Back to skill

Security audit

灵枢·Agent设计师

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about designing agents, but its built-in publishing workflow can rewrite a GitHub main branch and publish externally with too little scoping.

Review this skill carefully before installing. Use it for planning and design only unless you are comfortable auditing every release command manually. Do not run the included publish flow with live GitHub or ClawHub credentials unless --force is removed, the repository and branch are verified, staged files are allowlisted, and sensitive enterprise documents or URLs are processed only with explicit approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
ling-shu-agent-designer/SKILL.md:363
Finding

Unsanitized Release Parameters and Destructive Forced Publication

Content
View full analysis
.skill / # 2. Push to GitHub cd /tmp/lingshu-agent-architect git add . git commit -m "Release v: " git push -u origin main --force # 3. Publish to ClawHub clawhub publish --slug lingshu-agent-architect \ --name "Ling Shu Agent Designer" \ --version ``` ### Technical Analysis The release workflow instructs the agent to interpolate a skill name, version, and update description directly into shell commands. It does not require validation, shell-safe quoting, or an argument-array execution API. The following parameters are unsafe: - `` appears unquoted in both the output archive name and source path. - `` is inserted into a double-quoted shell argument. Embedded quotation marks, command substitutions, backticks, or shell metacharacters could escape the intended commit message. - `` is passed unquoted to both Git and ClawHub-related commands. - The workflow uses a predictable shared directory under `/tmp`, without verifying ownership, rejecting symbolic links, or checking the repository remote. - `git add .` stages every file in the working tree rather than an explicit allowlist of reviewed files. - `git push ... --force` can overwrite the remote `main` branch and destroy commits that are not present in the local checkout. The requirement to show a diff and obtain confirmation reduces accidental publication risk, but it does not neutralize shell metacharacters, detect a substituted temporary repository, prevent a time-of-check/time-of-use modification after review, or make the forced push safe. ### Attack Path 1. An attacker suppl ...[truncated 2083 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow includes git push ... --force but does not prominently warn that this can rewrite remote history and destroy others' commits. Omitting that warning in a user-facing release process makes misuse more likely and prevents meaningful informed approval before a destructive remote action.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

git push -u origin main --force is a direct destructive command that can overwrite the remote main branch, erase commit history, and replace trusted content with whatever is currently in the local checkout. In this skill, the danger is amplified because the command is embedded in an automated publish workflow tied to broad triggers and fixed external destinations.

Content

Scanner excerpt · ling-shu-agent-designer/SKILL.md (reported line 361)May include surrounding context.

md
cd /tmp/lingshu-agent-architect
git add .
git commit -m "Release v<x.x.x>: <更新说明>"
git push -u origin main --force

# 3. 发布到 ClawHub
clawhub publish --slug lingshu-agent-architect \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The main skill's trigger conditions are broad enough to activate on generic requests like designing or optimizing an AI agent, without clear scoping or explicit invocation requirements. In a skill that can later create artifacts and assist with publishing workflows, overbroad activation increases the chance of unintended routing, context capture, or execution of higher-impact behaviors when the user only wanted general advice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The enterprise planner is described as activating whenever a user provides company information, website content, or industry reports, which is too permissive for a planning skill that may process large amounts of business-sensitive context. This can cause accidental activation on ordinary discussion or document review tasks, leading to unnecessary ingestion of sensitive enterprise data and unintended generation of strategic outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly tells the agent to use a browser tool to fetch enterprise website content and other parsing tools, but it does not require user consent, disclose that external URLs and uploaded materials will be sent to tools, or define boundaries for network/tool access. In an enterprise-planning context, users may provide sensitive internal documents or private URLs, so silent retrieval/parsing creates a real data-handling and privacy risk even if the intent is operational rather than malicious.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad enough to match common user requests such as asking for an agent design, configuration help, or publication-related actions. Overbroad triggers increase the chance that the skill activates in contexts where the user did not intend to grant packaging or publishing behavior, especially when combined with remote-write capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The release workflow claims automatic triggering from ambiguous phrases like '发布' or '更新技能包', which are common requests and do not by themselves prove informed consent for remote publication. In a skill that can push to GitHub and publish externally, ambiguous auto-triggering materially raises the risk of accidental or socially engineered release actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill embeds a publishing workflow that performs repository modification and includes force-push semantics to a fixed GitHub repository, which exceeds the minimum privileges expected for an agent-design/planning skill. If triggered inappropriately or with incorrect content, it can overwrite remote history and publish unintended artifacts to GitHub and ClawHub.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The identity section states the skill is not about Python code, runtime infrastructure, or databases, framing it as a configuration-and-skill-package designer. However, later sections prescribe concrete shell commands for packaging, committing, force-pushing to GitHub, and publishing to ClawHub, which contradict the earlier representation of a design-focused, non-engineering role.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.