Back to skill

Security audit

Clawsec Feed

Security checks for vulnerabilities and agentic risk

Overview

This security-feed skill is mostly purpose-aligned, but its main install and feed workflows trust mutable remote content in ways that could affect future agent behavior.

Install only if you trust the Prompt Security GitHub release process and are willing to review the deployment commands manually. Prefer the signed manifest verification section with a pinned version before installing, avoid automatic latest-release installs, keep CLAWSEC_FEED_URL on a trusted HTTPS source, and require explicit user approval before applying any remediation suggested by feed content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:208
Finding

Deployment workflow relies on an unsigned remote checksum manifest

Content
View full analysis
/dev/null 2>&1; then echo "ERROR: Invalid checksums.json structure" exit 1 fi echo "Attempting .skill artifact installation..." if curl -sSL --fail --show-error --retry 3 --retry-delay 1 \ "$BASE_URL/clawsec-feed.skill" -o "$TEMP_DIR/clawsec-feed.skill" 2>/dev/null; then ``` The downloaded manifest is then used as the trust source for extracted files: ```bash for file in $(jq -r '.files | keys[]' "$TEMP_DIR/checksums.json"); do EXPECTED=$(jq -r --arg f "$file" '.files[$f].sha256' "$TEMP_DIR/checksums.json") FILE_PATH=$(jq -r --arg f "$file" '.files[$f].path' "$TEMP_DIR/checksums.json") # Try nested path first, then flat filename if [ -f "$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH" ]; then ACTUAL=$(shasum -a 256 "$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH" | cut -d' ' -f1) elif [ -f "$TEMP_DIR/extracted/clawsec-feed/$file" ]; then ACTUAL=$(shasum -a 256 "$TEMP_DIR/extracted/clawsec-feed/$file" | cut -d' ' -f1) else echo " ✗ $file (not found in artifact)" CHECKSUM_FAILED=1 continue fi if [ "$EXPECTED" != "$ACTUAL ...[truncated 3529 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:538
Finding

Advisory feed accepts unauthenticated content from a configurable remote source

Content
View full analysis
/dev/null; then echo "Error: Invalid JSON in feed" exit 1 fi FEED=$(cat "$TEMP_FEED") AFFECTED=$(echo "$FEED" | jq -r '.advisories[].affected[]?' 2>/dev/null | sort -u) if [ $? -ne 0 ]; then echo "Error: Failed to parse affected skills from feed" exit 1 fi ``` Advisory content from the feed is later displayed without authenticity verification: ```bash if echo "$AFFECTED" | grep -qF "$skill"; then echo "WARNING: Installed skill '$skill' has a security advisory!" # Get advisory details for this skill echo "$FEED" | jq --arg s "$skill" '.advisories[] | select(.affected[] | contains($s))' fi ``` ### Technical Analysis The workflow verifies only that the downloaded response is syntactically valid JSON. It does not verify a feed signature, pin a content hash, enforce a strict schema, impose a response-size limit, or constrain `CLAWSEC_FEED_URL` to an approved origin. Consequently, any party controlling the configured URL or upstream feed can supply attacker-controlled advisory titles, descriptions, exploitability rationales, affected-package declarations, and recommended actions. These values are not directly passed to `eval`, a shell, or another execution primitive in the reviewed snippets, so direct remote code execution is not confirmed. Nevertheless, the Skill is intended for an AI agent. Presenting ...[truncated 1998 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
For standalone installs, verify the signed release manifest before trusting `SKILL.md`, `skill.json`, or the archive. The `skill.json` file is the package metad

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the package as a passive advisory feed, but the documented behavior includes installation workflows, file writes, updates, and persistent state handling. That mismatch weakens informed consent and increases the chance an agent or user grants broader capabilities than expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description claims risky code and external dependencies were removed, yet the skill still relies heavily on network downloads and shell tooling such as curl, jq, unzip, and openssl. This is a trust-signaling mismatch that can cause users to underestimate the attack surface and execute the workflow with less scrutiny.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger keywords include generic terms like "advisory," "feed," "package," and "security," which are broad enough to appear in many ordinary requests unrelated to this specific skill. The manifest does not provide narrowing context, explicit invocation constraints, or negative examples to reduce accidental activation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
* Required runtime for standalone installation: `bash`, `curl`, `jq`, `shasum`, `unzip`
* Side effects: standalone install only writes local skill files
* Network behavior: downloads release metadata/artifacts and, if you choose to poll manually, fetches the advisory feed
* Trust model: this package does not itself create cron jobs or submit data externally; automation is delegated to `clawsec-suite` or your own scheduler

**An open source project by [Prompt Security](https://prompt.security)**

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs agents to fetch release metadata and content from external endpoints. Any network-fetching installer path increases supply-chain risk, and the initial SKILL.md retrieval here occurs before artifact verification, so a user may rely on untrusted remote content during bootstrap.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

Agents should review scripts before execution!

bash
LATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \
  jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name')

SKILL_URL="https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md"

Session Persistence

Medium
Category
Rogue Agent
Confidence
82% confidence
Finding

The install flow creates a persistent skill directory under the user's home path, establishing ongoing presence on disk. For a package presented mainly as a feed, this persistence is security-relevant because it enables future agent-triggered use and widens the trust boundary beyond a one-time read.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

