Back to skill

Security audit

TeamClaw Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for TeamClaw orchestration, but its broad auto-activation and unsafe shell examples create review-worthy risk before installation.

Install only if you intentionally want ordinary build requests delegated to TeamClaw. Keep the controller bound to trusted local access, review what requirements or files may be shared with workers, avoid sending secrets, and prefer safe JSON serialization such as jq or a structured HTTP client instead of pasting user text into the documented curl templates.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:57
Finding

Shell Command Injection Through Unsafe JSON Interpolation

Content
View full analysis
"}' ``` #### Clarification answer — `SKILL.md:129-131` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/clarifications//answer" \ -H "Content-Type: application/json" \ -d '{"answer": "", "answeredBy": "user"}' ``` #### Task creation — `SKILL.md:139-147` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/tasks" \ -H "Content-Type: application/json" \ -d '{ "title": "Implement user login", "description": "Create a login form with email/password auth", "priority": "high", "assignedRole": "developer" }' ``` #### Team messaging — `SKILL.md:157-173` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/messages/direct" \ -H "Content-Type: application/json" \ -d '{ "from": "user", "toRole": "developer", "content": "Please also add input validation" }' # Broadcast to all workers curl -s -X POST "$TEAMCLAW_URL/api/v1/messages/broadcast" \ -H "Content-Type: application/json" \ -d '{ "from": "user", "content": "Deadline moved up — prioritize core features" }' ``` ### Technical Analysis The skill instructs the agent to insert requirements, clarification answers, task details, and message content into JSON embedded in single-quoted shell arguments. If an implementation performs direct textual substitution, an attacker-controlled single quote can terminate the shell string. Shell operators and commands following that quote may then be interpreted by the local shell. Even where the payload does not achieve ...[truncated 2038 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

The skill provides built-in commands for sending arbitrary direct and broadcast messages into the orchestration system, which can relay user content or sensitive project information to multiple workers without strong consent boundaries. In this skill's context, broad activation plus message-sending capabilities increase the risk of prompt/data exfiltration into a multi-agent environment and make misuse more dangerous than a simple local automation helper.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

Valid priorities: low, medium, high.

6. Send Messages to the Team

bash
# Direct message to a role

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely broad and include common software-assistance requests such as 'build me' and 'create a', which can cause the skill to activate for ordinary coding requests that do not require delegation to an external orchestration system. This increases the chance of unintended routing of user prompts into TeamClaw workflows, potentially causing unnecessary external actions, task creation, or data transmission.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation guidance says to use the skill whenever the user wants to build or implement something, but that overlaps heavily with normal assistant behavior and does not require explicit consent to orchestrate a team. In context, this ambiguity is dangerous because the skill also performs API calls to a local controller, so accidental activation can lead to unintended task submission and sharing of user requirements with another system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

TEAMCLAW_URL="http://127.0.0.1:9527"

Health check — verify the controller is running

curl -sf "$TEAMCLAW_URL/api/v1/health"

text

If the health check fails, tell the user to start TeamClaw first (install the `teamclaw-setup` skill for guidance).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The API reference documents endpoints that expose arbitrary workspace metadata and file contents (/api/v1/workspace/tree and /api/v1/workspace/file?path=<path>) without any warning about the sensitivity of those capabilities or expected access restrictions. In a multi-agent orchestration skill, this can normalize broad file-reading behavior and increase the chance that users or connected workers expose secrets, source code, or unrelated local files if path handling or authorization is weak.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.