Back to skill

Security audit

claude-code (Deprecated alias)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent as a Claude Code tmux orchestrator, but it starts coding agents with permission safeguards disabled and has under-scoped shell, SSH, and temp-file handling that users should review before installing.

Install only if you are comfortable with this skill starting autonomous Claude Code sessions that can modify the selected repository without normal permission prompts. Prefer a sandbox, VM, container, or dedicated low-privilege account; avoid untrusted task text, paths, and prompt files; and review or remove the unsafe launch mode, SSH/SCP behavior, and `/tmp` report handling before using it on sensitive projects.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/start-tmux-task.sh:193
Finding

Claude Code Is Launched with Permission Safeguards Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-tmux-task.sh:193
Finding

Shell Command Injection Through Unvalidated Orchestrator Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/start-tmux-task.sh:55
Finding

Predictable Temporary Files Allow Symlink Clobbering and Completion Report Spoofing

Content
View full analysis
"$PROMPT_TMP" <
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description emphasizes triggering Claude Code development tasks in observable tmux sessions with stable startup and progress visibility, plus completion callback behavior. This code chunk instead appears to be a completion/reporting helper that assumes work has already happened: it changes into a workdir, inspects git status/diff, runs lint/build quality checks, determines a simple risk/recommendation, writes JSON and Markdown reports, and optionally sends a wake notification. The only tmux-related behavior is deriving a session name for filenames; there is no tmux control, no session creation/monitoring, and no Claude Code task startup. The notification aspect is somewhat aligned, but the primary purpose is materially different and includes undeclared capabilities around repository inspection, command execution, and report generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The declared description emphasizes launching Claude Code development work in tmux with stable startup, progress visibility, SSH monitoring, and completion callbacks to OpenClaw. This script does not start or manage coding sessions, does not trigger Claude Code tasks, and does not perform any callback or push to OpenClaw. Instead, it inspects task listings from another script, checks report file mtimes against a local delivery-state JSON file, outputs a summary of completed-but-undelivered tasks, and can mark them as delivered. While tmux session names and attach commands are included for observability, the primary purpose is post-completion reconciliation and delivery-state management, which is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared purpose emphasizes initiating Claude Code work in tmux sessions and handling observability plus completion notification. The actual code chunk is a reporting utility (summarize-tasks.sh) that consumes task listings and formats a status heartbeat for chat. While this is loosely related to progress visibility, it omits the core declared behaviors of triggering tasks, setting up sessions, and notifying OpenClaw on completion. Therefore the code chunk's primary purpose is materially different from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on orchestrating Claude Code coding jobs inside observable tmux sessions and notifying OpenClaw upon completion. The actual code chunk is a small wrapper around openclaw gateway call wake (or a legacy fallback) that sends arbitrary text and a mode to OpenClaw, then exits. It does not launch development tasks, manage sessions, expose progress, support SSH access, or handle completion state. Its primary purpose is materially different from the declared purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs launching claude --dangerously-skip-permissions, which disables normal permission safeguards for subsequent coding actions. In a skill designed to run arbitrary development tasks in a user workdir, this materially increases the risk of unauthorized file changes, command execution, secret exposure, and destructive actions without user-facing warning or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script starts Claude with --dangerously-skip-permissions, explicitly disabling approval and permission safeguards for an agent that is then instructed to perform coding tasks in a real working directory. In this skill context, that materially increases the chance of unauthorized file changes, command execution, secret exposure, or destructive actions, especially because the whole purpose of the skill is to launch autonomous development work in tmux sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This finding is substantively the same unsafe behavior as SDI-2: the script suppresses Claude's safety/permission controls without any explicit confirmation step or warning to the operator. In a tool designed to trigger coding work automatically and remotely, hiding the reduction in safety controls makes accidental misuse and high-impact agent actions significantly more likely.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill clearly directs shell execution through multiple local scripts, but it declares no explicit tool scope or permissions boundary. That creates ambiguous authority and weakens review controls, increasing the chance that an agent can execute commands in contexts the user did not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger text is broad enough to match routine coding requests, which could cause the skill to activate in situations where the user did not intend remote orchestration or shell-based task launching. Over-broad activation increases the chance of unnecessary privileged execution and reduces meaningful user consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is described as triggering Claude Code work in tmux and reporting completion, but this helper also accepts free-form --lint-cmd and --build-cmd values and executes them as shell commands. Running arbitrary commands is a broader capability than merely generating completion status and is not explicitly justified by the manifest description of progress visibility and completion callback behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script executes user-supplied command strings from --lint-cmd and --build-cmd through command substitution, which can run arbitrary shell commands in the target working directory. Although this behavior may be functional, the file itself provides no warning, confirmation, or explanatory comment that these supplied commands will be executed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script emits user-facing status and instruction text in Chinese only, including the final recommended reply format. This imposes a specific language/locale choice without offering the user an option or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest focuses on starting Claude Code work in observable tmux sessions and providing progress visibility plus completion callback. In addition to that, the script copies the reference prompt to a remote host and later instructs Claude to copy JSON/Markdown reports to a separate Mac mini via scp, which is cross-host file transfer behavior not reflected in the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated prompt content in lines L155-L184 is entirely in Chinese and instructs the downstream agent in that language, effectively imposing a locale/language choice. There is no visible opt-in, configuration, or justification indicating that this skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The user-facing output strings from L29 onward are consistently Chinese, including headings, status messages, and instructions. This imposes a specific language on all users without any opt-in or documented locale justification, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes predictable report filenames into /tmp using a session-derived name, which exposes it to symlink and clobbering issues in multi-user environments. A local attacker could pre-create a symlink at the expected path and cause the script to overwrite an arbitrary file writable by the script's user, or read sensitive build/report data from world-accessible temporary locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code creates and later updates a persistent state file under the skill directory, which is a file-write operation. Although the script has internal comments, there is no user-facing prompt, log, or explicit disclosure at the write points that local state will be created and modified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.