Back to skill

Security audit

clawsouls

Security checks for vulnerabilities and agentic risk

Overview

The skill’s persona-management purpose is clear, but it includes unpinned package execution paths for tools that can change agent identity files and publish content.

Install only if you are comfortable letting this skill modify active agent persona files and interact with the ClawSouls registry. Confirm before switching personas, publishing, or syncing memory; review any soul directory for secrets before publishing; and prefer pinned/local CLI versions over the unpinned npx wrapper or adapter commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · HERMES_ADAPTER.md (reported line 19)May include surrounding context.

bash
# from a URL
hermes skills install https://raw.githubusercontent.com/clawsouls/clawsouls-skill/main/SKILL.md

# or clone into the skills directory
git clone https://github.com/clawsouls/clawsouls-skill ~/.hermes/skills/clawsouls

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L25 says the skill can be invoked by simply asking "install a soul," but it does not bound that phrase to a specific command context or provide exclusions. Because this is a natural-language trigger in a markdown skill description, it is broad enough to match ordinary conversation and could cause unintended invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This is the same unpinned npx clawsouls execution path on line 30, which causes users to run whatever version is current at execution time. That creates a supply-chain execution risk, especially for a tool that edits files in the active agent workspace.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

npx clawsouls soulscan is also unpinned, so users may execute an unexpected future package version when performing a safety scan. A scanning command is often perceived as safer, which can lower user suspicion while still granting arbitrary code execution to the fetched package.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises publishing soul packages to an external registry but does not clearly warn that package contents will be transmitted off-machine. Because persona/workspace files may include sensitive prompts, identity data, or embedded secrets, users may unintentionally exfiltrate confidential material when following these instructions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L017 contains a user-facing instruction entirely in Korean with no accompanying translation or indication that the user can choose another language. This creates a locale/language policy issue because the skill presents mandatory operational guidance in a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs users to execute an unpinned package directly from npm via npx -y soul-spec-mcp, which allows whatever version is current at execution time to run on the host. If the package is updated maliciously, compromised in the supply chain, or replaced through dependency confusion or account compromise, users could execute attacker-controlled code with their local permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This wrapper executes npx --yes clawsouls "$@" without pinning an exact package version, so it may fetch and run whatever package version the registry serves at execution time. If the npm package is compromised, typo-squatted, or a malicious new version is published, running this script would execute attacker-controlled code on the user's machine, which is especially dangerous because this skill manages workspace files, authentication, and potentially publishing or sync operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README describes installing, switching, backing up, and restoring personas without clearly warning that local workspace persona files will be modified. In this skill's context, those files influence agent behavior, so silent replacement or backup/restore operations can alter execution context, overwrite prior state, or confuse users about what configuration is active.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The design describes install/use behavior that writes identity files into agent workspace paths and can alter the active persona, but it omits an explicit user-facing warning at the point where these operations are documented. In the context of a persona-management skill, changing SOUL.md/IDENTITY.md can materially change agent behavior, so lack of clear warning increases the risk of users making security-relevant workspace changes without informed consent.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency is specified with a caret range (^0.1.0), which permits automatic installation of newer compatible versions within the 0.x line. That creates supply-chain risk because a future compromised or malicious release of the clawsouls package could be pulled in without explicit review, and this skill has a sensitive role involving workspace modification, token-authenticated registry access, and optional Git-based memory sync.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
},
  "homepage": "https://clawsouls.ai",
  "dependencies": {
    "clawsouls": "^0.1.0"
  }
}

Static analysis

No suspicious patterns detected.