T09 · Insecure Skill Coding Practices
- Location
scripts/publish.sh:138- Finding
Shell Command Injection Through eval in the Publishing Workflow
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says, but its publishing workflow has unsafe escape hatches and a command-injection risk that could run unintended local commands.
Install only if you are comfortable reviewing the shell scripts and running publishing commands manually. Avoid --skip-checks and --force, review the entire skill folder for secrets before publishing, and treat the security scan as advisory rather than authoritative until the eval-based publish command and scanner bypasses are fixed.
scripts/publish.sh:138Shell Command Injection Through eval in the Publishing Workflow
scripts/security-scan.sh:41Security Scan Can Be Bypassed Using Trusted Script Basenames
scripts/security-scan.sh:48External Network Detection Can Be Bypassed Through Substring-Based Host Allowlisting
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
bash {baseDir}/scripts/scaffold.sh my-skill && \
# edit skills/my-skill/SKILL.md ... && \
bash {baseDir}/scripts/validate.sh skills/my-skill && \
bash {baseDir}/scripts/security-scan.sh skills/my-skill && \
bash {baseDir}/scripts/publish.sh skills/my-skill --slug my-skill --version 1.0.0
Documenting a --skip-checks option exposes a supported path to bypass validation and security scanning before publication. In a skill-publishing context, this materially weakens trust controls and makes it easier for unsafe or malicious skills to be distributed, even if the feature was added for convenience.
echo " --slug <name> Skill slug (required)"
echo " --version <x.y.z> Version number (required)"
echo " --changelog <text> Changelog message (optional)"
echo " --skip-checks Skip validation and security scan"
echo " --force Force publish even with warnings"
echo ""
echo "Example:"
The argument parser enables --skip-checks, allowing a caller to disable both validation and security scanning before a publish. Because this script's core purpose is to create and distribute agent skills, bypassing those controls directly increases the chance of publishing harmful content and undermines the intended safety gate.
CHANGELOG="$2"
shift 2
;;
--skip-checks)
SKIP_CHECKS=true
shift
;;
The validation failure path explicitly suggests using --skip-checks to bypass safeguards, normalizing unsafe behavior when controls detect a problem. In this context, that guidance makes operator override more likely and weakens the protective value of the checks.
if ! bash "$SCRIPT_DIR/validate.sh" "$SKILL_DIR"; then
echo ""
echo "❌ Validation failed. Fix errors and try again."
echo " Or use --skip-checks to bypass (not recommended)"
exit 1
fi
echo ""
The skill invokes shell scripts for scaffolding, validation, scanning, and publishing, but it does not declare any tool scope such as permissions or allowed-tools. That omission weakens containment and review because consumers cannot see upfront that shell execution is required, increasing the chance of unintended command execution in environments that auto-enable skills.
The trigger phrases are broad and include common requests like 'make a skill' or 'package this as a skill,' which may cause the skill to activate in contexts where the user did not intend publishing or shell-backed automation. Because this skill performs file creation and can lead to external publication, accidental activation increases the risk of unintended actions.
The publish step states that it pushes to ClawHub but does not clearly warn that local skill artifacts and metadata will be transmitted to an external service. Without an explicit disclosure and confirmation step, users may unintentionally upload sensitive content, proprietary code, or secrets included in the skill folder.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
bash {baseDir}/scripts/scaffold.sh my-skill && \
# edit skills/my-skill/SKILL.md ... && \
bash {baseDir}/scripts/validate.sh skills/my-skill && \
bash {baseDir}/scripts/security-scan.sh skills/my-skill && \
bash {baseDir}/scripts/publish.sh skills/my-skill --slug my-skill --version 1.0.0
This shell script ultimately executes clawhub publish, which performs a publish action to an external service and can affect remote state. Although the script prints the command and some status messages, it does not require any explicit user confirmation immediately before the irreversible publish step.
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
# 6. File permissions - check for setuid/setgid (4xxx, 2xxx) which are dangerous
while IFS= read -r file; do
PERMS=$(stat -c %a "$file" 2>/dev/null || stat -f %OLp "$file" 2>/dev/null || echo "")
# Only flag setuid (4xxx), setgid (2xxx), or world-writable (xx7)
if [[ "$PERMS" =~ ^[42] ]] || [[ "$PERMS" =~ [0-7][0-7]7$ ]]; then
WARNINGS+=("Dangerous permissions on $(basename "$file"): $PERMS")
fi
The template leaves the skill activation description as a generic TODO, so downstream authors may publish skills without clear trigger boundaries. In an agent ecosystem, vague or overly broad activation text can cause accidental invocation in unrelated contexts, increasing the chance that powerful publishing or packaging actions run when not intended.
No suspicious patterns detected.