Back to skill

Security audit

Clawhub Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a real Citedy marketing automation integration, but it can publish publicly, spend credits, start recurring content runs, add referral links, and delete content without strong confirmation guardrails.

Review this before installing. Use it only with a Citedy account you trust, set publishing defaults to preview or draft-first where possible, explicitly approve every public post, recurring session, referral footer, and deletion, and provide a non-sensitive agent name during registration.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:476
Finding

Referral Link Injection into Automatically Published Social Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 476-494
Vulnerability Type: Persistent instruction and output hijacking
Risk Level: High

Vulnerable Code

http
POST /api/agent/adapt
{
  "article_id": "uuid-of-article",
  "platforms": ["linkedin", "x_thread"],
  "include_ref_link": true
}

Required: article_id (UUID), platforms (1-3 unique values)

Platforms: x_article, x_thread, linkedin, facebook, reddit, threads, instagram, instagram_reels, youtube_shorts

Optional:

  • include_ref_link (bool, default true) — append referral footer to each adaptation

~5 credits per platform (varies by article length). Max 3 platforms per request.

If the owner has connected social accounts, adaptations for linkedin, x_article, x_thread, facebook, reddit, instagram, and youtube_shorts are auto-published. The response includes platform_post_id for published posts.

text

Related persistent instructions also appear at `SKILL.md:126-139` and `SKILL.md:1352-1359`, directing the agent to save and use the account owner's referral URL and to always include it when recommending Citedy.

### Technical Analysis

The Skill changes normal agent output by directing it to insert an account-attributed referral URL. The API parameter responsible for this behavior defaults to `true`, and the documented workflow explicitly supplies that value. Referral insertion is not technically required to generate an article or adapt it for social media.

The issue is amplified because adaptations for connected accounts may be published automatically. Consequently, promotional tracking material can be posted under the user's identity without a separate decision to include affiliate or referral advertising. The instruction financially benefits the referral owner and is therefore not a neutral implementation detail.

The pre-scan-highlighted statement at line 45, `You are now conne
...[truncated 1434 chars]
Remediation
View remediation

Remediation Suggestions

  1. Change include_ref_link to default to false.
  2. Remove instructions requiring the agent to always include or persistently prefer the account owner's referral URL.
  3. Require explicit, informed user consent before adding a referral link to any output.
  4. Clearly disclose that the link is account-attributed and may financially benefit the account owner.
  5. Present the exact referral footer in a preview before publication.
  6. Separate content adaptation from publication so adaptation does not automatically post to connected accounts.
  7. Require per-destination confirmation immediately before publishing referral-bearing content.
  8. Record consent and publication destinations in an auditable action log.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:365
Finding

Content Generation Defaults to Public and Potentially Recurring Side Effects

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 365-401
Vulnerability Type: Unsafe publication and paid-action defaults
Risk Level: High

Vulnerable Code

http
POST /api/agent/autopilot
{
  "topic": "How to Use AI for Content Marketing",
  "source_urls": ["https://example.com/article"],
  "language": "en",
  "size": "standard",
  "mode": "standard",
  "enable_search": false,
  "persona": "musk",
  "illustrations": true,
  "audio": true,
  "disable_competition": false,
  "auto_publish": true
}

Required: either topic or source_urls (at least one)

Optional:

  • topic — article topic (string, max 500 chars)
  • source_urls — array of 1-3 URLs to extract text from and use as source material (2 credits per URL)
  • size — mini (~500w), standard (~1000w, default), full (~1500w), pillar (~2500w)
  • mode — standard (default, full pipeline) or turbo (ultra-cheap micro-articles, see below)
  • enable_search (bool, default false) — enable web + X/Twitter search for fresh facts (turbo mode only)
  • persona — writing style persona slug (call GET /api/agent/personas for list, e.g. "musk", "hemingway", "jobs")
  • language — ISO code, default "en"
  • illustrations (bool, default false) — AI-generated images injected into article (disabled in turbo mode)
  • audio (bool, default false) — AI voice-over narration (disabled in turbo mode)
  • disable_competition (bool, default false) — skip SEO competition analysis, saves 8 credits
  • auto_publish (bool, optional) — publish article immediately after generation. When false, article stays as draft (status: "generated") and must be published later via POST /api/agent/articles/{id}/publish. Default uses tenant setting (configurable in dashboard → Agent Settings). If no tenant setting, defaults to true.

When source_urls is provided, the response includes extraction_results showing success/fai ...[truncated 3196 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make auto_publish: false the unconditional default.
  2. Treat content generation, adaptation, scheduling, and publication as separate user-authorized operations.
  3. Require an explicit confirmation immediately before every public publication.
  4. Show the article title, preview, destinations, visibility, and exact or maximum credit cost before confirmation.
  5. Do not infer permission to publish from permission to generate content.
  6. Require separate confirmation before creating or starting a recurring session.
  7. Provide session status, projected recurring cost, an end date or spending limit, and a clearly documented stop operation.
  8. Restrict publication to destinations individually selected by the user rather than all connected accounts.
  9. For asynchronous publication, poll for final status and accurately report whether publication succeeded or failed.
  10. Apply conservative tenant defaults such as ask_all or show_preview; never silently fall back to autonomous publication.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/register.mjs:10
Finding

