Back to skill

Security audit

Skill Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its publishing workflow has unsafe escape hatches and a command-injection risk that could run unintended local commands.

Install only if you are comfortable reviewing the shell scripts and running publishing commands manually. Avoid --skip-checks and --force, review the entire skill folder for secrets before publishing, and treat the security scan as advisory rather than authoritative until the eval-based publish command and scanner bypasses are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/publish.sh:138
Finding

Shell Command Injection Through eval in the Publishing Workflow

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security-scan.sh:41
Finding

Security Scan Can Be Bypassed Using Trusted Script Basenames

Content
View full analysis
/dev/null; then WARNINGS+=("Potential code execution in: $(basename "$file") - review eval/exec usage") fi done ``` ```bash # 4. Environment variable harvesting (beyond reasonable scope) for file in $ALL_FILES; do [[ "$(basename "$file")" =~ ^(security-scan|publish|validate|scaffold)\.sh$ ]] && continue ENV_HARVEST=$(grep -oE '\$\{?[A-Z_]+\}?' "$file" 2>/dev/null | sort -u | wc -l) if [[ $ENV_HARVEST -gt 10 ]]; then WARNINGS+=("Many env vars accessed in $(basename "$file") ($ENV_HARVEST) - verify necessity") fi # Specific dangerous env vars if grep -l -E "(AWS_SECRET|PRIVATE_KEY|PASSWORD|TOKEN.*=)" "$file" 2>/dev/null; then WARNINGS+=("Sensitive env var pattern in $(basename "$file") - review carefully") fi done ``` ```bash # 5. Base64 encoded payloads for file in $ALL_FILES; do [[ "$(basename "$file")" =~ ^(security-scan|publish|validate|scaffold)\.sh$ ]] && continue if grep -l -E "base64.*-d|atob\(|decode\('base64'\)" "$file" 2>/dev/null; then WARNINGS+=("Base64 decoding in $(basename "$file") - check for hidden payloads") fi done ``` ### Technical Analysis The scanner excludes files according to their basename rather than verifying that they are the audit tool's own trusted files. Any file in the Skill being scanned whose basename is one of the following is skipped by several checks: - `security-scan.sh` - `publish.sh` - `validate.sh` - `scaffold.sh` The scanned dire ...[truncated 1754 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security-scan.sh:48
Finding

External Network Detection Can Be Bypassed Through Substring-Based Host Allowlisting

Content
View full analysis
/dev/null | grep -vE "$SAFE_HOSTS" || true) if [[ -n "$SUSPICIOUS_URLS" ]]; then RED_FLAGS+=("External network call in $(basename "$file"): $SUSPICIOUS_URLS") fi done ``` ### Technical Analysis The scanner identifies network-command text and then removes matches containing any textual occurrence of an allowlisted domain. It does not parse the URL and compare its hostname against an exact allowlist. Consequently, an attacker-controlled hostname containing an allowlisted domain as a substring may be treated as safe even when it is unrelated to that domain. The allowlist entries are also regular expressions in which dots are not escaped, further weakening matching precision. This is a scanner bypass rather than direct data exfiltration by `security-scan.sh`. The scanner itself performs local text matching and does not send scanned files or sensitive values over the network. ### Attack Path 1. An attacker adds a `curl` or `wget` command to a Skill file. 2. The command targets an attacker-controlled hostname crafted to contain an allowlisted domain string. 3. The first `grep` extracts the network command. 4. `grep -vE "$SAFE_HOSTS"` removes the command because the text contains an allowlisted substring. 5. `SUSPICIOUS_URLS` becomes empty and no red flag is generated. 6. The Skill may be published or approved despite containing an external network destination. 7. If the Skill is later executed, the command may transmit information to or retrieve content from the attacker-controlled h ...[truncated 497 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

bash
bash {baseDir}/scripts/scaffold.sh my-skill && \
  # edit skills/my-skill/SKILL.md ... && \
  bash {baseDir}/scripts/validate.sh skills/my-skill && \
  bash {baseDir}/scripts/security-scan.sh skills/my-skill && \
  bash {baseDir}/scripts/publish.sh skills/my-skill --slug my-skill --version 1.0.0

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

Documenting a --skip-checks option exposes a supported path to bypass validation and security scanning before publication. In a skill-publishing context, this materially weakens trust controls and makes it easier for unsafe or malicious skills to be distributed, even if the feature was added for convenience.

