Back to skill

Security audit

clawpatch

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed operating guide for the Clawpatch code-review CLI, with expected risks around npm installs, provider CLIs, and repository access.

Install only if you are comfortable trusting the Clawpatch npm package, the skills installer, and the chosen provider CLI with the repositories you review. Prefer pinned versions, avoid running install commands as root, review provider authentication yourself, and treat full-repo scans or fixes as actions that can expose or modify project code.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:69
Finding

Unverified Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:69-74; additional occurrences in SKILL.md:18-23 and README.md:32-58
Vulnerability Type: Unverified npm and npx supply-chain dependencies
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:69-74:

markdown
## Setup

`clawpatch doctor` verifies the install and the provider. The published CLI
requires Node.js 22+. If `clawpatch` is missing, install the current published
package (`npm install -g clawpatch@0.7.2`). The provider (codex by default) is
the user's to install and authenticate — don't run login flows on their behalf.

SKILL.md:18-23:

yaml
install:
  - id: npm
    kind: node
    package: clawpatch
    bins: [clawpatch]
    label: Install Clawpatch (npm)

README.md:32-58:

markdown
## Prerequisites

- **Node.js 22+ + npm** — Clawpatch is an npm package
  (`npm install -g clawpatch@0.7.2`).
- **A coding-agent provider CLI** — one of `codex` (default), `claude` (routes
  through your local Claude Code CLI), `cursor`, `grok`, `opencode`, `pi`, or
  `acpx`.

The skill checks both with `clawpatch doctor` and walks you through install if
either is missing.

## Install

Install only this skill from the repo:

```bash
npx skills add tmchow/agent-skills --skill clawpatch

Add --global to install it at the user level instead of the current project:

bash
npx skills add tmchow/agent-skills --skill clawpatch --global

Update later with npx skills update clawpatch.

text

### Technical Analysis

The skill instructs an agent or user to obtain and execute registry-resolved npm packages without requiring artifact integrity verification, package provenance validation, or source inspection.

Pinning `clawpatch` to version `0.7.2` limits unintended version drift, but it does not independently establish that the registry artifact is authentic or uncompromised. Its transitive depe
...[truncated 2732 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every executable package used through npx, including the skills runner, to a reviewed version rather than relying on registry resolution of the current release.
  2. Publish and document trusted release checksums or signed provenance attestations, and require verification before installation.
  3. Use npm lockfiles with integrity metadata for project-local installations and retain them in version control.
  4. Prefer project-local installation over npm install -g to limit cross-project exposure and make the resolved dependency graph auditable.
  5. Inspect package manifests and tarball contents before first execution. Verify the expected publisher, repository, signatures, provenance, lifecycle scripts, and included files.
  6. Disable lifecycle scripts during acquisition with npm install --ignore-scripts where the package supports it, then explicitly run only reviewed setup operations.
  7. Use a trusted registry and enforce registry configuration so similarly named packages cannot be resolved from an unintended source.
  8. Run installation and review tooling in a sandbox or container with minimal filesystem access, no unnecessary credentials, and restricted network access.
  9. Avoid automatic updates. Review release notes, source changes, dependency changes, and provenance before accepting a new skill or CLI version.
  10. Document that users must not run these installation commands with administrator or root privileges.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
without a full re-review.

Prefer those over trusting stale statuses *or* wiping. Wiping
(`[ -d .clawpatch ] && rm -r .clawpatch` — guarded, never `rm -rf`) is a last
resort for genuinely corrupt state, not the freshness tool — it discards
resume context and costs a full re-review. (There's no `--resume` flag;
"resume" just means the on-disk state is still there.)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
90% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
Prefer those over trusting stale statuses *or* wiping. Wiping
(`[ -d .clawpatch ] && rm -r .clawpatch` — guarded, never `rm -rf`) is a last
resort for genuinely corrupt state, not the freshness tool — it discards
resume context and costs a full re-review. (There's no `--resume` flag;
"resume" just means the on-disk state is still there.)
Use `clawpatch triage --finding <id> --status <status> --note <text>` to mark

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
overrides the failed-validation guard. `fix` has no `--force`; keep the clean
  source-worktree preflight intact. Clawpatch does **not** merge/land PRs today
  (there's no `land` command); if a merge/land command ever appears, treat it
  the same way — never run it without approval.
- **Never combine subagents with `clawpatch fix`.** Sharing `.clawpatch/`
  across subagents risks patches landing in the wrong worktree (evidence
  paths resolve against the original `rootPath`); copying state per subagent

Static analysis

No suspicious patterns detected.