Back to skill

Security audit

Publish a Webpage

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for publishing a webpage, but it asks users to paste a reusable deployment URL and uses raw shell deployment commands without enough consent or safety guidance.

Review this skill before installing. It is meant to publish content online, so only use it with material you intend to make public. Treat the goclawgo Agent URL like a credential, avoid pasting sensitive project keys into chat when possible, and rotate the key if it is exposed. Deployment commands should validate the URL, local path, and deployment id rather than directly substituting text into shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Sensitive Project Credential Exposed Through a Reusable Agent URL

Content
View full analysis
Remediation
View remediation
`. 3. Obtain credentials through a protected secret-input or credential-store interface that prevents inclusion in model context and logs. 4. Use short-lived, single-project tokens with only the deployment permissions required for this task. 5. Ensure tokens are revocable and provide users with a clear rotation procedure. 6. Redact credentials and sensitive URL components from shell output, error messages, traces, access logs, and audit records. 7. Avoid writing authenticated commands to shell history. 8. Warn users to rotate any project key that has already been pasted into a conversation or otherwise exposed. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:26
Finding

Unvalidated Values Interpolated into Shell Commands

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises with very broad phrases like 'put my idea online,' 'publish my website,' and 'share my idea,' which can match many ordinary conversations and cause the skill to activate when the user did not clearly intend a public deployment workflow. In this skill's context, misrouting is more dangerous because activation can lead to collecting a project deployment URL and publishing user-provided content to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to package user content and POST it to an external hosting service, but it does not require an explicit warning that the content will be transmitted to goclawgo and potentially made publicly accessible. In this context, that omission is significant because non-technical users may not understand that their text, branding, contact details, or other sensitive material is being uploaded and published outside the local agent environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.