Installation steps:

Step 1: Create skill directory and save this file

bash
mkdir -p ~/.skill-platform/skills/clawsec-feed

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The deployment flow pulls release metadata from GitHub to determine the latest tag, then downloads artifacts based on that response. This creates a network dependency and a moving-target install path, increasing supply-chain exposure and making installs less reproducible.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

bash
LATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \
  https://api.github.com/repos/prompt-security/ClawSec/releases | \
  jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name')

BASE_URL="https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
echo "Installing from artifact..."
      mkdir -p "$INSTALL_DIR"
      cp -r "$TEMP_DIR/extracted/clawsec-feed"/* "$INSTALL_DIR/"
      chmod 600 "$INSTALL_DIR/skill.json"
      find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} \;
      echo "SUCCESS: Skill installed from .skill artifact"
      exit 0

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 742)May include surrounding context.

md
echo "Installing from artifact..."
      mkdir -p "$INSTALL_DIR"
      cp -r "$TEMP_DIR/extracted/clawsec-feed"/* "$INSTALL_DIR/"
      chmod 600 "$INSTALL_DIR/skill.json"
      find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} \;
      echo "SUCCESS: Skill installed from .skill artifact"
      exit 0

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 749)May include surrounding context.

md
echo "Installing from artifact..."
      mkdir -p "$INSTALL_DIR"
      cp -r "$TEMP_DIR/extracted/clawsec-feed"/* "$INSTALL_DIR/"
      chmod 600 "$INSTALL_DIR/skill.json"
      find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} \;
      echo "SUCCESS: Skill installed from .skill artifact"
      exit 0

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 760)May include surrounding context.

md
echo "Installing from artifact..."
      mkdir -p "$INSTALL_DIR"
      cp -r "$TEMP_DIR/extracted/clawsec-feed"/* "$INSTALL_DIR/"
      chmod 600 "$INSTALL_DIR/skill.json"
      find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} \;
      echo "SUCCESS: Skill installed from .skill artifact"
      exit 0

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

md
mkdir -p "$INSTALL_DIR"
      cp -r "$TEMP_DIR/extracted/clawsec-feed"/* "$INSTALL_DIR/"
      chmod 600 "$INSTALL_DIR/skill.json"
      find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} \;
      echo "SUCCESS: Skill installed from .skill artifact"
      exit 0
    else

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 364)May include surrounding context.

echo "Installing from individual files..." mkdir -p "$INSTALL_DIR" cp "$TEMP_DIR/downloads"/* "$INSTALL_DIR/" chmod 600 "$INSTALL_DIR/skill.json" find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} ; echo "SUCCESS: Skill installed from individual files"

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 365)May include surrounding context.

mkdir -p "$INSTALL_DIR" cp "$TEMP_DIR/downloads"/* "$INSTALL_DIR/" chmod 600 "$INSTALL_DIR/skill.json" find "$INSTALL_DIR" -type f ! -name "skill.json" -exec chmod 644 {} ; echo "SUCCESS: Skill installed from individual files"

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 501)May include surrounding context.

md
Shared exploitability prioritization guidance is maintained in:

* `wiki/exploitability-scoring.md`
* `skills/clawsec-suite/SKILL.md` ("Quick feed check")

### Get exploitability context for an advisory

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill enumerates directories of installed skills on disk and compares them against advisory data, which exposes local environment inventory beyond what a simple feed reader needs. Even if used for legitimate matching, this expands access to sensitive operational metadata and could be repurposed if the feed or surrounding logic were compromised.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 813)May include surrounding context.

md
CURRENT_VERSION=$(jq -r '.version' "$INSTALL_DIR/skill.json" 2>/dev/null || echo "unknown")
echo "Installed version: $CURRENT_VERSION"

LATEST_URL="https://api.github.com/repos/prompt-security/ClawSec/releases"
LATEST_VERSION=$(curl -sSL --fail --show-error --retry 3 --retry-delay 1 "$LATEST_URL" 2>/dev/null | \
  jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name // empty' | \
  sed 's/clawsec-feed-v//')

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description contains substantial Chinese-language content, including capability descriptions and trigger keywords, while other sections are in English. There is no statement that the skill is Chinese-only, bilingual by choice, or that users can select their preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The installation section presents a Chinese instruction line in an otherwise English document. Because no language preference or bilingual policy is explained, this creates an inconsistent forced-locale experience for some users.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
85% confidence
Finding

The skill instructs downloading a remote SKILL.md directly from GitHub before local verification of release artifacts. Even though later sections discuss verification, this bootstrap step exposes users to untrusted remote script/document content and can normalize executing fetched instructions prematurely.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

jq -r '[.[] | select(.tag_name | startswith("clawsec-feed-v"))][0].tag_name')

SKILL_URL="https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md" curl -sSL --fail --show-error "$SKILL_URL"

text

Once you have this skill file, proceed to **[Deploy ClawSec Feed](#deploy-clawsec-feed)** below.

Static analysis

No suspicious patterns detected.