Back to skill

Security audit

Clawdhub

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent ClawdHub CLI helper, but it documents broad install, forced update, and publish operations without enough guardrails for changing agent skills or uploading local content.

Review commands before running them. Prefer pinned CLI and skill versions, avoid `--all --no-input --force` unless you have inspected the changes and can roll back, confirm the registry is trusted, and publish only directories you have checked for secrets or private files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned CLI Installation and Unverified Remote Skill Updates

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:3, SKILL.md:9-12, SKILL.md:24-34, and SKILL.md:49-53
Vulnerability Type: Supply-chain exposure through unpinned dependencies and unverified remote content
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:3:

yaml
description: Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.

SKILL.md:9-12:

markdown
Install
```bash
npm i -g clawdhub
text

`SKILL.md:24-34`:

```markdown
Install
```bash
clawdhub install my-skill
clawdhub install my-skill --version 1.2.3

Update (hash-based match + upgrade)

bash
clawdhub update my-skill
clawdhub update my-skill --version 1.2.3
clawdhub update --all
clawdhub update my-skill --force
clawdhub update --all --no-input --force
text

`SKILL.md:49-53`:

```markdown
Notes
- Default registry: https://clawdhub.com (override with CLAWDHUB_REGISTRY or --registry)
- Default workdir: cwd; install dir: ./skills (override with --workdir / --dir)
- Update command hashes local files, resolves matching version, and upgrades to latest unless --version is set

Technical Analysis

The documented installation command retrieves the latest available clawdhub npm package and installs it globally without pinning an exact version or integrity digest. Consequently, the code installed at execution time can differ from the package version that was previously reviewed.

The CLI is then instructed to install or update Agent Skills from a remote registry. Several examples omit a version, while update --all --no-input --force permits unattended replacement of local content. Although the documentation states that local files are hashed to identify their ...[truncated 2372 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to an explicitly reviewed version, for example clawdhub@X.Y.Z, and update it only through a controlled dependency-review process.
  2. Record and verify npm lockfile integrity metadata or an independently trusted checksum before installation.
  3. Prefer a project-local installation over a global installation to reduce cross-project exposure and avoid unnecessary elevated privileges.
  4. Pin installed Skills to reviewed versions and verify signed manifests, artifact signatures, or trusted checksums before activation.
  5. Restrict registries to an allowlist of approved HTTPS endpoints. Reject unexpected CLAWDHUB_REGISTRY values and untrusted --registry arguments.
  6. Validate publisher identity and package provenance, including npm provenance attestations where available.
  7. Avoid unattended forced updates such as update --all --no-input --force in production or trusted agent environments.
  8. Download updates into a staging directory, inspect file changes, scan scripts and instructions, and require explicit approval before replacing active Skills.
  9. Execute the CLI and downloaded Skills with least privilege in an isolated environment that does not expose unrelated credentials or sensitive files.
  10. Document rollback procedures and retain the hashes and versions of previously approved artifacts.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill explicitly documents forceful update operations (including --all --no-input --force) and publishing local directories without any warning that these actions can overwrite installed skills or upload local content to a remote registry. In a skill-execution context, this increases the chance of unintended destructive changes or accidental data disclosure, especially if an agent or user invokes the commands without understanding their side effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.