Back to skill

Security audit

Preflight Workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent preflight checklist, but it includes under-disclosed persistent shell changes and an unrelated live publishing script.

Review install.sh before running it, avoid custom install paths containing shell metacharacters, and consider adding PATH manually instead of letting the installer edit shell startup files. Treat publish.sh as unrelated release tooling and do not run it unless you intend to publish to ClawHub with the configured owner account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:19
Finding

Persistent Shell Command Injection Through Unsanitized Installation Path

Content
View full analysis
/dev/null; then echo "" >> "$SHELL_RC" echo "# preflight workflow package" >> "$SHELL_RC" echo "export PATH=\"\$PATH:$INSTALL_DIR\"" >> "$SHELL_RC" echo " Added to PATH ($SHELL_RC)" echo " Run: source $SHELL_RC" else echo " PATH already contains preflight; skipping" fi ``` ### Technical Analysis The `--path` argument is accepted without validation and stored directly in `INSTALL_DIR`. Although filesystem operations quote this variable correctly, the installer subsequently interpolates it into executable shell syntax appended to the user's `.bashrc` or `.zshrc`. Shell quoting at the time `echo` runs does not make the generated startup-file content safe. An installation path containing a double quote, command separator, command substitution, or newline can terminate the generated `export` statement and inject additional shell commands. For example, a value conceptually shaped as: ```text /some/path"; injected_command; # ``` produces startup-file content shaped as: ```bash export PATH="$PATH:/some/path"; injected_command; #" ``` The injected command executes whenever the startup file is sourced, including during later interactive shell sessions. This turns a nominal path parameter into a persistent code-execution channel. The same issue affects both Bash and Zsh because the installer selects either `.bashrc` or `.zshrc` as the output file. ### Attack Path 1. An attacker influences the arguments passed to ...[truncated 1497 chars]
Remediation
View remediation
&2 exit 1 } INSTALL_DIR=$2 case "$INSTALL_DIR" in *$'\n'*|*$'\r'*) printf '%s\n' "Error: installation path contains invalid characters" >&2 exit 1 ;; esac shift 2 ;; ``` 2. Serialize the path using Bash-compatible shell escaping rather than embedding it inside manually constructed quotes: ```bash printf -v QUOTED_INSTALL_DIR '%q' "$INSTALL_DIR" printf '\n# preflight workflow package\n' >> "$SHELL_RC" printf 'export PATH="$PATH":%s\n' "$QUOTED_INSTALL_DIR" >> "$SHELL_RC" ``` If Zsh portability is required, avoid relying solely on Bash-specific `%q`. Prefer a fixed launcher directory with a validated character set or create a symbolic link in a standard user-local binary directory such as `$HOME/.local/bin`. 3. Apply a conservative validation policy where practical, for example permitting only expected path characters: ```bash case "$INSTALL_DIR" in *[!A-Za-z0-9_./\ -]*) printf '%s\n' "Error: unsupported characters in installation path" >&2 exit 1 ;; esac ``` 4. Avoid editing startup files by default. Ask for explicit confirmation or provide the exact configuration line for the user to review and add manually. 5. Use a unique marker comment for idempotency instead of the broad `grep -q "preflight"` check. The current test can be triggered by unrelated text and may incorrectly skip installation: ```bash MARKER='# preflight-workflow managed entry' if ! grep -Fqx "$MARKER" "$SHELL_RC" 2>/dev/null; then printf '\n%s\n' "$MARKER" >> "$SHELL_RC" # Append safely serialized configuration. fi ``` 6. Add regression tests using paths containing spaces, ...[truncated 191 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill's purpose is to perform or enforce four mandatory checks before operations. However, the supplied code chunk does not implement those checks at all; it is purely an installation script. Its primary behavior is filesystem modification and shell configuration, including creating directories, copying files, chmod'ing a script, and appending PATH changes to the user's shell rc file. Those are materially different capabilities from the declared workflow behavior, so this is a clear description/behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description suggests an operational safety assistant that enforces four checks before actions. The supplied code does not implement search, rollback, test, or scope checks. Instead, it is a release/publishing script for uploading a skill to Clawhub. Its primary purpose is materially different from the declared purpose, and it exercises undeclared deployment-related capabilities, including remote publish actions and use of a specific owner account and local filesystem path.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
86% confidence
Finding

