Back to skill

Security audit

Clawdbot Documentation Expert

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation helper with simple local helper scripts, and the only notable issue is a gateway example that could expose a service if copied without care.

Reasonable to install as a documentation aid. Before copying its gateway example, consider changing the bind host to 127.0.0.1 for local-only use or ensure authentication, firewalling, and TLS/reverse-proxy controls are in place for remote access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
snippets/common-configs.md:37
Finding

Gateway Listens on All Network Interfaces by Default

Content
View full analysis

Vulnerability Details

File Location: snippets/common-configs.md, lines 37–45
Vulnerability Type: Unsafe network exposure
Risk Level: Medium

Vulnerable Code

json
{
  "gateway": {
    "host": "0.0.0.0",
    "port": 8080
  }
}

Technical Analysis

The reusable gateway configuration binds the service to 0.0.0.0, causing it to listen on every available IPv4 network interface. The example does not include authentication, TLS, firewall restrictions, network allowlisting, or a warning about the security implications of exposing the gateway.

Because this is presented as a ready-to-use common configuration, users may copy it into environments where port 8080 is reachable from a local network, container network, cloud network, or the public Internet. Actual exploitability depends on the gateway's authentication controls and surrounding network policy, neither of which is established by the audited project.

Attack Path

  1. A user copies the provided gateway configuration.
  2. The gateway starts and listens on port 8080 across all IPv4 interfaces.
  3. A firewall, container port mapping, cloud security group, or local network configuration permits another host to reach that port.
  4. An attacker discovers the exposed gateway through network scanning or prior knowledge.
  5. The attacker connects to any gateway functionality not protected by effective authentication and authorization controls.

Impact Assessment

If the deployed gateway lacks adequate compensating controls, an attacker within network reach could access exposed interfaces, APIs, operational information, or Agent-related functionality. The exact privileges and scope depend on the gateway implementation and its runtime authentication configuration. The audited snippet alone does not demonstrate privileged access or successful authentication bypass.

Remediation
View remediation

Remediation Suggestions

  • Change the default bind address to 127.0.0.1 so the gateway is accessible only from the local host.
  • Require users to opt in explicitly before binding to 0.0.0.0.
  • Add a prominent warning explaining that 0.0.0.0 exposes the service on all available IPv4 interfaces.
  • If remote access is necessary, require strong authentication and authorization for every gateway endpoint.
  • Terminate TLS directly at the gateway or through a securely configured reverse proxy.
  • Restrict inbound access with host firewalls, cloud security groups, container network policies, or IP allowlists.
  • Avoid publishing port 8080 to public interfaces unless operationally required.
  • Document a hardened remote-access example rather than presenting unrestricted binding as the common default.
  • Add deployment checks that warn or fail when a gateway binds publicly without authentication or transport encryption.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.