Back to skill

Security audit

ClawDate

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with ClawDate account operations, but it installs recurring background execution and has unsafe installation/input-handling paths that need review before use.

Install only after reviewing the exact CLI package and the missing profile-sync template from a trusted source. Avoid install.sh remote SOURCE URLs, use --skip-cron unless persistent sync is explicitly needed, validate profile names to simple safe identifiers, and protect or delete owner profile JSON/logs that contain contact details and internal assessments.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T06 · System Persistence

Error
Location
scripts/init_owner.sh:171
Finding

Recurring Cron Persistence Is Installed by Default

Content
View full analysis
/dev/null 2>&1; then warn "crontab is not available on this machine; cron setup skipped." return fi section "Cron" ( crontab -l 2>/dev/null | grep -v -F "${PROFILE}-sync.sh"; echo "$CRON_ENTRY" ) | crontab - crontab -l | grep -F "${PROFILE}-sync.sh" || warn "Cron entry write verification did not echo back." } ``` The recurring command is constructed at `scripts/init_owner.sh:91-94`: ```bash OWNER_PROFILE_PATH="$HOME/.clawdate/profiles/${PROFILE}-owner-profile.json" WRAPPER_SCRIPT_PATH="$HOME/.clawdate/bin/${PROFILE}-sync.sh" LOG_PATH="$HOME/.clawdate/logs/${PROFILE}.log" CRON_ENTRY="*/5 * * * * /bin/bash -lc \"$WRAPPER_SCRIPT_PATH\"" ``` Equivalent persistence instructions are also documented in `SKILL.md:232-243` and bundled in `assets/cron.example.txt:1-3`: ```bash CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"' ( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab - crontab -l | grep -F "__PROFILE__-sync.sh" ``` ### Technical Analysis The recommended bootstrap path modifies the current user's crontab and schedules the generated synchronization wrapper to execute every five minutes. This scheduled task survives completion of the Skill run and continues across shell and Agent sessions. Ongoing synchronization is related to the declared ClawDate functionality, and the script offers a `--skip-cron` option. Nevertheless, persistence is enabled by default rather than being installed only after explicit, informed user consent. The project also provides no corresponding removal script or documented c ...[truncated 1563 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
install.sh:4
Finding

Arbitrary Remote Source Can Supply Executable Skill Files

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/init_owner.sh:127
Finding

Unpinned npm Package Is Installed Globally or Executed Through npx

Content
View full analysis
/dev/null 2>&1; then section "CLI Install" note "Global clawdate-agent not found. Trying npm install -g @qybaihe/clawdate-agent-cli ..." if npm install -g @qybaihe/clawdate-agent-cli; then hash -r else warn "Global install failed. Falling back to npx @qybaihe/clawdate-agent-cli." fi fi if command -v clawdate-agent >/dev/null 2>&1; then CLI=("clawdate-agent") CLI_DESC="clawdate-agent" else CLI=("npx" "@qybaihe/clawdate-agent-cli") CLI_DESC="npx @qybaihe/clawdate-agent-cli" fi ``` The runbook repeats the unpinned execution pattern in `SKILL.md:72-80` and `SKILL.md:96-101`: ```bash npm install -g clawhub ``` ```bash npx @qybaihe/clawdate-agent-cli --help ``` ```bash npx @qybaihe/clawdate-agent-cli install --install-url "" --agent-label "龙虾" --profile "" ``` ### Technical Analysis No exact version or integrity value is specified for `@qybaihe/clawdate-agent-cli`. Consequently, npm resolves the package to the registry version current at execution time. The effective code can change after this Skill has been audited. The bootstrap first attempts a global installation, which broadens the filesystem and environment scope of the dependency. npm lifecycle scripts may execute during installation. If global installation fails, `npx` still retrieves and executes the unpinned package. The CLI subsequently receives the account-specific installation URL, local profile identifier, owner-profile data, and WeChat contact information. A malicious package release or compromised dependency could access and transmit this information. ### Attack Path 1. The expected `clawdate-agent` binary is not present. 2. Bootstrap inv ...[truncated 1069 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init_owner.sh:47
Finding

Unvalidated Profile Identifier Enables Path Manipulation and Cron Command Injection

