Back to skill

Security audit

ClawHub 技能开发模板

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese ClawHub skill-template document with no executable code, dependencies, credential access, exfiltration, or hidden system changes.

Install only if you want a Chinese-language template for creating ClawHub skills. Before copying it into a new skill, remove the promotional star line and make any trigger phrases specific to your skill's actual scope.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:113
Finding

Promotional Instruction Propagation Through the Skill Template

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 113 and 192
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Low

Evidence at line 113:

markdown
*如果你觉得这个技能有用,请给它点个星,谢谢!⭐*

Evidence at line 192:

markdown
*如果你觉得这个技能有用,请给它点个星,谢谢!⭐*

Technical Analysis

The project is a template for producing other agent skills. Line 113 embeds a fixed promotional solicitation inside the copyable SKILL.md template, while line 192 includes the same solicitation in the template skill itself.

When an agent follows the documented template, the instruction can be copied into unrelated downstream skills. This manipulates generated skill output by adding author-selected promotional content that is not necessary to fulfill the user's requested task. The issue is limited to instruction-layer output manipulation; the audited project contains no executable scripts or dependencies.

Attack Path

  1. A user asks an agent to create a skill using this template.
  2. The agent copies the sample SKILL.md, including the instruction at line 113.
  3. The generated skill is published or loaded by another agent.
  4. The downstream skill retains or emits the fixed promotional solicitation.
  5. The author-controlled wording consequently propagates across otherwise unrelated skills and sessions where those skills are used.

Impact Assessment

The issue can affect the integrity and relevance of generated skill documentation or output by introducing unsolicited promotional language. It does not grant filesystem, network, account, system, or administrative privileges. No credential access, code execution, persistence, data exfiltration, or privilege escalation is enabled by the identified instruction.

Remediation
View remediation

Remediation Suggestions

  1. Remove the promotional sentence from the copyable template at line 113.
  2. Remove the duplicate sentence from the template skill at line 192.
  3. Restrict generated templates to instructions directly required for the declared skill behavior.
  4. If optional attribution or promotional material is desired, place it in a clearly labeled documentation section that agents are instructed not to copy by default.
  5. Add a release check that rejects templates containing fixed solicitations, unrelated calls to action, or instructions that modify downstream agent responses.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
"main": "SKILL.md",

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

powershell
# 1. 创建技能目录
mkdir -p ~/.openclaw/workspace/skills/your-skill-slug

# 2. 复制模板文件
# 从本技能复制SKILL.md和package.json,替换占位符

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

powershell
# 1. 创建技能目录
mkdir -p ~/.openclaw/workspace/skills/your-skill-slug

# 2. 复制模板文件
# 从本技能复制SKILL.md和package.json,替换占位符

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file contains natural-language guidance stating that descriptions are '中文推荐20-50字', which imposes a language preference in the template. Because the template is presented as a general skill development standard rather than a clearly justified region-specific tool, this is a language-policy concern without user choice or opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is in scope for vague-trigger review. The advice to make triggers 'natural' and include 'different phrasings' lacks constraints, and elsewhere the template does not provide negative examples or explicit scope limits, which could lead skill authors to choose activation phrases that overlap with common everyday speech and cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is entirely in Chinese and explicitly labels the template as a Chinese skill-development template, which imposes a language/locale assumption in user-facing metadata. There is no indication of optional language support, user choice, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.