Content

Scanner excerpt · scripts/publish.sh (reported line 18)May include surrounding context.

sh
echo "  --slug <name>        Skill slug (required)"
  echo "  --version <x.y.z>    Version number (required)"
  echo "  --changelog <text>   Changelog message (optional)"
  echo "  --skip-checks        Skip validation and security scan"
  echo "  --force              Force publish even with warnings"
  echo ""
  echo "Example:"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The argument parser enables --skip-checks, allowing a caller to disable both validation and security scanning before a publish. Because this script's core purpose is to create and distribute agent skills, bypassing those controls directly increases the chance of publishing harmful content and undermines the intended safety gate.

Content

Scanner excerpt · scripts/publish.sh (reported line 48)May include surrounding context.

sh
CHANGELOG="$2"
      shift 2
      ;;
    --skip-checks)
      SKIP_CHECKS=true
      shift
      ;;

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The validation failure path explicitly suggests using --skip-checks to bypass safeguards, normalizing unsafe behavior when controls detect a problem. In this context, that guidance makes operator override more likely and weakens the protective value of the checks.

Content

Scanner excerpt · scripts/publish.sh (reported line 106)May include surrounding context.

sh
if ! bash "$SCRIPT_DIR/validate.sh" "$SKILL_DIR"; then
    echo ""
    echo "❌ Validation failed. Fix errors and try again."
    echo "   Or use --skip-checks to bypass (not recommended)"
    exit 1
  fi
  echo ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes shell scripts for scaffolding, validation, scanning, and publishing, but it does not declare any tool scope such as permissions or allowed-tools. That omission weakens containment and review because consumers cannot see upfront that shell execution is required, increasing the chance of unintended command execution in environments that auto-enable skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad and include common requests like 'make a skill' or 'package this as a skill,' which may cause the skill to activate in contexts where the user did not intend publishing or shell-backed automation. Because this skill performs file creation and can lead to external publication, accidental activation increases the risk of unintended actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The publish step states that it pushes to ClawHub but does not clearly warn that local skill artifacts and metadata will be transmitted to an external service. Without an explicit disclosure and confirmation step, users may unintentionally upload sensitive content, proprietary code, or secrets included in the skill folder.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

bash
bash {baseDir}/scripts/scaffold.sh my-skill && \
  # edit skills/my-skill/SKILL.md ... && \
  bash {baseDir}/scripts/validate.sh skills/my-skill && \
  bash {baseDir}/scripts/security-scan.sh skills/my-skill && \
  bash {baseDir}/scripts/publish.sh skills/my-skill --slug my-skill --version 1.0.0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script ultimately executes clawhub publish, which performs a publish action to an external service and can affect remote state. Although the script prints the command and some status messages, it does not require any explicit user confirmation immediately before the irreversible publish step.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/security-scan.sh (reported line 91)May include surrounding context.

sh
# 6. File permissions - check for setuid/setgid (4xxx, 2xxx) which are dangerous
while IFS= read -r file; do
  PERMS=$(stat -c %a "$file" 2>/dev/null || stat -f %OLp "$file" 2>/dev/null || echo "")
  # Only flag setuid (4xxx), setgid (2xxx), or world-writable (xx7)
  if [[ "$PERMS" =~ ^[42] ]] || [[ "$PERMS" =~ [0-7][0-7]7$ ]]; then
    WARNINGS+=("Dangerous permissions on $(basename "$file"): $PERMS")
  fi

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template leaves the skill activation description as a generic TODO, so downstream authors may publish skills without clear trigger boundaries. In an agent ecosystem, vague or overly broad activation text can cause accidental invocation in unrelated contexts, increasing the chance that powerful publishing or packaging actions run when not intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.