Content
View full analysis
"$WRAPPER_SCRIPT_PATH" chmod 0755 "$WRAPPER_SCRIPT_PATH" note "Wrote $WRAPPER_SCRIPT_PATH" } ``` Finally, it affects crontab rewriting: ```bash install_cron() { if [[ "$SKIP_CRON" -eq 1 ]]; then warn "Skipping cron setup because --skip-cron was provided." return fi if ! command -v crontab >/dev/null 2>&1; then warn "crontab is not available on this machine; cron setup skipped." return fi section "Cron" ( crontab -l 2>/dev/null | grep -v -F "${PROFILE}-sync.sh"; echo "$CRON_ENTRY" ) | crontab - crontab -l | grep -F "${PROFILE}-sync.sh" || warn "Cron entry write verification did not echo back." } ``` ### Technical Analysis `PROFILE` is accepted directly from a command-line argument and is not restricted to a safe identifier syntax. The runbook states that the profile name comes from an operator prompt, so this value may originate o ...[truncated 2369 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill is a detailed SOP for operators performing owner account setup/rebinding and operational validation tasks. The supplied code chunk is not that SOP logic; it is an installation script for deploying the skill's files. While installation is loosely related to setup, the actual behavior materially differs from the declared primary purpose because it performs file system installation, optional remote fetching of files, permission changes, and deletion of a script, but does not carry out the operator workflow described. This is a description/behavior mismatch.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · assets/cron.example.txt (reported line 2)May include surrounding context.

text
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The rm -f command operates on a path derived from the externally influenced SKILL_ROOT variable, so an unsafe or unexpected SKILL_ROOT can cause deletion outside the intended installation target. The path suffix is fixed, which limits scope, but the lack of path validation still makes this a real file-deletion risk.

Content

Scanner excerpt · install.sh (reported line 33)May include surrounding context.

sh
install_file "assets/cron.example.txt"
install_file "scripts/init_owner.sh"

rm -f "$SKILL_ROOT/scripts/cleanup_owner.sh"

chmod 0644 "$SKILL_ROOT/SKILL.md" \
  "$SKILL_ROOT/agents/openai.yaml" \

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · scripts/init_owner.sh (reported line 184)May include surrounding context.

sh
PATH" > "$WRAPPER_SCRIPT_PATH"
  chmod 0755 "$WRAPPER_SCRIPT_PATH"
  note "Wrote $WRAPPER_SCRIPT_PATH"
}

install_cron() {
  if [[ "$SKIP_CRON" -eq 1 ]]; then
    warn "Skipping cron setup because --skip-cron was provided."
    return
  fi

  if ! command -v crontab >/dev/null 2>&1; then
    warn "crontab is not available on this machine; cron setup skipped."
    return
  fi

  section "Cron"
  ( crontab -l 2>/dev/null | grep -v -F "${PROFILE}-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
  crontab -l | grep -F "${PROFILE}-sync.sh" || warn "Cron entry write verification did not echo back."
}

run_wrapper_once() {
  section "Wrapper Smoke Check"
  bash "$WRAPPER_SCRIPT_PATH"
  if [[ -f "$LOG_PATH" ]]; then
    tail -n 20 "$LOG_PATH"
  else
    warn "Log file not found yet: $LOG_PATH"
  fi
}

section "CLI Ready"
note "Using $CLI_DESC"

if [[ "$SKIP_INSTALL" -ne 1 ]]; then
  section "Install"
  run_cli install --install-url "$INSTALL_URL" --agent-label "$AGENT_LABEL" --profile "$PROFILE"
els

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs shell execution, package installation, cron modification, and wrapper script creation, but it declares no explicit tool scope or allowed-tools metadata. That makes the operational boundary ambiguous and increases the chance an agent executes powerful commands without least-privilege constraints or user awareness.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

At line 34 the skill states that the init script will write a 5-minute cron entry automatically, meaning persistence is built into the preferred bootstrap path rather than an optional advanced step. This makes the behavior more dangerous because operators may create unattended recurring execution before fully understanding what code the wrapper runs.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
- run `whoami / sync / profile get`
- export the owner profile draft JSON
- materialize the wrapper script
- write the 5-minute cron entry
- run a wrapper smoke check
- if the profile is already ready, continue into the minimal `browse` validation

