Back to skill

Security audit

Skill Distill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent project-to-skill packaging helper, but it can expose real secrets in scan output and can write scaffolded files outside the intended directory.

Use this only on project directories you are prepared to expose in terminal or agent logs until scan output is redacted. Avoid scanning real .env files with live credentials, use a simple skill name with no slashes or path components, inspect the scaffolded directory manually, and require explicit confirmation before running clawhub publish.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scan.sh:29
Finding

Detected secrets are disclosed verbatim in scanner output

Content
View full analysis

Vulnerability Details

File Location: scripts/scan.sh, lines 29–38; additional affected output logic at lines 75–79
Vulnerability Type: Sensitive information exposure through diagnostic output
Risk Level: High

Vulnerable Code:

bash
scan_pattern() {
  local label="$1" pattern="$2" risk="$3"
  while IFS= read -r line; do
    local file="${line%%:*}"
    [[ "$(realpath "$file")" == "$SELF_PATH" ]] && continue
    echo "${line}:${risk}  # ${label}"
    FOUND=1
  done < <(grep -rnI --include='*' -E "$pattern" "$TARGET_DIR" \
    --exclude-dir='.git' --exclude-dir='node_modules' \
    --exclude-dir='__pycache__' --exclude-dir='.venv' \
    --exclude='*.png' --exclude='*.jpg' --exclude='*.ico' \
    2>/dev/null || true)
}

The same issue occurs when scanning environment files:

bash
while IFS= read -r envfile; do
  while IFS= read -r line; do
    echo "${line}:HIGH  # env-secret"
    FOUND=1
  done < <(grep -nE '^[A-Z_]+\s*=\s*.+' "$envfile" \
    | grep -ivE '=(true|false|[0-9]+|""|'\'''\''|\$\{)' 2>/dev/null || true)
done < <(find "$TARGET_DIR" -maxdepth 3 -name '.env*' -not -name '.env.example' \
  -not -path '*/.git/*' 2>/dev/null || true)

Technical Analysis

The scanner uses grep -n or grep -rnI, both of which return the entire matching source line. The resulting line is then emitted directly with echo. When the match is an API key, password assignment, access token, or environment variable, the sensitive value itself is therefore copied into standard output.

This violates secure secret-handling principles because a detection tool should report secret metadata without reproducing the secret. Standard output may be retained in CI logs, terminal capture systems, Agent conversation transcripts, or other audit artifacts. The environment-file branch is especially broad because it prints complete nontrivial assignments from ...[truncated 1185 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not print the complete matching line. Report only the file path, line number, finding label, and severity.
  • Use grep -l or process matches so that sensitive values are replaced with a constant such as [REDACTED].
  • For .env files, parse only variable names and emit output such as path:line:VARIABLE_NAME:[REDACTED].
  • Ensure partial masking cannot expose short secrets or enough characters to reconstruct them.
  • Document that scanner output must be treated as potentially sensitive until the redaction fix is deployed.
  • Add automated tests containing synthetic credentials and verify that no credential value appears in standard output or standard error.
  • Consider restrictive handling for generated reports, including limited file permissions and disabled CI artifact retention where practical.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scaffold.sh:18
Finding

Unvalidated skill name allows destination path traversal

Content
View full analysis

Vulnerability Details

File Location: scripts/scaffold.sh, lines 18–38
Vulnerability Type: Filesystem path traversal and unintended directory write
Risk Level: Medium

Vulnerable Code:

bash
[[ $# -lt 2 ]] && usage
SRC_DIR="$1"
SKILL_NAME="$2"
[[ ! -d "$SRC_DIR" ]] && echo "ERROR: '$SRC_DIR' is not a directory" && exit 1

DEST_DIR="./${SKILL_NAME}"
if [[ -d "$DEST_DIR" ]]; then
  echo "ERROR: '$DEST_DIR' already exists" && exit 1
fi

echo "Scaffolding skill '$SKILL_NAME' from $SRC_DIR ..."

mkdir -p "$DEST_DIR"/{scripts,references}

# Copy core files, excluding noise
rsync -a --exclude='.git' --exclude='node_modules' \
  --exclude='.env' --exclude='.env.*' \
  --exclude='logs/' --exclude='*.log' \
  --exclude='__pycache__' --exclude='.venv' \
  --exclude='.DS_Store' --exclude='Thumbs.db' \
  --exclude='dist/' --exclude='build/' \
  --exclude='.towow/' --exclude='.wow-harness/' \
  "$SRC_DIR/" "$DEST_DIR/"

Technical Analysis

SKILL_NAME is used directly to construct DEST_DIR without being constrained to a simple directory name. Quoting prevents shell command injection, but it does not prevent filesystem traversal. A value containing ../ is resolved by the operating system outside the current working directory.

