Back to skill

Security audit

TOSR Publish Then Update Test

Security checks for vulnerabilities and agentic risk

Overview

This is a transparent lifecycle-test skill that describes real ClawHub publish, update, inspect, and cleanup behavior for a fixed ephemeral test skill.

Install or run this only in a ClawHub test context where creating, updating, and deleting the named ephemeral skill is acceptable. Do not use it with production credentials unless you intend those lifecycle changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The skill advertises a DELETE operation parameterized by a slug, which is a classic dangerous capability because the target resource can be selected dynamically. In context, this is somewhat mitigated by the test-oriented description and fixed test slug, but it remains a real vulnerability pattern if the slug is not strictly constrained, since misuse could delete unintended remote resources.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data
2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug}
3. **Update** — Publishes a new version of an existing skill
4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug}

## Notes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes creating, updating, and deleting real remote resources through the live clawhub API, but it does not provide a clear user-facing warning that execution will modify external state. This creates a real safety issue because an operator or downstream agent could invoke it without understanding that it performs destructive actions against production-like resources.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The statement that the skill will be 'automatically deleted after the test completes' indicates autonomous destructive behavior without any mention of approval gates or confirmation. Even if intended for cleanup, autonomous deletion against a real API increases risk because an agent may perform state-changing actions without user awareness or review.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
## Notes

This skill is ephemeral and will be automatically deleted after the test completes.
If you see this skill listed on clawhub, it means a test run failed to clean up properly.

Static analysis

No suspicious patterns detected.