Back to skill

Security audit

Multi Find Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent skill-discovery purpose, but its search and installation guidance gives agents several high-impact, under-scoped ways to run mutable tools and change the user’s skill environment.

Review this skill before installing. Use it only if you are comfortable with an agent searching external registries, running package-manager-backed CLIs, and maintaining local preference memory. Avoid the documented --force, -g, -y, whole-repository install, and registry-mirror commands unless you have independently verified the exact package source, version, and install scope.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
sources.md:45
Finding

Routine searches execute unpinned remote npm packages

Content
View full analysis
" npx skills find "" npx -y @lobehub/market-cli skills search --q "" ``` ### Technical Analysis The Skill instructs the Agent to invoke multiple npm packages through `npx` as part of an ordinary search. No exact package versions, integrity hashes, lockfiles, or immutable releases are specified. When a package is unavailable locally, `npx` can retrieve and execute it from the configured npm registry. The effective code therefore remains mutable after this Skill has been reviewed. The LobeHub command also uses `-y`, suppressing the normal package-execution confirmation. This code execution happens during discovery, before the user selects or approves installation of a recommended Skill. The conservative installation policy therefore does not protect against malicious code in the search CLI itself. ### Attack Path 1. An attacker compromises one of the referenced npm packages, its publisher account, or a transitive dependency. 2. The Skill activates, potentially through its broad implicit activation rules. 3. The Agent runs an unpinned `npx` search command. 4. `npx` downloads the current package version and dependencies. 5. Malicious package initialization or runtime code executes with the Agent process's operating-system permissions. 6. The payload can access resources available to that process or modify files writable by the user. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the Agent user's account. The accessible scope may include user files, Agent configuration, environment variables, authentication material exposed to the process, and writable Skill directories. No direct privilege escalation to root is de ...[truncated 88 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
sources.md:173
Finding

Installation guidance enables unattended global installation of unpinned repositories

Content
View full analysis
--agent open-claw ``` The documented parameter meanings are: ```text -g = global installation -y = skip confirmation ``` ### Technical Analysis The installation commands combine several unsafe supply-chain characteristics: - Remote execution through an unpinned `npx` package. - Automatic confirmation through `-y`. - Global installation through `-g`. - The option to install an entire repository rather than only the selected Skill. - No immutable commit, release version, signature, or content hash. This directly conflicts with `SKILL.md:195-203` and `SKILL.md:257-261`, which state that the Skill must not automatically add `-y`, silently select global scope, or install without conservative confirmation. A general response such as “install it” does not necessarily constitute informed consent to global scope, an entire repository, and suppression of package-manager confirmations. ### Attack Path 1. An attacker publishes or compromises a repository that appears in a search result. 2. Metadata such as popularity, description, or update recency causes the Skill to recommend it. 3. The user gives general consent to install the recommended Skill. 4. The Agent follows the documented command containing `-g -y`, or installs the entire repository. 5. Confirmation and scope-selection prompts are skipped. 6. Attacker-controlled Skill content is installed globally and becomes available to later Agent sessions. ### Impact Assessment The installation may affect all compatible Agent contexts for the current user rather than only the current project. Installing an entire repository ca ...[truncated 206 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
troubleshooting.md:184
Finding