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

Using npx clawhub without a pinned version allows execution of whatever package version is currently published or resolved at runtime. This creates a supply-chain risk where a compromised publisher account, malicious update, or dependency confusion event could cause arbitrary code execution on the operator's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The fallback command executes npx @qybaihe/clawdate-agent-cli without version pinning, so the binary fetched at runtime may change over time. In a workflow that handles tokens, contact data, local files, and cron persistence, an untrusted package update could directly compromise sensitive operator and owner data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This second unpinned npx @qybaihe/clawdate-agent-cli reference repeats the same supply-chain exposure in another execution path. Multiple unpinned invocation points make the risk more likely to be triggered during normal operator use.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The manual install path also uses the same unpinned package, again permitting arbitrary remote code to be fetched and executed at runtime. Because the skill is an operator runbook, users are likely to follow these commands verbatim, increasing practical exploitability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs operators to collect a specific contact identifier (WeChat ID) and other matching-related personal attributes, but it does not require a clear privacy notice, data minimization statement, or consent step before collection. In practice, operators may store and transmit personal data without the owner understanding retention, exposure, or who can access it.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The runbook tells operators to export and submit owner profile JSON files to local disk, and elsewhere to append logs, but it does not prominently warn that these files may contain sensitive personal data and internal assessments. This can lead to insecure storage, accidental sharing, over-retention, or exposure through backups and multi-user systems.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The skill explicitly installs a recurring cron job, which is a persistence mechanism. While persistence is operationally intended here, it still creates a lasting execution foothold that can continue running unattended and could be abused if the wrapper script, environment, or package dependencies are later compromised.

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

bash
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The verification step confirms persistence was successfully written to crontab, reinforcing that the skill's changes survive beyond the current session. In an environment where the underlying CLI or wrapper is compromised, this persistence magnifies long-term impact and makes cleanup less obvious.

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

bash
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Always verify the entry was written.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This line installs a persistent cron job that executes a shell script every 5 minutes. Even if intended for legitimate synchronization, persistence mechanisms are security-relevant because they repeatedly launch code in the user's context and can be abused if the target script path or its contents are modified.

Content

Scanner excerpt · assets/cron.example.txt (reported line 2)May include surrounding context.

text
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · assets/cron.example.txt (reported line 3)May include surrounding context.

text
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/init_owner.sh (reported line 185)May include surrounding context.

sh
CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"'
( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab -
crontab -l | grep -F "__PROFILE__-sync.sh"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template strings instruct the writer in Chinese (for example, how to fill publicSummary and lobsterEvaluation), which imposes a specific language/locale on the skill content. There is no indication that users can choose another language or that the Chinese-only constraint is required for a region-specific use case.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer accepts an arbitrary HTTP(S) SOURCE and downloads multiple skill files directly into the active skill directory without any origin restriction, integrity verification, or trust prompt. That makes the installer capable of replacing the skill content with attacker-controlled files, which exceeds a simple local SOP installer and creates a supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Remote download and file copy operations overwrite files under $SKILL_ROOT with no confirmation, dry-run, backup, or warning. Combined with the arbitrary SOURCE parameter, this can silently replace trusted local skill files with unexpected content and leave the user unaware of the change.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 35)May include surrounding context.

sh
rm -f "$SKILL_ROOT/scripts/cleanup_owner.sh"

chmod 0644 "$SKILL_ROOT/SKILL.md" \
  "$SKILL_ROOT/agents/openai.yaml" \
  "$SKILL_ROOT/assets/owner-profile.template.json" \
  "$SKILL_ROOT/assets/profile-sync.sh.template" \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 40)May include surrounding context.

sh
"$SKILL_ROOT/assets/owner-profile.template.json" \
  "$SKILL_ROOT/assets/profile-sync.sh.template" \
  "$SKILL_ROOT/assets/cron.example.txt"
chmod 0755 "$SKILL_ROOT/scripts/init_owner.sh"

echo "Installed clawdate skill into $SKILL_ROOT"
echo "If the current lobster session does not see the skill yet, refresh or reopen the workspace."

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/init_owner.sh (reported line 168)May include surrounding context.

sh
"$SKILL_ROOT/assets/owner-profile.template.json" \
  "$SKILL_ROOT/assets/profile-sync.sh.template" \
  "$SKILL_ROOT/assets/cron.example.txt"
chmod 0755 "$SKILL_ROOT/scripts/init_owner.sh"

echo "Installed clawdate skill into $SKILL_ROOT"
echo "If the current lobster session does not see the skill yet, refresh or reopen the workspace."

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The script falls back to executing an unpinned npm package via npx, which allows whatever version is current at execution time to run with the user's privileges. In this skill, that package performs install/sync/profile actions and is then used to bootstrap persistence, so a compromised or malicious upstream release could directly execute arbitrary code and steal local profile data or credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.