Back to skill

Security audit

Clawhub Skills Rank

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently checks public ClawHub search rankings and does not show hidden persistence, credential access, destructive behavior, or data exfiltration.

Install without elevated privileges, prefer a pinned or already trusted ClawHub CLI when available, and use this skill only for ClawHub ranking checks. Be aware that queried keywords are sent to ClawHub's public search API and verbose terminal output may display remote result text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:28
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md:28-32
Vulnerability Type: Supply-chain risk from unpinned package execution
Risk Level: Medium

Vulnerable Code Snippet:

markdown
### Via ClawHub CLI

```bash
npx clawhub install clawhub-skill-rank
text

### Technical Analysis

The documented installation command invokes the `clawhub` npm package through `npx` without specifying a reviewed version or integrity value. If the package is not already available locally, `npx` may retrieve and execute the version currently resolved by the npm registry.

This makes the executed installer mutable after the Skill itself has been reviewed. The repository does not provide a package version, lockfile, checksum, publisher verification procedure, or other mechanism that binds the installation command to a known artifact.

This finding does not establish that the current `clawhub` package is malicious. It identifies a supply-chain boundary where a compromised package, compromised maintainer account, or unexpectedly changed release could result in arbitrary code execution.

### Attack Path

1. An attacker compromises the npm package, its publisher account, or the relevant package-distribution channel.
2. The attacker publishes or substitutes a malicious version that is selected by the unpinned package reference.
3. A user follows the installation instructions and runs `npx clawhub install clawhub-skill-rank`.
4. `npx` downloads and executes the attacker-controlled package code.
5. The malicious package runs with the permissions of the user who invoked the installation command.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the invoking user's account. Depending on that account's privileges and environment, the malicious installer could read or modify user-accessible files, steal accessible credentials, alter installed Skills, or execute additional commands.

The fi
...[truncated 151 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to a specifically reviewed version rather than resolving the latest available release.
  • Use an explicit invocation such as npx --package=clawhub@<reviewed-version> clawhub install clawhub-skill-rank.
  • Publish the expected package name, version, publisher identity, and integrity hash in the installation documentation.
  • Prefer a previously installed and independently verified CLI where practical.
  • Review new package versions before updating the documented pin.
  • Consider distributing a lockfile or verified installation wrapper that rejects artifacts with unexpected integrity metadata.
  • Advise users not to run the installer with elevated privileges.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/rank_checker.py:248
Finding

Terminal Escape Injection Through API-Controlled Search Results

Content
View full analysis

Vulnerability Details

File Location: scripts/rank_checker.py:248-259
Vulnerability Type: Unsanitized terminal rendering of remote content
Risk Level: Low

Vulnerable Code Snippet:

python
for tr in entry['top_results']:
    marker = " ◀ TARGET" if tr['is_target'] else ""
    print(f"    #{tr['rank']} {tr['slug']} (score: {tr['score']}){marker}")
    if verbose and tr['summary']:
        print(f"       {tr['summary']}")

if entry.get('competitors') and not entry.get('top_results'):
    print(f"  Nearby competitors:")
    for c in entry['competitors']:
        marker = " ◀ TARGET" if c['is_target'] else ""
        print(f"    #{c['rank']} {c['slug']} (score: {round(c['score'], 2)}){marker}")
        if verbose and c['summary']:
            print(f"       {c['summary']}")

Technical Analysis

The slug and summary fields are obtained from the remote ClawHub search API and printed directly to the terminal. Although locally supplied keywords are checked for certain control characters, equivalent sanitization is not applied to API response fields.

If an attacker can cause crafted skill metadata to appear in search results, that metadata could contain ANSI, OSC, or other terminal control sequences. A compatible terminal may interpret those sequences rather than render them as harmless text. The verbose display of summaries provides the clearest injection path, while slugs are also rendered without defensive filtering.

JSON output is less exposed to this issue because json.dumps escapes JSON control characters. The vulnerable path is the human-readable terminal output.

Attack Path

  1. An attacker publishes or modifies searchable skill metadata containing terminal control sequences in a field returned as slug or summary.
  2. The attacker causes the crafted skill to rank for a keyword likely to be queried by a victim.
  3. The victim invokes the checker with an option that dis ...[truncated 920 chars]
Remediation
View remediation

Remediation Suggestions

  • Sanitize every remote string before including it in human-readable terminal output.
  • Remove C0 and C1 control characters except explicitly permitted formatting characters.
  • Strip or visibly escape ANSI CSI, OSC, DCS, and related terminal escape sequences.
  • Apply sanitization to slug, displayName, and summary, including future API-controlled fields.
  • Keep raw API values only in structured JSON output, where serialization safely escapes control characters.
  • Consider a helper dedicated to terminal-safe rendering, for example:
python
ANSI_ESCAPE = re.compile(
    r'\x1B(?:[@-Z\\-_]|\[[0-?]*[ -/]*[@-~]|\][^\x07]*(?:\x07|\x1b\\))'
)

def terminal_safe(value):
    value = str(value)
    value = ANSI_ESCAPE.sub('', value)
    return re.sub(r'[\x00-\x08\x0b\x0c\x0e-\x1f\x7f-\x9f]', '', value)
  • Add regression tests using ANSI color sequences, OSC title changes, OSC clipboard sequences, carriage returns, backspaces, and other control characters.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx clawhub install clawhub-skill-rank without pinning a specific package version. This can lead to non-deterministic installs and creates supply-chain risk if the referenced package is updated maliciously, compromised, or unexpectedly changed after publication. Because this is a user-facing install command in documentation, it increases the chance that consumers execute an unsafe or altered package.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs execution of a Python script that performs outbound requests to the public ClawHub search API, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates a policy/containment gap: an agent may invoke network-capable code without clear authorization boundaries, reducing auditability and increasing the chance of unintended external requests or future abuse if the script changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like 'search position' and 'keyword ranking', which can match user requests that are not specifically about ClawHub skill ranking. Overbroad activation can cause the wrong skill to run, leading to unintended network calls, confusing results, or disclosure of user-provided competitor/keyword data to an external service when the user did not intend to use this skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.