Forced installation instructions can bypass protective installation failures

Content
View full analysis
/SKILL.md clawhub install --force ``` The troubleshooting guide repeats the unsafe recovery behavior: ```bash # Retry after an installation failure clawhub install --force # Reinstall after validation failure clawhub install --force ``` Elsewhere, `troubleshooting.md:65-79` says that force installation must never be used and scanner warnings must not be skipped. ### Technical Analysis The project contains mutually contradictory security instructions. Its suspicious-Skill procedure prohibits `--force`, while its primary installation validation and troubleshooting paths repeatedly prescribe that flag after failure. The documentation does not constrain `--force` to a proven-safe overwrite operation. It also does not require determining whether the original failure resulted from a scanner finding, package conflict, integrity failure, or another protective control. An Agent following the recovery path may therefore override the very condition intended to prevent unsafe installation. ### Attack Path 1. A malicious, suspicious, conflicting, or malformed Skill causes normal installation or post-installation validation to fail. 2. The Agent enters the documented failure-recovery procedure. 3. The procedure instructs the Agent to retry using `--force`. 4. A protective refusal, file conflict, or scanner-related block may be overridden. 5. The untrusted Skill is written into the Agent's Skill directory. 6. The installed instructions or code become available for later loading and execution. ### Impact Assessment The affected scope is the current user's OpenClaw Skill environment. Exploitation could install attacker-controlled instructions or code despite a prior failure. Subse ...[truncated 235 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:174
Finding

ClawHub registry can be persistently redirected to an unverified mirror

Content
View full analysis
--registry https://cn.clawhub-mirror.com ``` The troubleshooting guide also recommends: ```bash clawhub install --registry https://cn.clawhub-mirror.com ``` ### Technical Analysis The project instructs the Agent to replace ClawHub's configured registry with a third-party mirror when installation fails. The reviewed files provide no evidence of official ownership, trusted provenance, certificate pinning, package signatures, immutable hashes, or independent verification of content obtained from this mirror. The `config set registry` command is persistent and can affect later ClawHub operations beyond the immediate installation attempt. A malicious or compromised mirror could serve altered content under legitimate package names, creating a tool-spoofing and supply-chain substitution channel. ### Attack Path 1. The normal registry is unavailable or an installation request fails. 2. The Agent follows the documented fallback and persistently changes the registry. 3. Subsequent searches or installations trust responses from the replacement registry. 4. The mirror returns a modified package using the expected Skill name. 5. The Agent installs the substituted package without verifying it against an independent trusted source. 6. The altered Skill is loaded in a later Agent session. ### Impact Assessment A compromised registry can influence every package subsequently obtained through the affected ClawHub configuration. It can substitute arbitrary Skill instructions or code within the permissions of the current user. Because the registry change persists, the exposure can continue across later tasks and sessions until manually restored. ]]>
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
memory.md:24
Finding

Persistent behavioral tracking contradicts the explicit-only memory policy

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (62)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · evaluation.md (reported line 129)May include surrounding context.

md
- ✅ 340K 安装量,社区验证

**安装命令:**
​```bash
clawhub install frontend-design
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · evaluation.md (reported line 131)May include surrounding context.

md
- ✅ 340K 安装量,社区验证

**安装命令:**
​```bash
clawhub install frontend-design
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · evaluation.md (reported line 146)May include surrounding context.

md
- ✅ 340K 安装量,社区验证

**安装命令:**
​```bash
clawhub install frontend-design
​```

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · evaluation.md (reported line 148)May include surrounding context.

