Back to skill

Security audit

Deep Research Pro 1.0.2

Security checks for vulnerabilities and agentic risk

Overview

This research skill is mostly coherent, but its workflow tells agents to fetch arbitrary URLs with a shell command and save reports locally without clear user control.

Review before installing if your agent environment has access to private networks, cloud metadata, sensitive local files, or shared storage. Use safer URL-fetching controls, avoid substituting untrusted URLs into shell commands, and consider confirming the save path before writing research reports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:58
Finding

Unsafe Shell Interpolation and Unrestricted Retrieval of Untrusted URLs

Content
View full analysis
" | python3 -c " import sys, re html = sys.stdin.read() # Strip tags, get text text = re.sub('<[^>]+>', ' ', html) text = re.sub(r'\s+', ' ', text).strip() print(text[:5000]) " ``` ### Technical Analysis The Skill instructs the Agent to insert a URL obtained from search results into a shell command. Although the placeholder is enclosed in double quotes, double-quoted shell strings still process command substitutions such as `$()` and backticks. If an untrusted URL is copied verbatim into this template, shell metacharacters within that value could cause commands to run locally with the privileges of the Agent process. The command also invokes `curl` with `-L`, permitting redirects, without restricting destination schemes, resolved addresses, redirect targets, response size, or request duration. An attacker-controlled URL could therefore redirect the request to loopback, private-network, link-local, or cloud metadata services. This can expose resources that are inaccessible to an external attacker but reachable from the Agent's environment. The downloaded response is passed to fixed Python code as standard input and is not itself interpreted as Python or shell code. Therefore, this is not a confirmed remote-payload execution pattern based solely on response content. The risk instead arises from unsafe URL interpolation and unrestricted outbound retrieval. ### Attack Path 1. An attacker supplies a crafted URL directly in a research request or publishes a page that becomes visible in search results. 2. The Agent selects that URL as one of the sources to read. 3. The Agent substitutes the URL verbatim into the documented shell template. 4. A URL containing shell command substitution syntax causes the shell to execute an attack ...[truncated 1520 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill fetches arbitrary URLs from search results with curl and pipes the full response into downstream processing, creating an SSRF-style and untrusted-content retrieval risk. Even though the Python snippet only strips HTML, the dangerous part is the unrestricted network fetch itself: an attacker-controlled URL or redirect could hit internal services, metadata endpoints, or other sensitive network locations accessible from the agent environment.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

For the most promising URLs, fetch full content:

bash
curl -sL "<url>" | python3 -c "
import sys, re
html = sys.stdin.read()
# Strip tags, get text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is effectively designed to trigger on almost any generic request for information or research, which can cause it to activate in situations broader than users may expect. Over-broad activation increases the chance that the agent performs networked research, source collection, and follow-on actions when a simpler non-network response would have been safer or more appropriate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to create directories and save reports to local disk without requiring explicit user consent or a visible notice. This can lead to unexpected persistence of potentially sensitive research topics, accumulation of local artifacts, and privacy or data-handling issues in shared or managed environments.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

text
sessions_spawn(
  task: "Run deep research on [TOPIC]. Follow the deep-research-pro SKILL.md workflow.
  Read /home/clawdbot/clawd/skills/deep-research-pro/SKILL.md first.
  Goal: [user's goal]
  Specific angles: [any specifics]
  Save report to ~/clawd/research/[slug]/report.md

Static analysis

No suspicious patterns detected.