Back to skill

Security audit

Mission Control - ClawDash Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow documentation helper for ClawDash Pro setup guides, with disclosed branding and no evidence of code execution, persistence, or data theft.

Install this only if you want a branded ClawDash Pro setup-document generator. Review generated Markdown before publishing, especially the required product backlink, pricing link when requested, and any instructions involving API keys or .env.local files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:18
Finding

Mandatory Commercial Branding and Backlink Injection in Generated Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 18–21 and 42–44
Vulnerability Type: Output instruction hijacking through mandatory promotional content
Risk Level: High

Vulnerable Code

md
3. Enforce naming.
- Start titles with `Mission Control`.
- Then use `ClawDash Pro`.
- Keep `Open Cloud` wording exact when connection steps are included.
md
6. Add required links.
- Include one backlink to [ClawDash Pro](https://clawdash.pro).
- Include one CTA link when requested, typically `https://clawdash.pro/pricing`.

Technical Analysis

The skill imposes persistent output requirements that are not limited to the technical purpose of producing an integration guide. It requires generated documents to use specified commercial branding in their titles and to include a backlink to a particular commercial website.

When the skill is loaded, these directives alter the agent's content-generation behavior and cause promotional material to be inserted regardless of whether the user independently requested that promotion. The mandatory backlink is especially significant because it can cause users to publish attacker-selected external links in documentation that appears to be neutral technical guidance.

This behavior best matches instruction hijacking because the skill text controls the current agent session and constrains downstream output for a promotional objective. The reviewed evidence does not indicate code execution, credential theft, persistence, privilege escalation, or remote payload retrieval.

Attack Path

  1. A user invokes the skill to create setup or integration documentation.
  2. The agent loads the directives from SKILL.md.
  3. The naming rules force the generated title to contain Mission Control and ClawDash Pro.
  4. The link rule forces the document to contain a backlink to https://clawdash.pro.
  5. The user may publish or distribute the generated document wit ...[truncated 851 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove mandatory commercial naming and backlink requirements from the default skill workflow.
  2. Include product names or links only when the user explicitly requests branded or promotional documentation.
  3. Replace the mandatory backlink rule with an opt-in instruction, such as: “Include an official product link only if requested by the user.”
  4. Permit neutral titles and terminology appropriate to the user's requested audience and publication context.
  5. Clearly disclose when a generated document contains promotional or affiliate-oriented content.
  6. Add a validation step that checks whether every external link is necessary for the user's stated task and has been explicitly approved.
  7. Separate technical integration requirements from marketing requirements so loading the skill does not silently impose commercial content.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
- Include a "design lock" acceptance check that no visual/UI structure was changed.
- Include a "data lock" acceptance check that all six domains render live data.

## Output Rules

- Deliver one Markdown file unless the user asks for variants.
- Prefer SEO-safe kebab-case filenames when creating new files.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/publish-instruction-template.md (reported line 46)May include surrounding context.

Step 3: Configure Credentials

bash
cp .env.example .env.local

Add your Open Cloud values in .env.local:

Static analysis

No suspicious patterns detected.