The instruction to 'Update this SKILL.md' encourages self-modification of the skill's own behavior based on operational outcomes. In an agent context, self-modifying instructions can let the toolchain drift from reviewed behavior, weaken safeguards over time, or introduce malicious or erroneous changes without proper review.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
|---------|--------|
| ✅ Success | Log it (date + what + result) |
| ❌ Failure | Write to LEARNINGS.md (root cause + fix + prevention) |
| 💡 New insight | Update this SKILL.md |

## CLI Mode (no agent, just a shell script)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
| `SKILL.md` | Loadable skill for any SKILL.md-compatible agent |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is described as a preflight safety workflow, but this script performs an actual publish operation after only minimal file-existence checks and a dry run. In an agent-skill context, that mismatch can cause users or downstream agents to invoke deployment behavior they did not intend, creating a material risk of unauthorized or premature publication.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese usage example uses a very generic activation phrase ('加载 preflight-workflow skill,说"先跑 preflight"'), which could plausibly overlap with ordinary user conversation and cause unintended skill activation in agents that rely on loose natural-language matching. In an agent context, accidental invocation of workflow logic can alter execution flow, block operations unexpectedly, or interact badly with other skills if trigger boundaries are not explicit.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README recommends piping a remotely downloaded archive directly into extraction and then running an installer, without any warning about authenticity, integrity, or code review. This normalizes execution of unverified remote content and could lead users to run tampered or malicious installer code if the hosting domain, transport, or archive is compromised.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The English activation instruction ('Load the skill and say "run preflight"') is loosely specified and may be triggered by normal prose, testing text, or quoted examples rather than deliberate invocation. In systems that auto-route based on keyword similarity, this ambiguity increases the risk of accidental skill loading or execution at the wrong time.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill advertises shell-related usage and includes executable script references, but it does not declare any explicit tool scope or permission boundaries. In agent ecosystems, missing scope metadata can cause overly broad tool access or make it unclear what the agent is authorized to execute, increasing the risk of unintended command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation guidance is extremely broad ('every time' before running commands, modifying code, changing configuration, or unfamiliar operations), which can cause the skill to trigger for many routine tasks. Over-broad invocation can degrade agent behavior, create workflow deadlocks, or cause users to bypass safety mechanisms entirely due to alert fatigue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer appends an export line directly into the user's shell startup file without prompting, previewing the change, or requiring explicit consent. Modifying ~/.bashrc or ~/.zshrc creates persistent environment changes that can surprise users, interfere with existing shell configuration, and normalize unsafe installer behavior in a skill-distribution context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell script includes natural-language comments, usage text, prompts, and output exclusively in Chinese, which effectively forces a specific language on users. Under the policy, this is a locale/language constraint that should either be optional, user-selectable, or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The header advertises a safety-oriented preflight workflow, but the implementation is a one-click release script intended to execute after entering a device code. This misleading framing increases the chance that a user or agent will trust and run the script expecting harmless checks, when it actually performs a state-changing external publish action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language comments and usage instruction are written only in Chinese, including the directive about when the script should be executed. This imposes a specific language/locale on operators without any opt-in or alternative, matching the policy's language-choice concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase saying the skill can be triggered by simply saying "run preflight" is overly broad and does not define any authentication, context, or explicit activation boundaries. In agent ecosystems, vague trigger phrases can cause accidental invocation during normal conversation or prompt-injection-style coercion, especially because this skill is positioned as a general safety workflow that may be wired into operational actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file forces a specific language/locale for all user-facing instructions, examples, and descriptions without any opt-in or alternative language option. Under the policy, language constraints should either be user-selectable or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language strings in comments and terminal output are written in Chinese, and the script does not offer users any language or locale selection. This can violate language/locale policy where tools must not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The document explicitly labels the primary listing body as English while the surrounding material is Chinese, but it does not explain whether the published skill experience is language-selectable or intentionally targeted to a specific locale. That can create a locale-policy concern if users are effectively forced into one language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.