Back to skill

Security audit

skillscope

Security checks for vulnerabilities and agentic risk

Overview

This skill is a skill-finder, but it can send broad user task details to a third-party service and relay remote install commands without enough user control.

Review this skill before installing. Use it only when you intentionally want third-party skill recommendations, avoid sending confidential project details or secrets in task descriptions, and independently verify any returned install command, publisher, version, and source before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Untrusted Remote Installation Commands Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-17 and SKILL.md:60-69
Vulnerability Type: Unvalidated third-party installation instructions
Risk Level: Medium

Vulnerable Code Snippet:

markdown
1. User describes a task → call **recommend** → get best skill + alternatives with reasons
2. User wants to install → provide the `install` command from the response
3. User wants details → call **detail** for full analysis
markdown
## Install

Users can install skills via:
- `clawhub install <slug>` (official ClawHub CLI)
- `skillscope install <slug>` (China mirror, `pip install skillscope`)

To get installable files via API:

```bash
curl "https://skillscope.cn/api/v1/install/weather/files"
text

### Technical Analysis

The skill instructs the agent to provide an installation command received from an external recommendation service. It does not require the command, package identifier, resolved repository, publisher, arguments, version, signature, or checksum to be validated before presenting the command to the user.

This creates an insecure dependency and supply-chain trust boundary. The effective package selected for installation can change independently of the reviewed `SKILL.md` file. A compromised API, poisoned catalog record, malicious publisher, package-name collision, or dependency takeover could cause a recommendation to resolve to attacker-controlled content.

The additional instruction to use `pip install skillscope` is unpinned and does not specify an integrity hash. Consequently, the installed artifact depends on the package registry's current resolution state rather than a version reviewed with this skill.

### Attack Path

1. An attacker compromises the external recommendation service, poisons a catalog entry, takes over a listed package, or publishes a deceptively named dependency.
2. A user asks the agent to find a skill for a supported task.
3. The 
...[truncated 1247 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not accept or relay arbitrary command strings from the remote API. Require the API to return structured identifiers such as package name, registry, publisher, repository URL, version, and integrity digest.
  2. Construct installation commands locally from validated fields using a strict allowlist of supported installers and arguments.
  3. Resolve each recommendation to its canonical source and show the user the publisher, repository, requested permissions, version, and security-review status.
  4. Pin packages and skills to reviewed versions or immutable commit identifiers.
  5. Verify cryptographic signatures or trusted checksums before installation.
  6. Detect package-name collisions, typosquatting, unexpected publisher changes, and repository ownership transfers.
  7. Require explicit user confirmation after displaying the exact source and security implications.
  8. Install third-party skills in a sandbox with least privilege and restricted filesystem, credential, and network access.
  9. Replace the unpinned pip install skillscope instruction with a verified, version-pinned installation procedure using hashes.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

User Task Content and Environment Context May Be Disclosed to an External Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-49
Vulnerability Type: Unprotected transmission of potentially sensitive user input
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Recommend (Primary Tool)

**When to use**: User asks "find me a skill for X", "is there a tool that can Y", "what's the best skill for Z", or describes any task that a skill could help with.

```bash
curl -X POST "https://skillscope.cn/api/v1/recommend" \
  -H "Content-Type: application/json" \
  -d '{"task": "translate a PDF document to Chinese", "explain": true}'

With context for better results:

bash
curl -X POST "https://skillscope.cn/api/v1/recommend" \
  -H "Content-Type: application/json" \
  -d '{
    "task": "translate a PDF document to Chinese",
    "context": {"platform": "macos", "region": "cn", "budget": "free"},
    "explain": true
  }'

Parameters:

  • task (required): natural language task description
  • context.platform: macos / linux / windows
  • context.region: cn / us (auto-inferred if omitted)
  • context.budget: free / paid / any (default any)
  • context.skill_level: beginner / intermediate / advanced
text

### Technical Analysis

The workflow sends the user's natural-language task to `https://skillscope.cn/api/v1/recommend` and may include platform, region, budget, and skill-level metadata. User task descriptions can contain confidential project names, proprietary requirements, personal information, internal URLs, filenames, customer information, credentials, or other secrets.

Although HTTPS protects the request in transit, the external service receives the plaintext request at the application layer. The skill provides no instruction to obtain informed consent, remove sensitive content, minimize metadata, detect secrets, or explain retention and downstream processing. It also states that region may be inferred when omitted,
...[truncated 1333 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user consent before sending task content or contextual metadata to the external service.
  2. Clearly identify the destination, transmitted fields, purpose, and applicable retention or privacy policy before making the request.
  3. Add mandatory redaction rules for credentials, API keys, tokens, personal data, internal URLs, customer information, file contents, and proprietary identifiers.
  4. Minimize requests to the least amount of information necessary. Do not send platform, region, budget, or skill level unless required and explicitly approved.
  5. Do not automatically infer or transmit regional information without notice and consent.
  6. Implement secret and sensitive-data detection before transmission, blocking the request when high-risk data is detected.
  7. Provide a local or manual search alternative for users who do not consent to external processing.
  8. Document retention, deletion, logging, subprocessors, data residency, and incident-response practices for the external service.
  9. Ensure request logs do not retain full task text unless strictly necessary, and apply encryption, access controls, and short retention periods.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill hardcodes China-hosted infrastructure and states region auto-inference/default behavior without meaningful user opt-in. This creates data-governance and privacy risk, because user task descriptions and context may be transmitted cross-border or to an unexpected jurisdiction based on implicit defaults rather than informed choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance is extremely broad, effectively applying whenever a user describes almost any task that might be solved by a skill. In an agent setting, this can cause over-invocation and unnecessary routing of user prompts to an external recommendation service, increasing privacy exposure and the chance of unneeded third-party influence on decisions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill instructs the agent to send natural-language task descriptions and optional context to an external API endpoint. Because the trigger is broad and the transmitted fields can contain sensitive user intent, environment, or budget information, this creates a real external data exfiltration path to a third-party service without any stated minimization, consent, or sanitization controls.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

When to use: User asks "find me a skill for X", "is there a tool that can Y", "what's the best skill for Z", or describes any task that a skill could help with.

bash
curl -X POST "https://skillscope.cn/api/v1/recommend" \
  -H "Content-Type: application/json" \
  -d '{"task": "translate a PDF document to Chinese", "explain": true}'

Static analysis

No suspicious patterns detected.