Back to skill

Security audit

TOSR Publish Then Update Test

Security checks for vulnerabilities and agentic risk

Overview

This is a small disclosed integration-test skill for the ClawHub skill lifecycle, with no bundled executable code or hidden behavior.

Install or use this only if you understand it is meant for ClawHub API lifecycle testing. Use narrowly scoped test credentials and verify it targets the intended ephemeral slug before any publish, update, or delete operation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The skill explicitly documents a DELETE operation against a live API resource using a slug parameter. Even though the stated purpose is benign integration testing, delete capabilities are inherently risky because weak validation, overbroad permissions, or parameter substitution could allow removal of unintended skills if an agent or caller supplies the wrong slug.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
1. **Publish** — Creates a new skill via POST /api/v1/skills with multipart form data
2. **Inspect** — Retrieves skill metadata via GET /api/v1/skills/{slug}
3. **Update** — Publishes a new version of an existing skill
4. **Delete** — Removes the skill via DELETE /api/v1/skills/{slug}

## Notes

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is written as a directive in Chinese ('一句话描述该 Skill 的功能和使用场景'), which imposes a specific language despite the rest of the file being in English. This is a natural-language locale policy concern because there is no user choice, opt-in, or documented reason for requiring Chinese.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
## Notes

This skill is ephemeral and will be automatically deleted after the test completes.
If you see this skill listed on clawhub, it means a test run failed to clean up properly.

Static analysis

No suspicious patterns detected.