Back to skill

Security audit

Craft CLI

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it exposes real-looking Craft access URLs and documents powerful document mutation commands without enough safeguards.

Review carefully before installing. Do not use the embedded Craft URLs; treat them as exposed credentials and replace them with your own protected configuration. Prefer a user-local, verified CLI install, and confirm the active Craft space and document ID before any create, update, or delete action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
craft-helper.sh:7
Finding

Capability-Bearing Craft API URLs Embedded in Public Project Files

Content
View full analysis

Vulnerability Details

File Location: craft-helper.sh:7-9; duplicated in SKILL.md:22-30 and SKILL.md:148-152
Vulnerability Type: Hardcoded sensitive access configuration
Risk Level: High

Vulnerable Code

craft-helper.sh:7-9:

bash
# API URLs
WAVEDEPTH_API="https://connect.craft.do/links/5VruASgpXo0/api/v1"
PERSONAL_API="https://connect.craft.do/links/HHRuPxZZTJ6/api/v1"

SKILL.md:22-30:

bash
### wavedepth Space (Business)
```bash
~/clawd/skills/craft-cli/craft config set-api https://connect.craft.do/links/5VruASgpXo0/api/v1

Personal Space

bash
~/clawd/skills/craft-cli/craft config set-api https://connect.craft.do/links/HHRuPxZZTJ6/api/v1
text

### Technical Analysis

The project embeds unique link-based API endpoints associated with named business and personal Craft spaces. The documentation treats the API URL as the authentication configuration and states that an invalid or unauthorized API URL results in an authentication failure. This indicates that possession of a valid URL may convey access authority rather than merely identifying a public service endpoint.

Storing such capability-bearing URLs directly in scripts and documentation exposes them to every person or system that can read the project, including repository users, package recipients, logs, backups, and source-history mirrors. The documented CLI supports reading and mutating operations, including document listing, retrieval, creation, update, and deletion.

### Attack Path

1. An attacker obtains a copy of the project or reads its repository history.
2. The attacker extracts either hardcoded Craft API URL from `craft-helper.sh` or `SKILL.md`.
3. The attacker installs or otherwise obtains the compatible Craft CLI.
4. The attacker configures the CLI using:
   ```bash
   craft config set-api <extracted-api-url>
   ```
5. The attacker tests access using `craft list`, `craft sea
...[truncated 751 chars]
Remediation
View remediation

Remediation Suggestions

  1. Revoke both exposed Craft links immediately and generate replacements.
  2. Remove all capability-bearing URLs from scripts, documentation, examples, release artifacts, and repository history.
  3. Require users to supply API URLs through protected runtime configuration, such as an environment variable, operating-system credential store, or secret-management service.
  4. Add the local configuration file containing the URL to .gitignore and ensure it has restrictive filesystem permissions.
  5. Replace real endpoints in documentation with obvious placeholders such as https://connect.craft.do/links/YOUR_LINK/api/v1.
  6. Review Craft access logs for use of the exposed links and investigate unexpected document reads or mutations.
  7. Restrict each replacement credential to the minimum required space and operations, and implement periodic rotation.
  8. Add automated secret scanning to CI and pre-commit workflows to prevent similar links from being committed again.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unverified Third-Party Binary Downloaded and Installed into a Global Executable Path

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-13; related version inconsistency at SKILL.md:210-214
Vulnerability Type: Unverified binary dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:9-13:

bash
If not installed:
```bash
curl -L https://github.com/nerveband/craft-cli/releases/download/v1.0.0/craft-darwin-arm64 -o craft
chmod +x craft
sudo mv craft /usr/local/bin/
text

The documented project version is inconsistent with the downloaded release at `SKILL.md:210-214`:

```markdown
## Version

Current version: 1.6.0

Technical Analysis

The installation instructions download a precompiled executable from a third-party GitHub release, make it executable, and place it in /usr/local/bin using sudo. No expected cryptographic checksum, trusted signature, or release-attestation verification is performed before installation.

HTTPS protects the transport connection but does not establish that the release asset contains the intended program if the upstream repository, maintainer account, release process, or asset itself is compromised. The mismatch between the downloaded v1.0.0 binary and the documented current version 1.6.0 further weakens dependency provenance and makes it harder for users to determine which code is expected.

Installing the file in a global executable directory also causes subsequent workflows to trust and execute it by command name. The supplied project does not contain the binary that README.md claims is included, so users may be more likely to follow the unverified download instructions.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, release pipeline, or release asset, or otherwise causes the referenced asset to serve a malicious binary.
  2. A user follows the documented curl command.
  3. Because no checksum or signature is checked, the malicious file is accepted without detecting su ...[truncated 1062 chars]
Remediation
View remediation

Remediation Suggestions

  1. Publish an expected SHA-256 or stronger digest for the exact release asset and verify it before applying executable permissions or installation:
    bash
    curl --fail --location --proto '=https' \
      https://github.com/nerveband/craft-cli/releases/download/v1.6.0/craft-darwin-arm64 \
      -o craft
    echo '<trusted-sha256>  craft' | shasum -a 256 --check -
    
  2. Prefer a cryptographically signed release and verify the signature against a maintainer key distributed through a separate trusted channel.
  3. Use release attestations and reproducible builds so users can validate binary provenance.
  4. Align the downloaded release version with the documented version and pin both the version and digest.
  5. Avoid unnecessary privileged installation. Prefer a user-controlled directory such as ~/.local/bin with appropriate permissions.
  6. Make the installation fail safely by using curl --fail, restricting allowed protocols, and stopping immediately if verification fails.
  7. Correct the README so it does not claim that a binary is included when the distributed project does not contain one.
  8. Document the source commit and build process corresponding to each binary release.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The installation instructions download a binary from the internet and then use sudo to place it in a privileged system path, with no checksum, signature, or provenance verification. If the download source, network path, or release artifact is compromised, this pattern can lead to privileged installation of malicious code.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

bash
curl -L https://github.com/nerveband/craft-cli/releases/download/v1.0.0/craft-darwin-arm64 -o craft
chmod +x craft
sudo mv craft /usr/local/bin/

Configuration

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents easy switching between business and personal API endpoints without any safety guidance about data-boundary changes. In practice, an agent may read, create, update, or delete content in the wrong space if it does not verify the current configuration first, causing cross-space data leakage or unintended modification of business or personal documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes a destructive delete operation with no warning, confirmation guidance, or scope checks. In an agent/LLM context, that increases the chance of accidental or misdirected deletion of documents, especially when document IDs are copied from prior command output or when the active space is not verified first.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.