Back to skill

Security audit

Turn quotes and reflections from books or films into polished shareable check-in posters.

Security checks for vulnerabilities and agentic risk

Overview

This skill is an instruction-only poster generator that uses Mew APIs, with expected API-key and image-sharing privacy considerations.

Install only if you are comfortable sharing a revocable mew.design API key in the conversation and sending selected quotes, image URLs, or explicitly approved uploaded images to external services for poster generation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The install intent examples include generic phrases like 'Help me install this ClawHub skill' and 'Install this skill and then use it', which can overlap with ordinary conversation and cause unintended installation or activation. In a skill ecosystem, ambiguous triggers increase the chance of the agent treating unrelated user requests as consent to install or run external-action-capable functionality.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:257