Back to skill

Security audit

Agent发布技能

Security checks for vulnerabilities and agentic risk

Overview

This skill is meant to publish agent packages, but it defaults to packaging complete agent configuration files and pushing them to public external destinations with limited safeguards.

Review the exact packaged files before installing or using this skill. Do not use it on agents whose SOUL.md, AGENTS.md, IDENTITY.md, TOOLS.md, or generated skill directory may contain secrets, private endpoints, internal instructions, customer data, or credentials. Prefer private repositories, explicit file allowlists, secret scanning, and separate confirmations for ClawHub publishing, GitHub pushing, and public visibility.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Potential Public Disclosure of Sensitive Agent Configuration

Content
View full analysis
/ ├── SKILL.md ├── _meta.json └── references/ ├── soul.md ├── agents.md ├── identity.md └── tools.md ``` ```bash gh repo create / \ --public \ --description "" \ --source \ --push cd git add -A git commit -m "v: " git push origin master ``` The packaging instructions specify that `references/soul.md` contains the complete `SOUL.md` file. The adjacent entries similarly package `AGENTS.md`, `IDENTITY.md`, and `TOOLS.md`. ### Technical Analysis The workflow copies complete Agent configuration files into a publication directory and then publishes that directory to ClawHub and GitHub. When creating a GitHub repository, it explicitly selects public visibility through `--public`. For existing repositories, `git add -A` stages every tracked and untracked change under the Skill directory without applying a file allowlist. Agent configuration files may contain private operating instructions, internal tool details, filesystem paths, private endpoints, user information, or credentials accidentally embedded during development. The workflow does not require secret scanning, sensitive-content review, an explicit file manifest, repository-visibility verification, or inspection of the staged Git diff before publication. Although the Skill asks whether publication should occur, that general confirmation does not communicate which files will become public or require separate approval for public repository visibility. Once pushed, sensitive information may remain recoverable from Git history even if it is removed in a later commit. ### Attack Path 1. A developer or Agent writes sensitive information into `SOUL.md`, `AGE ...[truncated 1483 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- `SKILL.md`(如有)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill declares automatic activation whenever core files change, but does not define sufficiently strict scope boundaries such as trusted project type, expected repository layout, or user-initiated publish mode. In a base skill that must be loaded in all agent workspaces, this broad condition increases the chance of unsolicited publish flows and unintended handling of sensitive workspace content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very common words such as '发布', '推送', 'publish', and 'push', which can appear in ordinary conversation and may cause the skill to activate outside the user's intended context. Because this skill performs packaging and publishing to external services, accidental activation can lead to unintended repository updates or publication prompts during unrelated tasks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The changelog entry is written entirely in Chinese, which indicates a language-specific presentation in a manifest file without any visible user opt-in or explanation that the skill is intended only for a Chinese-speaking context. This can violate language/locale policy when a skill implicitly forces one language for metadata or user-facing descriptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.