The script subsequently passes this path to mkdir, rsync, file creation, copying, and deletion operations. The existing-directory check limits overwriting of an already existing destination directory, but it does not stop creation and population of a new directory at an unintended writable location.

Attack Path

  1. An attacker influences the second argument supplied to scaffold.sh, or a user mistakenly treats an untrusted project name as a safe skill name.
  2. The supplied value contains traversal components, for example ../../unintended-skill.
  3. The script constructs DEST_DIR as ./../../unintended-skill.

...[truncated 1238 chars]

Remediation
View remediation

Remediation Suggestions

  • Validate SKILL_NAME against a strict basename policy before using it, for example ^[a-z0-9][a-z0-9-]{0,63}$.
  • Explicitly reject absolute paths, /, backslashes, . and .. path components, control characters, and empty values.
  • Define an explicit output root instead of implicitly using the current working directory.
  • Resolve the output root and candidate destination to canonical paths, then verify that the destination remains a direct child of the output root.
  • Fail safely if canonicalization is unavailable or the containment check does not pass.
  • Consider creating the destination with mkdir without -p after validating its parent, reducing accidental creation of arbitrary parent paths.
  • Add regression tests using names such as ../outside, ../../outside, /tmp/outside, ., and names containing path separators.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code aligns with the 'scaffold standard structure' portion of the description: it creates a destination skill directory, copies project contents while excluding common noise and sensitive env files, generates SKILL.md, and adds a checklist reference. However, the declared purpose materially overstates the behavior by claiming scanning for hardcoded paths and secrets and validation before publishing. None of those actions occur in this script; they are only referenced as next steps. Therefore the description does not accurately represent what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The declared description presents a broader skill-packaging tool that can distill or generalize an existing project into a publishable skill, including scaffolding standard structure. The supplied code chunk does not perform conversion, scaffolding, extraction, or packaging; it strictly validates a provided skill directory against publication rules and calls a separate scan script. It also enforces a specific English-only metadata policy not mentioned in the description. While validation and scanning align partially with the description, the primary behavior of this code chunk is narrower and materially different from the declared end-to-end project-to-skill transformation purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/checklist.md (reported line 13)May include surrounding context.

md
## 2. 敏感信息清除
- [ ] 无 API key / token(sk-、ghp_、xoxb-、AKIA 等)
- [ ] 无 password/secret 赋值
- [ ] 无 .env 文件含真实值
- [ ] 无本地用户名引用

## 3. 依赖声明完整性

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan.sh (reported line 14)May include surrounding context.

sh
## 2. 敏感信息清除
- [ ] 无 API key / token(sk-、ghp_、xoxb-、AKIA 等)
- [ ] 无 password/secret 赋值
- [ ] 无 .env 文件含真实值
- [ ] 无本地用户名引用

## 3. 依赖声明完整性

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan.sh (reported line 75)May include surrounding context.

sh
## 2. 敏感信息清除
- [ ] 无 API key / token(sk-、ghp_、xoxb-、AKIA 等)
- [ ] 无 password/secret 赋值
- [ ] 无 .env 文件含真实值
- [ ] 无本地用户名引用

## 3. 依赖声明完整性

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scaffold.sh (reported line 35)May include surrounding context.

sh
# Copy core files, excluding noise
rsync -a --exclude='.git' --exclude='node_modules' \
  --exclude='.env' --exclude='.env.*' \
  --exclude='logs/' --exclude='*.log' \
  --exclude='__pycache__' --exclude='.venv' \
  --exclude='.DS_Store' --exclude='Thumbs.db' \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/scaffold.sh (reported line 82)May include surrounding context.

sh
fi

# Remove .git if rsync somehow included it
rm -rf "$DEST_DIR/.git"

echo ""
echo "Done. Skill scaffolded at: $DEST_DIR"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The text states that frontmatter name/description must be fully English and treats Chinese characters as invalid, which imposes a language restriction. The file does not present this as a user choice or explain a region-specific compliance reason beyond a platform requirement, so it appears to be a natural-language locale policy constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow instructs the agent to publish to an external service without an explicit user warning or confirmation checkpoint. In the context of a skill that processes local projects and may still contain residual proprietary content, this increases the risk of accidental disclosure of source code, secrets, or internal metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The checklist imposes an English-only requirement for frontmatter without any user consent, compatibility rationale, or documented necessity. This is a policy-level restriction rather than code execution, but it can cause exclusionary behavior, metadata loss, or forced transformation of user-authored content in ways that may violate localization or publishing expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comment and failure message state that SKILL.md frontmatter must be English-only and explicitly fail when Chinese characters are present. This is a natural-language locale policy constraint applied unconditionally, with no user choice or clearly documented region-specific compliance basis in the file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes scanning projects for hardcoded paths, secrets, and local traces, but this implementation also inspects the runtime environment via USER and uses it as scan input. Reading host environment variables is not an obvious requirement for packaging or publishability validation, especially when the manifest does not mention environment access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.