Back to skill

Security audit

AI Content Collector

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent news-collection and spreadsheet-reporting workflow, with notable but disclosed risks around optional unpinned tool installation.

This skill is reasonable to install for Chinese-language AI and automotive news reporting. Be cautious with the optional enhancement commands: only run unpinned `npx clawhub@latest` installs after verifying the packages, and expect the skill to create a local report file in the working directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:741
Finding

Unpinned Third-Party CLI Execution and Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 741–757
Vulnerability Type: Supply-chain risk through mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
## Optional Enhancement Skill Installation Guide

The following Skills are not required, but installing them can significantly improve search and fetching capabilities:

### multi-search-engine

```bash
npx clawhub@latest install multi-search-engine

xcrawl-search + xcrawl-scrape

bash
npx clawhub@latest install xcrawl-search
npx clawhub@latest install xcrawl-scrape
text

### Technical Analysis

The installation instructions invoke `npx clawhub@latest`, which downloads and executes the version currently published under that package name. Neither the CLI version nor its integrity is pinned. The CLI subsequently installs additional third-party Skills whose versions, contents, publishers, and integrity are also not constrained by the audited project.

This creates a mutable remote execution chain: the code executed when a user follows the instructions can differ from the code available when the Skill was reviewed. A registry compromise, malicious package update, dependency confusion event, or compromise of one of the installed Skills could therefore introduce arbitrary code into the Agent environment.

These enhancements are optional and relevant to the declared search functionality, but executing mutable third-party packages is not necessary for the core workflow, which already declares `WebSearch` and `WebFetch`. The recommendation consequently exceeds the minimum dependencies needed for basic operation.

### Attack Path

1. An attacker compromises the `clawhub` registry package, its publisher account, its dependency chain, or one of the named third-party Skills.
2. The attacker publishes a malicious release or modifies the payload delivered under the mutable `latest` tag.
3. A user follows the installation guide and runs `npx clawhub@latest 
...[truncated 967 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a reviewed exact version instead of using @latest.
  2. Pin every installed Skill to an immutable version, release digest, or commit.
  3. Verify package publishers, signatures, checksums, and provenance before installation.
  4. Maintain an allowlist of reviewed Skills and trusted registries.
  5. Inspect downloaded package contents and dependency lockfiles before activation.
  6. Run installation and third-party Skills in a sandbox with restricted filesystem, network, process, and secret access.
  7. Do not expose API keys to optional Skills unless explicitly required; use scoped, revocable credentials.
  8. Separate installation from normal Skill execution and require informed user approval.
  9. Document reviewed versions and establish a controlled update process that includes security re-audit.
  10. Prefer the already declared WebSearch and WebFetch tools where they satisfy the task, avoiding optional package execution entirely.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L003 的触发条件包含“扫描行业信息”“整理资料到Excel”“信息周报/日报”等宽泛表述,这些短语可与很多普通办公请求重叠,未清楚限定必须是本技能所针对的 AI/汽车行业新闻收集场景。描述中也没有给出负例或排除条件来说明哪些相似请求不应触发该技能。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L084-L090 明确规定“禁止回退到纯英文来源”且“最终报告中,中文来源占比必须 ≥60%”,后文多处也强制 language: "zh" 与“绝不放弃中文来源”。这构成了固定语言/地区策略,但文档未说明这是面向特定中文用户群的限定,也未提供用户选择其他语言或来源偏好的机制。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Lines L111-L116 state that if openpyxl is missing, the skill must print a missing-dependency message and stop. But later, L641-L651 explicitly documents a fallback path that generates CSV when openpyxl is not installed, which is a direct contradiction in the documented operational intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L294-L295 and repeated statements such as L780 say Excel generation is mandatory and cannot be skipped. However, L641-L651 documents generating a CSV instead when openpyxl is unavailable, which conflicts with the stated requirement that the skill must complete Excel output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill recommends executing npx clawhub@latest install ..., which pulls and runs the latest package code at execution time without pinning an exact version or integrity. That creates a supply-chain risk: a compromised publisher account, malicious update, or breaking change could cause arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This line instructs the user/agent to run npx clawhub@latest install xcrawl-search, which executes unpinned remote package code. Because npx fetches packages dynamically, this exposes the environment to supply-chain compromise and unexpected behavior changes over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command repeats the same unpinned npx ... @latest pattern for xcrawl-scrape, again allowing execution of whatever code is current in the registry at runtime. In an agent skill context, such guidance is especially risky because users may follow it verbatim, expanding the attack surface beyond the core skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document mandates use of Chinese authoritative sources as primary references, including a dedicated section labeled '必须使用' and a prioritized list of Chinese media outlets. This is a natural-language locale constraint that does not provide user opt-in or an alternative based on the user's preferred language or region.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

L555-L651 明确要求生成 Excel 文件,并在降级情况下写出 CSV 文件,属于文件写入操作。虽然这是技能目标的一部分,但文档没有显式提醒用户会在本地工作目录创建文件、文件名格式为何,以及可能覆盖或新增输出产物。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.