Back to skill

Security audit

Code Url Cleaner

Security checks for vulnerabilities and agentic risk

Overview

This skill is not evidently malicious, but it automatically rewrites every agent response and can change commands, URLs, and code before you see them.

Review carefully before installing. This skill should only be enabled if you are comfortable with a session-wide output filter that may rewrite commands, code snippets, paths, and URLs before display. Prefer an opt-in version with a disable switch, scoped transformations, and a way to compare original versus cleaned output; use a pinned installer version where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
cleaner.py:64
Finding

Automatic Global Output Hook Can Silently Corrupt Agent Responses

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:67
Finding

Installation Instructions Execute an Unpinned Mutable npm Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
| `SKILL.md` | `SKILL.md` | This documentation | 本文档 |

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx clawhub@latest install ..., which fetches and executes the latest package code rather than a pinned, reviewed version. This creates a supply-chain risk: if the upstream package is compromised or changed unexpectedly, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that all agent output is automatically cleaned after install, but does not prominently warn that displayed commands, paths, and URLs may be altered before the user sees them. Silent output rewriting is security-relevant because it can change operational instructions or links in ways that obscure the original model output and reduce user ability to validate content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This section documents an auto-registered hook that intercepts all agent output on load and modifies it, yet provides no safety warning, consent step, or limitation on scope. An on-load global hook is more dangerous than a manual utility because it affects every response transparently, potentially rewriting security-sensitive commands, filesystem paths, or repository URLs without visibility.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The documented design auto-executes hook registration on import, meaning merely loading the module changes runtime behavior without an explicit user action. Autonomous activation increases the chance of unexpected or unauthorized behavior and makes the skill context more dangerous because it modifies agent output globally rather than acting as a user-invoked helper.

Content

Scanner excerpt · README.md (reported line 158)May include surrounding context.

Code Example | 代码示例

python
# In cleaner.py - Auto-executed on import | 导入时自动执行
def _auto_register_hook():
    from openclaw import get_current_agent
    agent = get_current_agent()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic hook registration that modifies all agent output on load, but does not provide a strong warning about the full scope and security implications of intercepting every response. This is dangerous because global output rewriting can silently alter commands, code, URLs, or security-relevant text, reducing user visibility and potentially enabling deceptive or unsafe behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The installation command uses npx clawhub@latest, which fetches and executes the latest remote package without pinning to a specific version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious update is published, users may unknowingly install and run untrusted code.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The documented implementation auto-executes code on import and immediately registers a lifecycle hook against the current agent. Import-time side effects are risky because merely loading the skill causes autonomous behavior changes without user approval, and in this case the hook gains control over all outgoing agent output.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

Code | 代码

python
# cleaner.py - Auto-executed on import | 导入时自动执行
def _auto_register_hook():
    from openclaw import get_current_agent
    agent = get_current_agent()

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module is presented as a harmless text-cleaning utility, but importing it triggers hidden global behavior by registering a before_output hook. That mismatch is dangerous because users or downstream systems may load the skill expecting a pure helper while it silently alters all agent output, creating an integrity and transparency problem.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The module description states in Chinese that it automatically checks and cleans spaces in code and URLs, and the file predominantly presents behavior/documentation in Chinese without offering a language choice. Per the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically registering an output-modifying hook on import creates an undisclosed side effect that changes agent behavior globally without user consent. In a skill ecosystem, this can be exploited to tamper with responses, hide content changes, or introduce subtle output corruption that is difficult to trace back to the imported module.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

In the exception path, the comment says 'will auto-register when loaded', implying deferred successful registration. The actual behavior is only to return False, with no deferred registration mechanism beyond the current import attempt, so the comment materially misstates what the code does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.