Back to skill

Security audit

Clawhub Skill

Security checks for vulnerabilities and agentic risk

Overview

This memory skill has coherent memory features, but it exposes private memory and changes agent behavior in ways that need review before installation.

Review before installing. Use only on a trusted machine and network, bind the API to localhost or add authentication, avoid storing secrets, do not enable remote LLM or webhook settings unless you accept memory data leaving the device, and be aware that the skill may change the assistant's identity/style and maintain or alter long-term memory automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
src/prompt-builder.ts:198
Finding

Agent Identity and Response-Policy Hijacking Through System-Prompt Injection

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/soul-api.ts:115
Finding

Unauthenticated Memory API Exposed on All Network Interfaces

Content
View full analysis
{ res.setHeader('Access-Control-Allow-Origin', '*') res.setHeader('Access-Control-Allow-Methods', 'POST, GET, OPTIONS') res.setHeader('Access-Control-Allow-Headers', 'Content-Type, Authorization') if (req.method === 'OPTIONS') { res.writeHead(204); res.end(); return } const url = req.url || '' res.setHeader('Content-Type', 'application/json') try { const body = req.method === 'POST' ? JSON.parse(await readBody(req)) : {} if (url === '/memories' && req.method === 'POST') { try { const { addMemory } = await import('./memory.ts') const { extractFacts, addFacts } = await import('./fact-store.ts') const content = body.content || body.message || body.text || '' const userId = body.user_id || body.userId || 'default' const scope = body.scope || 'fact' if (!content) { res.writeHead(400) res.end(JSON.stringify({ error: 'content required' })) return } addMemory(content, scope, userId, 'private') const facts = extractFacts(content, 'user_said', userId) if (facts.length > 0) addFacts(facts) res.writeHead(200) res.end(JSON.stringify({ stored: true, facts_extracted: facts.length })) } catch (e: any) { res.writeHead(500) res.end(JSON.stringify({ error: e.message })) } return } ``` ```ts if (url === '/search' && req.method === 'POST') { const userId = body.user_id || body.userId || 'default' const topN = body.top_n || body.limit || 5 // Memory search and fact lookup occur here. const ...[truncated 3234 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
src/plugin-entry.ts:87
Finding

Persistent Prompt Injection Through Untrusted Memory Content

Content
View full analysis
0 ? msgs[msgs.length - 1] : null const userMsg = typeof lastMsg?.content === 'string' ? lastMsg.content : Array.isArray(lastMsg?.content) ? lastMsg.content.find((p: any) => p.type === 'text')?.text || '' : '' const cleanMsg = userMsg.includes(':') ? userMsg.split(/\n/).pop()?.replace(/^\S+:\s*/, '') || userMsg : userMsg if (cleanMsg && cleanMsg.length > 1) { const recalled = recall(cleanMsg, 5) if (recalled.length > 0) { memoryAugment = '\n\n[相关记忆] ' + recalled.map((m: any) => m.content?.slice(0, 80)).join(';') } } return { systemPrompt: soulPrompt + memoryAugment } } catch (e: any) { console.error(`[cc-soul][context-engine] assemble error: ${e.message}`) return { systemPrompt: '' } } } } ``` The unauthenticated storage path is: ```ts if (url === '/memories' && req.method === 'POST') { const { addMemory } = await import('./memory.ts') const { extractFacts, addFacts } = await import('./fact-store.ts') ...[truncated 2559 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
src/context-prep.ts:191
Finding

Automatic Reading of Arbitrary Local Files Referenced in Chat Messages

Content
View full analysis
p.startsWith('~/') ? p.replace('~', process.env.HOME || '') : p) .slice(0, MAX_FILES) for (const p of paths) { try { if (!existsSync(p)) continue intentFlags.hasFiles = true const content = readFileSync(p, 'utf-8') if (content.length <= INLINE_LIMIT) { contexts.push({ content: `[文件内容: ${p}]\n${content}`, source: p }) } else { const lines = content.split('\n') const head = lines.slice(0, HEAD_LINES).join('\n') contexts.push({ content: `[文件内容: ${p}] (${lines.length}行, 前${HEAD_LINES}行)\n${head}`, source: p, }) } } catch { // Unreadable files are skipped. } } ``` The normal message-handling path invokes it directly: ```ts const preparedCtx = prepareContext(userMsg) for (const pctx of preparedCtx) { augments.push({ content: pctx.content, priority: 7, tokens: estimateTokens(pctx.content) }) } ``` ### Technical Analysis The context-preparation feature detects absolute and home-relative file paths in ordinary message text and reads those files automatically with the privileges of the plugin process. There is no: ...[truncated 1904 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (758)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module constructs a prompt telling an LLM to "become" the user and generates replies in the user's identity, with relationship-aware and emotion-aware behavior. Impersonation and acting on behalf of a person are distinct capabilities that are not an obvious requirement of a memory engine.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Python integration example takes retrieved memories and injects them directly into an external OpenAI chat completion request without any warning that stored user memories may be transmitted to a third party. This omission is dangerous because users may copy the example verbatim and unknowingly exfiltrate sensitive personal data from the local memory store.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The privacy claim 'Nothing ever leaves your machine' directly conflicts with the documented optional remote LLM setup and example integrations that can send memory content to third-party APIs. This can cause users to expose sensitive conversation history under a false assumption of strict local-only processing.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
83% confidence
Finding

The documented natural-language command set includes destructive memory operations such as 'delete memory' and restoration/pinning controls. In an agent skill, exposing broad state-changing memory commands through ordinary chat increases the risk of prompt-induced memory tampering, unauthorized deletion, or persistence manipulation.

Content

Scanner excerpt · README.md (reported line 416)May include surrounding context.

md
|---------|-------------|
| `我的记忆` / `my memories` | View recent memories |
| `搜索记忆 <词>` / `search memory <kw>` | Search memories |
| `删除记忆 <词>` / `delete memory <kw>` | Remove matching memories |
| `pin 记忆 <词>` / `pin memory <kw>` | Pin memory (never decays) |
| `unpin 记忆 <词>` | Unpin memory |
| `恢复记忆 <词>` / `restore memory <kw>` | Restore deleted memory |

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared deletion/expiration logic and heartbeat-driven sweeping are integrity-relevant behaviors that affect stored user data. This is dangerous because users may lose memories unexpectedly, and hidden retention logic can undermine trust and auditability.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cc-soul/cli.js:321

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cc-soul/context-prep.js:38

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cc-soul/handler-commands.js:314

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cc-soul/handler.js:406

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cc-soul/health.js:115

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/install.js:110

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/cli.ts:431

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/context-prep.ts:87

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/handler-commands.ts:343

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/handler.ts:457

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/health.ts:197

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
cc-soul/sqlite-store.js:52

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/sqlite-store.ts:67

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cc-soul/benchmark-locomo.js:9

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cc-soul/context-prep.js:131

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cc-soul/plugin-entry.js:5

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/benchmark-locomo.ts:23

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/context-prep.ts:205

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/plugin-entry.ts:14

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
cc-soul/cli.js:43

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
cc-soul/soul-api.js:57

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/cli.ts:84

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/soul-api.ts:66

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
cc-soul/handler-augments.js:639

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
src/handler-augments.ts:809