md
- ✅ 340K 安装量,社区验证

**安装命令:**
​```bash
clawhub install frontend-design
​```

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented recovery action says corrupted memory may be deleted and rebuilt, but it omits user confirmation and warning about data loss. Automatic deletion of persisted preference state is dangerous because corruption may be misdetected, and destructive recovery can irreversibly erase user choices or audit history.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implicit activation rules are broad enough to trigger skill searches from ordinary conversational phrases like 'How do I do X?' or 'Is there a better way?'. In this skill’s context, that can cause unsolicited marketplace queries and recommendations that nudge users toward installing third-party capabilities they did not explicitly request, increasing the chance of unsafe or socially engineered installations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide earlier states that forced installation must never be used for suspicious skills, but later recommends clawhub install <skill-name> --force as a general troubleshooting step. This contradiction encourages bypassing safety controls in a benign-looking recovery flow, increasing the chance that users suppress important protections and install unsafe content.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The troubleshooting section normalizes use of --force in natural-language recovery instructions, directly undermining earlier guidance not to bypass scanner warnings. This is dangerous because users often trust troubleshooting steps more than policy sections, making security-control bypass seem routine and acceptable.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Recommending a forced reinstall after validation failure further entrenches bypass behavior and may cause users to override protections instead of investigating why installation or verification failed. In a package/skill ecosystem, this can lead to installation of tampered, misplaced, or otherwise unsafe content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The implicit trigger phrases are broad enough to match ordinary problem-solving conversations, causing the skill to activate in contexts where the user did not actually ask for skill discovery. In this skill, accidental activation is meaningful because activation leads to external searches, memory reads, and recommendation workflows, potentially leaking query context and expanding the chance of unsafe package interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The detection step asks whether the user is describing a 'capability gap or installable need' without precise limits, which is ambiguous and likely to over-trigger. In the context of a skill that consults external ecosystems and local memory, this ambiguity can lead to unintended searches, preference use, and escalation from ordinary conversation into external command execution paths.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill instructs the agent to execute external CLIs via npx without pinning package versions, which allows resolution of whatever package version is current at execution time. If an upstream package is compromised, typosquatted, or publishes a malicious update, the agent could fetch and run attacker-controlled code during search or install workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command references npx clawhub without an exact version, so execution depends on mutable upstream package state rather than a reviewed artifact. In an agent setting, that creates a supply-chain execution risk because search behavior can trigger remote package download and code execution automatically.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using npx -y @lobehub/market-cli without pinning a specific version permits automatic download and execution of the latest published package, and the -y flag further reduces friction for unattended execution. In a skill that searches external ecosystems and may be run by an agent, this increases exposure to upstream compromise and silent supply-chain abuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This is a second unpinned use of npx -y @lobehub/market-cli, again enabling execution of a mutable upstream package with automatic confirmation. Repetition in operational guidance makes the unsafe pattern more likely to be copied into real agent actions, expanding the attack surface for supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill again references npx skills without version pinning, reinforcing a pattern of executing mutable remote dependencies. Because this skill is specifically for discovering and installing other skills, its operational context makes any supply-chain weakness more dangerous: the agent is already interacting with external package ecosystems and may do so frequently.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing guidance, prompts, and examples exclusively in Chinese, including interactive text such as '需要我帮你安装吗?'. The policy requires flagging language or locale constraints when a specific language is forced without explicit user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly instructs the skill to create and read/write a persistent memory file under the user's home directory, but it does not mention disclosure, consent, retention, or review controls. In an agent skill context, silent local profiling can accumulate user preferences and domain information in a way users may not expect, creating privacy and data-handling risk even if the stored fields appear limited.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains multiple instructional comments and field annotations in Chinese, such as the preference, adoption tracker, feedback, and metrics guidance. That imposes a language/locale assumption in the skill memory format without any indication that the user chose Chinese or that the skill is explicitly region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and all user-facing content are written exclusively in Chinese, and the document gives no indication that language selection is optional. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that initialization happens automatically and creates local persistent files without a clear upfront warning or consent flow. Silent filesystem modification can violate user expectations, make later state hard to audit, and create a precedent for broader unauthorized local changes by skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file defines an automatic trigger based on the agent's 'first activation' but does not clarify whether that means first use of this specific skill, first agent session, or another scope. The ambiguity could cause unintended invocation of the initialization behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file states that memory.md is updated only when the user explicitly declares information and that the skill should only record what the user clearly said. However, the initialization flow pre-populates status, last, sources, and integration automatically, which contradicts the stated update rule in the same document.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · setup.md (reported line 89)May include surrounding context.

展开查看
bash
mkdir -p ~/.openclaw/skills/multi-find-skills
cp memory-template.md memory.md
# 编辑 memory.md

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
74% confidence
Finding

整个文件以中文编写,且未说明这是可选语言版本、未提供多语言入口,也未声明仅面向特定中文用户群体。按规则,若技能在自然语言层面强制特定语言而没有用户选择或明确合理限定,可能构成语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.