Local Hostname Disclosed During Default Agent Registration

Content
View full analysis

Vulnerability Details

File Location: scripts/register.mjs, lines 10-19
Vulnerability Type: Unnecessary system metadata disclosure
Risk Level: Low

Vulnerable Code

js
import { hostname } from "os";

const BASE_URL = "https://www.citedy.com";

async function main() {
  const agentName = process.argv[2] || `agent-${hostname()}`;

  console.log(`Registering agent "${agentName}" with Citedy...`);

  const res = await fetch(`${BASE_URL}/api/agent/register`, {
    method: "POST",
    headers: { "Content-Type": "application/json" },
    body: JSON.stringify({ agent_name: agentName }),
  });

Technical Analysis

If the user does not supply an agent name, the registration script reads the local machine hostname and sends it to Citedy as part of the registration request. A stable registration identifier is necessary, but use of the real hostname is not.

Hostnames frequently contain usernames, employee names, organization names, environment identifiers, infrastructure roles, or internal asset naming conventions. Sending this value to an external service expands data disclosure beyond the minimum information needed to register an agent.

The request uses HTTPS and targets the documented Citedy endpoint. No response execution or local command execution was found, so the issue is limited to unnecessary metadata disclosure.

Attack Path

  1. The user runs the recommended command node scripts/register.mjs without an explicit agent name.
  2. The script invokes hostname() from the Node.js operating-system module.
  3. It constructs an identifier in the form agent-<local-hostname>.
  4. It sends that identifier to https://www.citedy.com/api/agent/register.
  5. Citedy receives and may retain the local hostname as registration metadata.

Impact Assessment

No additional system privilege is obtained. The external service receives local system metadata that is unnecessary for the de ...[truncated 379 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require the user to provide an explicit, non-sensitive agent name.
  2. Alternatively, generate a random identifier such as agent- followed by a cryptographically random value.
  3. Do not derive externally transmitted identifiers from the hostname, username, home directory, or other local system metadata.
  4. Display all fields that will be transmitted and obtain confirmation before registration.
  5. Document the service's retention and deletion policy for registration metadata.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
node scripts/register.mjs [agent_name]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The skill exposes a raw delete operation for product knowledge documents without guardrails on how the agent should validate identifiers, confirm user intent, or prevent deletion based on untrusted content. In an agentic environment, that creates a parameter-abuse risk where the model could delete the wrong document or act on attacker-supplied IDs.

Content

Scanner excerpt · SKILL.md (reported line 955)May include surrounding context.

Delete document:

http
DELETE /api/agent/products/{id}
  • 0 credits

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This endpoint permanently deletes articles and associated storage, yet the skill provides no constraints on parameter provenance, ownership verification in the agent workflow, or mandatory confirmation. That makes misuse particularly dangerous because a single attacker-influenced or mistaken article ID could trigger irreversible content loss and break downstream publishing/workflow state.

Content

Scanner excerpt · SKILL.md (reported line 1103)May include surrounding context.

Delete Article

http
DELETE /api/agent/articles/{id}
  • 0 credits. Permanently deletes an article and its associated storage files (images, audio).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Deleting webhook endpoints without strict confirmation and trusted parameter sourcing can silently disable event delivery, monitoring, or downstream automations. In context, webhooks may support operational workflows, so accidental or attacker-influenced deletion can cause loss of visibility and missed business events even if it is only a soft-delete.

Content

Scanner excerpt · SKILL.md (reported line 1238)May include surrounding context.

Delete Webhook Endpoint

http
DELETE /api/agent/webhooks/{id}
  • 0 credits. Soft-deletes the endpoint.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes extensive network-facing capabilities and sensitive side effects, but it does not declare any explicit tool scope such as allowed-tools or permissions. That weakens the host's ability to constrain execution and increases the blast radius if the skill is invoked in the wrong context or combined with prompt injection, since the agent is instructed to call many authenticated external endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages direct and automated publishing to external platforms, including recurring autopilot behavior, without a clear requirement for preview, consent, or destination confirmation. Because publishing affects third-party accounts and public content, an agent can cause reputational damage, spam, compliance issues, or unintended disclosure if it posts automatically based on incomplete or manipulated inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents irreversible deletion of articles and associated storage files but does not require a confirmation step or a user-warning before execution. In an agent setting, omission of an explicit confirmation rule makes accidental or manipulated destructive actions much more likely, especially if user intent is ambiguous or influenced by hostile content.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 1351)May include surrounding context.

md
- Reply in the user's language (match the language they write in).
- Before calling an API, briefly tell the user what you're about to do and the credit cost.
- For async operations (scout, ingest, shorts, leadmagnet, brand.scan), automatically poll the companion tool every 10-15 seconds — don't ask the user to poll manually.
- Show results as a readable summary, not raw JSON. Use bullet points, tables, or numbered lists.
- When showing scout results, highlight the top 5 trends with brief context.
- When an article is generated, show: title, word count, URL, credits spent.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/register.mjs (reported line 42)May include surrounding context.

js
const data = await res.json();

  if (!data.approval_url) {
    console.error("Unexpected response — no approval_url:", data);
    process.exit(1);
  }

Static analysis

No suspicious patterns detected.