Back to skill

Security audit

CrawlHub

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent CrawlHub API guide, but it exposes broad scraping, account, team, API-key, and billing actions without clear safeguards or user-confirmation boundaries.

Install only if you intend to use CrawlHub and are comfortable giving an agent access to your CrawlHub account tokens. Keep use read-only by default, verify that collection is authorized and compliant with platform rules and privacy obligations, and require explicit confirmation before any team, API-key, billing, profile, subscription, DELETE, PATCH, or PUT action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The skill exposes multiple write-capable execution methods, including DELETE, against a generic endpoint execution path without describing safeguards, allowed parameter validation, or user-confirmation requirements. In an agent setting, this increases the chance of destructive or unintended actions if the model selects a mutating method or attacker-controlled parameters are passed through.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

POST /execution/endpoints/{endpoint_id}/execute → Execute with JSON body PATCH /execution/endpoints/{endpoint_id}/execute → Partial update style execution PUT /execution/endpoints/{endpoint_id}/execute → Full replacement style execution DELETE /execution/endpoints/{endpoint_id}/execute → Delete style execution

text

### Authentication & Users

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

text
POST /auth/register       → Register new account
POST /auth/login          → Login (email + password)
POST /auth/refresh        → Refresh access token
POST /auth/logout         → Revoke tokens
POST /auth/password-reset → Request password reset email
GET  /auth/token-validate  → Validate current JWT

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

text
POST /auth/register       → Register new account
POST /auth/login          → Login (email + password)
POST /auth/refresh        → Refresh access token
POST /auth/logout         → Revoke tokens
POST /auth/password-reset → Request password reset email
GET  /auth/token-validate  → Validate current JWT

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The documented team-management endpoints include removing members and changing roles, but the skill provides no guardrails requiring confirmation or permission checks before such sensitive administrative actions. In context, this is more dangerous because these operations can directly revoke access or alter privileges within an organization, potentially causing service disruption or insider-abuse effects if triggered accidentally or through prompt manipulation.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
POST /teams                        → Create a new team
GET  /teams/{team_id}              → List team members
POST /teams/{team_id}/invite       → Invite member to team
DELETE /teams/{team_id}/{member_id} → Remove member
GET  /teams/{team_id}/permissions  → Get current user's permissions
PUT  /teams/{team_id}/{member_id}/role → Change member role
GET  /teams/roles                  → List available team roles

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
- **Check `/plans`** — before executing to understand your current plan's rate limits
- **Monitor usage** — via `/teams/{team_id}/billing/transactions` and request logs
- **Handle 503s gracefully** — implement exponential backoff when server is busy
- **Store access tokens securely** — never log them; refresh before expiry

## Notes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill promotes scraping and delivery of social-platform data without warning users about privacy, platform terms, consent, or legal/compliance constraints. In this context, the omission is risky because the skill explicitly advertises anti-bot circumvention and data extraction across social and messaging platforms, which can lead users to perform non-compliant or privacy-invasive actions without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
## API Reference

**Base URL:** `https://api.thecrawlhub.com/api/v1`

**Authentication:**
- Login: `POST /auth/login` with `{"email": "...", "password": "..."}` → returns `access_token` and `refresh_token`

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill lists account, team, API-key, and billing endpoints that can create accounts, invite or remove members, change roles, generate keys, and switch subscriptions, but it does not warn that these are state-changing operations. This can cause accidental organizational changes, unexpected charges, or privilege changes if an agent invokes these endpoints without explicit user confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.