Back to skill

Security audit

ClawHeart Security

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local security-audit helper, but its install fallback asks users to execute remote installer scripts directly and it can expose or modify sensitive agent/provider configuration without strong scoping.

Review this skill before installing. It is not evidence of hidden malware, but do not run the provided curl|sh or iwr|iex installer commands unless you independently trust and verify the installer. Treat agent, MCP, provider, and credential-governance outputs as sensitive, and require explicit confirmation before running commands that list or change provider configuration.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:23
Finding

Unverified Remote Installer Scripts Are Executed Directly

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 23 and lines 85–87
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: Critical

Vulnerable Code

At line 23:

sh
curl -fsSL clawheart.live/install.sh | sh

At lines 85–87:

sh
curl -fsSL https://clawheart.live/install.sh | sh
iwr https://clawheart.live/install.ps1 -useb | iex

Technical Analysis

The Skill instructs users or an AI Agent to download mutable scripts from an external server and pass the responses directly to a command interpreter. The Unix instructions pipe the response to sh, while the Windows instruction sends the response to PowerShell's Invoke-Expression alias, iex.

No version pinning, cryptographic signature verification, checksum validation, content review, or trusted package-manager verification occurs before execution. Consequently, the effective code is controlled by the remote endpoint at installation time and can change after the Skill package has been reviewed.

The command on line 23 additionally omits an explicit https:// scheme. Depending on client behavior and server redirects, this can create an avoidable risk of plaintext transport or unsafe redirection before reaching HTTPS.

Installing the CLI may support the Skill's declared functionality, but direct remote execution is not the minimum-risk installation method. A downloaded, versioned, and cryptographically verified artifact would provide the same functionality without automatically treating a network response as executable code. The repository does not include the installer source, so its behavior, requested permissions, and safety cannot be audited here.

Attack Path

  1. A user asks the Agent to perform a ClawHeart security operation.
  2. The Agent determines that the clawheart executable is not available.
  3. Following SKILL.md, the Agent recommends or facilitates one of the remote installation com ...[truncated 1225 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all direct download-and-execute patterns, including curl | sh and iwr | iex.
  2. Use explicit HTTPS URLs in every installation instruction.
  3. Publish immutable, versioned release artifacts through a documented release channel.
  4. Sign release artifacts and document verification using a trusted public key or platform-native code-signing mechanism.
  5. Publish SHA-256 or stronger checksums through an independently protected channel and require verification before execution.
  6. Split downloading and execution into separate steps so users can inspect the artifact before running it.
  7. Prefer reputable package managers with a pinned package and version where possible.
  8. Document the installer's expected filesystem changes, network access, and required permissions. Ensure it does not require administrative privileges unless strictly necessary.
  9. If an installer script remains available, publish its source alongside the Skill and pin instructions to an immutable release rather than a mutable install.sh or install.ps1 endpoint.
  10. Replace the current instructions with a workflow similar to:
sh
curl --proto '=https' --tlsv1.2 -fLo clawheart-installer.sh \
  https://clawheart.live/releases/VERSION/install.sh
echo 'EXPECTED_SHA256  clawheart-installer.sh' | sha256sum -c -
less clawheart-installer.sh
sh clawheart-installer.sh

The actual release version and digest must be fixed, authentic, and maintained securely. On Windows, use an equivalent download, Authenticode or checksum verification, review, and separate execution process rather than Invoke-Expression.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The documented fallback installation command fetches a remote script and pipes it straight to the shell. This is a classic unsafe pattern because it grants immediate execution to unreviewed remote content, enabling full compromise if the source or delivery path is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
你可以通过 `clawheart` 命令行调用本机 ClawHeart 服务做 AI 安全审计、技能鉴定、Agent 凭据治理。

> 前置:用户机器需要安装 ClawHeart CLI(`clawheart-cli` 或 `clawheart`,PATH 中可执行)。
> 若 `which clawheart` 失败,引导用户访问 https://clawheart.live 下载,或跑 `curl -fsSL clawheart.live/install.sh | sh`。

## 触发条件 → 命令映射

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to install the CLI by piping a remote script directly into a shell. This creates a code-execution path outside the skill's audit purpose, and if the remote host, transport, or script is compromised, arbitrary code could run on the user's machine.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The CLI-unavailable fallback repeats direct execution of remote shell and PowerShell install scripts. This broadens the unsafe behavior across platforms and turns a missing-tool condition into a high-risk code execution path that is unrelated to merely auditing local AI security.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
> ClawHeart CLI 似乎没装。访问 https://clawheart.live 下载,或运行:
>
> macOS / Linux:`curl -fsSL https://clawheart.live/install.sh | sh`
>
> Windows:`iwr https://clawheart.live/install.ps1 -useb | iex`

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description uses broad natural-language triggers like '扫一下 AI 安全' and similar intent phrasing, which can match many benign user requests. In an agent environment, ambiguous triggers increase the likelihood of unintended invocation of local security tooling and exposure of local configuration details.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages running commands that can reveal local agent inventory, config paths, MCP servers, and provider configuration, but it does not prominently warn that these outputs may contain sensitive information. Users may unknowingly authorize disclosure of credentials, filesystem paths, or security posture details into the chat context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger-to-command table maps vague keyword examples directly to commands without clear constraints, confirmation requirements, or disambiguation rules. This makes accidental execution more likely, especially for commands that enumerate agents, providers, and local security state.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
- ❌ 不要直接读 `~/.clawheart-v2/` 文件 — 必须通过 CLI
- ❌ 不要替用户输入密码 / API key
- ❌ skipped 项的 "未实现" 状态不要解读为漏洞或问题
- ❌ 不要自己尝试 sudo —— 遇到需要权限的提示直接转告用户

## CLI 不可用时的兜底

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is presented as an audit/governance helper, but its documented command set includes provider mutation operations such as add, import, and overwrite. That expands it from read-only inspection into credential and configuration modification, increasing the chance of unintended secret changes or account reconfiguration under the guise of a security scan.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Provider add/import/overwrite operations are not necessary for a skill whose stated role is auditing and governance visibility. Exposing these commands can let an invocation modify provider settings or credentials, creating opportunities for misconfiguration, credential replacement, or persistence changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.