Back to skill

Security audit

TOSR Publish Then Update Test

Security checks for vulnerabilities and agentic risk

Overview

This is a clearly labeled lifecycle test skill that discloses creating, updating, and deleting its own test skill through the real ClawHub API.

Install or run this only if you intend to participate in a ClawHub lifecycle test. Use credentials limited to test resources, verify the slug before cleanup, and avoid running it against production resources you cannot recreate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Documenting and invoking DELETE /api/v1/skills/{slug} creates a direct destructive capability, and the skill context shows it is part of an automated workflow against the real API. If the slug is influenced incorrectly, misbound, or executed with overly broad credentials, the skill could delete unintended resources, making this more dangerous than a purely informational reference.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data
2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug}
3. **Update** — Publishes a new version of an existing skill
4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug}

## Notes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states it performs publish, update, and delete operations against the real API, but it does not provide a clear user-facing warning about destructive behavior, production-side effects, or the need for scoped test credentials. A user or agent invoking it without realizing it targets a live service could unintentionally create, modify, or delete real resources.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The statement that the skill will be 'automatically deleted' indicates autonomous execution of a destructive action without an explicit per-run approval step. In the context of a real API, automated cleanup can remove resources unexpectedly or delete the wrong target if identifiers or environment boundaries are misconfigured.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
## Notes

This skill is ephemeral and will be automatically deleted after the test completes.
If you see this skill listed on clawhub, it means a test run failed to clean up properly.

Static analysis

No suspicious patterns detected.