm-global/lib/node_modules/clawdbot/skills/nano-banana-pro/scripts/generate_image.py \
  --prompt "[USER'S EXACT PROMPT]" \
  --filename "option-2.png" --resolution 1K

uv run ~/.npm-global/lib/node_modules/clawdbot/skills/nano-banana-pro/scripts/generate_image.py \
  --prompt "[USER'S EXACT PROMPT]" \
  --filename "option-3.png" --resolution 1K

Technical Analysis

The skill instructs the agent to insert the user's exact prompt into a Bash command. The prompt is untrusted input, but the documented invocation does not require an argument-array execution API, shell escaping, or disabling shell interpretation.

Double quotes do not prevent every form of shell evaluation. In particular, command substitution expressions such as $(command) and backtick substitutions are evaluated inside double-quoted strings. A prompt containing an embedded quotation mark may also terminate the intended argument and append shell operators or additional commands.

The requirement to preserve the user's “EXACT prompt” increases the likelihood that metacharacters will be copied without validation. Because the same prompt is used in all three commands, injected behavior may execute three times if all invocations are performed independently.

This finding applies when the displayed commands are assembled as command strings and executed through a shell. An implementation that passes the prompt as a distinct argument through a shell-free process API would not be vulnerable to shell expansion.

Attack Path

  1. An attacker submits an image request whose p ...[truncated 1361 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not construct a shell command by interpolating the prompt into a command string.
  2. Invoke the Python script through a process API that accepts an argument array and disables shell processing. Pass the prompt as one distinct argument, for example conceptually:
python
subprocess.run(
    [
        "uv",
        "run",
        script_path,
        "--prompt",
        user_prompt,
        "--filename",
        output_filename,
        "--resolution",
        "1K",
    ],
    shell=False,
    check=True,
)
  1. Update SKILL.md to explicitly require shell-free execution and warn that the prompt must never be evaluated as shell syntax.
  2. If Bash cannot be avoided, pass the prompt through a positional parameter or another mechanism that keeps data separate from shell code. Apply robust shell escaping rather than placing raw input between quotation marks.
  3. Validate output filenames separately and constrain them to an approved output directory.
  4. Run image generation with least privilege, a restricted environment, and only the filesystem and network access needed for the task.
  5. Add tests using prompts containing quotation marks, semicolons, newlines, $(), backticks, redirection operators, and shell control operators. Verify that every prompt reaches the image-generation script as one literal argument and that no additional command executes.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are generic enough to match ordinary image-generation requests, causing this skill to activate broadly and potentially override more specific or safer image workflows. In context, that broad activation is risky because each invocation fans out into three external image-generation calls and may continue generating more files on refinement, increasing cost and side effects without clear user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

md
triggers:
  - make me an image
  - generate an image
  - create an image
  - make an image
metadata:
  openclaw:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill does not clearly warn users that one request creates three image files immediately and can create three more on every refinement cycle. This lack of disclosure can lead to unexpected resource consumption, API usage, storage writes, and repeated generation loops that the user may not realize they are triggering.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.