Back to skill

Security audit

skill-distribution

Security checks for vulnerabilities and agentic risk

Overview

This skill is a publishing guide for agent skills, with local validation and registry instructions that are disclosed and aligned with its purpose.

Install only if you want help publishing skills publicly. Review each registry command before running it, confirm license and marketplace terms, and run the validator only on skill folders you intend to publish.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (11)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/checklist.md (reported line 31)May include surrounding context.

md
- **Does the description trigger?** Try three prompts a real user would type without naming the skill.
- **Secrets.** Search the folder for keys, tokens, internal URLs and personal paths before the first push; git history is public too.
- **Rights.** The user must own or be allowed to redistribute everything bundled, including scripts, fonts and reference text.
- **Security scan triggers.** Instructions to pipe remote scripts into a shell, read credential files, disable safety checks or ignore the user get skills flagged or delisted on ClawHub, agentskill.sh, skills.sh and the Hermes hub.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_skill.py (reported line 103)May include surrounding context.

python
if not path.is_file() or any(part.startswith(".") for part in path.relative_to(folder).parts):
            continue
        total += path.stat().st_size
        if path.suffix.lower() in {".md", ".txt", ".py", ".sh", ".js", ".ts", ".json", ".yaml", ".yml", ".env"}:
            content = path.read_text(encoding="utf-8", errors="replace")
            rel = path.relative_to(folder)
            if SECRET_RE.search(content):

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to read local reference files and run a shell command (python scripts/check_skill.py <skill-folder>), but it declares no permissions or allowed-tools scope. That mismatch increases the chance the skill is granted broader-than-necessary capabilities by a host or used without clear user visibility into its file/system access expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill whenever the user asks how to 'share, publish, upload, list, submit, release, sell, or get installs' for a skill, and even if they only name one marketplace. While skill-related, this trigger is broad and lacks exclusion conditions or negative examples, which can cause unintended invocation for adjacent requests about publishing or marketplaces.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill recommends using npx skills add owner/repo without pinning a package version. Unpinned npx execution can fetch the latest package at runtime, so a compromised upstream package, typosquatted replacement, or breaking update could execute unexpected code on the user's system.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/checklist.md (reported line 20)May include surrounding context.

md
| Registry | Extra requirement |
|---|---|
| ClawHub | `version` in semver (first release `1.0.0`). Everything published is licensed **MIT-0**, with no per-skill override — do not publish there if the user needs another license. Bundle max 50 MB. Declare runtime needs under `metadata.openclaw` (`requires.env`, `requires.bins`, `primaryEnv`, `install`). |
| skills CLI / skills.sh | Skills must sit where the CLI looks: `skills/<name>/SKILL.md`, optionally with one or two category folders in between, or an agent folder such as `.claude/skills/`. `metadata.internal: true` hides a skill from normal discovery. |
| Claude Code plugin | Plugin `name` in kebab-case and treated as permanent. `claude plugin validate --strict ./plugin` must pass. Either bump `version` on every release or omit it so the commit SHA is used. |
| Codex / ChatGPT | Optional `agents/openai.yaml` inside the skill for display name, icon, brand colour and `allow_implicit_invocation`. |
| claude.ai upload | A zip of the skill folder, max 50 MB (under 10 MB recommended). Code execution must be enabled for the skill to run. |

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/open-registries.md (reported line 19)May include surrounding context.

md
There is no upload and no submission form. skills.sh hosts nothing: the `skills` CLI clones GitHub repos, and the leaderboard is built from anonymous install telemetry. A skill shows up after people install it.

- Users install with: `npx skills add owner/repo` (also accepts full git URLs, a subfolder URL such as `https://github.com/owner/repo/tree/main/skills/my-skill`, and local paths).
- The CLI finds skills in `skills/`, `skills/.curated/` and agent folders like `.claude/skills/`, up to three levels deep.
- Scaffold a new one with `npx skills init my-skill`.
- `metadata.internal: true` hides a skill unless the user sets `INSTALL_INTERNAL_SKILLS=1`.
- Installs made with `DISABLE_TELEMETRY=1` or `DO_NOT_TRACK=1` are not counted.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/plugins.md (reported line 100)May include surrounding context.

md
## Gemini CLI extension

Extensions bundle skills with commands and connectors, live in public GitHub repos, and need no approval from Google; the gallery picks them up. The manifest name and the gallery's inclusion rule were **not verified** here — check https://geminicli.com/docs/extensions/ ("Build Gemini CLI extensions") for the current manifest and release steps before publishing.

Static analysis

No suspicious patterns detected.