Back to skill

Security audit

Security Audit Tianjin

Security checks for vulnerabilities and agentic risk

Overview

This security-audit skill is purpose-aligned, but its auto-fix mode can broadly change deployment file permissions without clear scoping or safeguards.

Review before installing. Use read-only audit modes only in the intended Clawdbot environment, preferably as a least-privileged user. Avoid --fix unless you have backups and have reviewed exactly which files under /root/clawd may be changed; it may break services that need group-readable JSON, key, or certificate files. I found no network exfiltration, hidden installer, or persistence mechanism.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/audit.cjs:54
Finding

Unrestricted Recursive Scanning of Sensitive Files Under a Privileged Directory

Content
View full analysis
entry.name.endsWith(ext))) { files.push(fullPath); } } } catch { // Ignore inaccessible directories } } traverse(dir); return files; } ``` ```javascript // Scan key files const keyFiles = [ CONFIG_DIR, path.join(CLAWDBOT_DIR, 'skills/.env'), path.join(CLAWDBOT_DIR, '.env'), path.join(CLAWDBOT_DIR, 'config.json') ]; for (const file of keyFiles) { scanFileForPatterns(file, credentialPatterns, 'CREDENTIALS'); } // Scan all code files const codeFiles = getFilesRecursively(CLAWDBOT_DIR); for (const file of codeFiles) { if (file.includes('node_modules') || file.includes('.git')) continue; scanFileForPatterns(file, credentialPatterns.filter(p => p.level !== 'CRITICAL'), 'CREDENTIALS'); } ``` ### Technical Analysis The audit uses a hardcoded privileged root directory, `/root/clawd`, and recursively enumerates supported file types throughout that directory. The discovered files are subsequently opened and read by `scanFileForPatterns ...[truncated 2106 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.cjs:426
Finding

Auto-Fix Recursively Changes Permissions and Can Follow Symbolic Links

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 14)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 73)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 141)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 142)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 413)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 420)May include surrounding context.

js
// Configuration
const CLAWDBOT_DIR = '/root/clawd';
const CONFIG_DIR = '/root/clawd/skills/.env';
const DOCKER_DIR = '/root/clawd';

// Results collection

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 195)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 197)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 233)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 412)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 424)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.cjs (reported line 459)May include surrounding context.

js
function checkConfigs() {
  log('INFO', 'CONFIGS', 'Validating configuration security...');
  
  // Check for .env file
  if (!checkFileExists(CONFIG_DIR)) {
    log('HIGH', 'CONFIGS', 'No .env file found - credentials may not be configured');
    return;

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · scripts/audit.cjs (reported line 282)May include surrounding context.

js
log('HIGH', 'DOCKER', 'Container may run as root user');
    }
    
    if (dockerContent.includes('--privileged')) {
      log('CRITICAL', 'DOCKER', 'Container has privileged mode enabled');
    }

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
- Open CORS policies

### Files
- World-readable files
- Executable by anyone
- Sensitive files in public dirs

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 233)May include surrounding context.

js
- Open CORS policies

### Files
- World-readable files
- Executable by anyone
- Sensitive files in public dirs

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 234)May include surrounding context.

js
- Open CORS policies

### Files
- World-readable files
- Executable by anyone
- Sensitive files in public dirs

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 235)May include surrounding context.

js
- Open CORS policies

### Files
- World-readable files
- Executable by anyone
- Sensitive files in public dirs

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 236)May include surrounding context.

js
- Open CORS policies

### Files
- World-readable files
- Executable by anyone
- Sensitive files in public dirs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly advertises an auto-fix mode that changes file permissions and configuration state, but it does not warn users that running the command will modify the local system and may have operational side effects. In a security-audit skill, this is more dangerous because users may expect a read-only assessment and invoke it in sensitive environments, leading to unintended permission changes, config drift, or service impact.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · scripts/audit.cjs (reported line 138)May include surrounding context.

js
}
  ];
  
  // Scan key files
  const keyFiles = [
    CONFIG_DIR,
    path.join(CLAWDBOT_DIR, 'skills/.env'),

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 219)May include surrounding context.

js
log('MEDIUM', 'CONFIGS', 'Debug logging enabled - may expose sensitive data');
    }
    
    // Check for CORS
    if (envContent.includes('CORS_ORIGIN=*') || envContent.includes('CORS_ALLOW_ALL=true')) {
      log('HIGH', 'CONFIGS', 'CORS configured to allow all origins');
    }

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 221)May include surrounding context.

js
// Check for CORS
    if (envContent.includes('CORS_ORIGIN=*') || envContent.includes('CORS_ALLOW_ALL=true')) {
      log('HIGH', 'CONFIGS', 'CORS configured to allow all origins');
    }
    
  } catch (e) {

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit.cjs (reported line 246)May include surrounding context.

js
const stats = fs.statSync(file);
      const mode = stats.mode & 0o777;
      
      // Check if world-readable
      if ((mode & 0o004) !== 0) {
        for (const sp of sensitivePatterns) {
          if (sp.pattern.test(file)) {

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/audit.cjs (reported line 279)May include surrounding context.

js
const dockerContent = fs.readFileSync(dockerFile, 'utf8');
    
    if (dockerContent.includes('USER root') || !dockerContent.includes('USER ')) {
      log('HIGH', 'DOCKER', 'Container may run as root user');
    }
    
    if (dockerContent.includes('--privileged')) {

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises comprehensive security auditing with auto-fix, but the implemented auto-fix only tightens file permissions and creates a .gitignore. This mismatch can create a false sense of safety and lead operators to believe exposed credentials, weak configs, or network issues were remediated when they were not.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/audit.cjs:166