Back to skill

Security audit

Clarity 认知引擎

Security checks for vulnerabilities and agentic risk

Overview

This skill is not proven malicious, but it substantially under-discloses persistent agent integration, broad memory behavior, external LLM forwarding, and unsafe host code execution capabilities.

Treat this as a Review install. Do not run install.sh or enable the MCP integration in a sensitive environment unless you are comfortable with persistent Claude configuration changes, local memory/state files, and possible external LLM forwarding when environment variables are set. The maintainer should remove or strongly gate host code execution, correct the dependency and persistence claims, require explicit opt-in for external calls and MCP registration, and provide a clear uninstall/rollback path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:382
Finding

Session-Wide Instruction and Output Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/core/intent-layer.js:132
Finding

Conversation Disclosure to an Arbitrary LLM Endpoint

Content
View full analysis
0 ? conversationHistory.slice(-5).map((msg, i) => `${i + 1}. ${msg.role || 'user'}: ${msg.content || msg}` ).join('\n') : '(no conversation history)'; return INTENT_PROMPT_TEMPLATE .replace('{userMessage}', userMessage) .replace('{conversationHistory}', historyText); } ``` The placeholder shown as `(no conversation history)` is translated from the original source comment-facing text; the executable behavior is unchanged. ### Technical Analysis When `LLM_ENDPOINT` is set, the module constructs a prompt containing the current user message and up to five previous conversation messages. It then sends the complete prompt to the configured endpoint with `LLM_API_KEY` in a Bearer authorization header. The endpoint is accepted directly from the environment without: - An HTTPS requirement - A hostname or provider allowlist - Certificate or endpoint pinning ...[truncated 1431 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/core/code/code-executor.js:233
Finding

Allowlisted Host Code Execution Without Effective Sandboxing

Content
View full analysis
{ const { timeout = DEFAULT_STEP_TIMEOUT, cwd = process.cwd(), maxMemoryMB = 512 } = options; const proc = spawn(command, args, { cwd, env: { ...process.env, NODE_ENV: 'production' }, stdio: ['pipe', 'pipe', 'pipe'], detached: false, }); ``` ```js async execute(code, language, options = {}) { // Security warning: execute() does not provide sandbox isolation; // it only performs blacklist checks. if (!options.silentDeprecation) { console.warn( '[CodeExecutor] Warning: execute() has no sandbox isolation; use sandbox() instead' ); } // ... const securityResult = securityCheck(code); if (!securityResult.safe) { return this._createErrorResult( `Security check failed: ${securityResult.reason}`, -1 ); } ``` ```js async sandbox(code, language, options = {}) { const sandboxOptions = { ...options, syntaxCheck: true, stepTimeout: options.stepTimeout || Math.min(this.stepTimeout, 3000), totalTimeout: options.totalTimeout || Math.min(this.totalTimeout, 10000), retryOnError: false, useCache: false, incremental: false }; const securityResult = securityCheck(code); if (!securityResult.safe) { return this._createErrorResult( `Sandbox security check failed: ${securityResult.reason}`, -1 ); } // Network and filesystem restrictions are implemented as regex checks. return this.execute(code, language, sandboxOption ...[truncated 3030 chars]
Remediation
View remediation

T06 · System Persistence

Error
Location
install.sh:146
Finding

Persistent Modification of Claude Configuration and Global Command Path

Content
View full analysis
/dev/null; then if [ ! -f "$HOME/bin/hf" ]; then ln -sf "$HF_CLI" "$HOME/bin/hf" 2>/dev/null fi fi ``` The repository simultaneously states that the packaged version has no background process, no side effects, no self-modification, and no external communication. ### Technical Analysis The installer writes an MCP server registration into Claude's persistent `settings.json`. That registration causes future Claude sessions to invoke a Node.js wrapper from the Skill directory. It also creates a symlink under `~/bin`, making a Skill-provided command globally reachable through the user's command path. These are persistent host changes, not temporary effects of a single Skill invocation. The script can choose `/etc/claude` if that location contains a settings file and the installer has permission to modify it. The audited directory listing does not contain the referenced `daemon/mcp-wrapper.js` or `bin/hf`. Consequently, the installer may save persistent configuration pointing to missing files. This can break future MCP startup and creates an unsafe update boundary if those paths are later popul ...[truncated 1349 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:57
Finding

Misleading Zero-Dependency Claim Conceals Third-Party Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (770)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

This module provides arbitrary code compilation/execution across multiple languages via child processes, which is a high-risk primitive. In the context of a skill presented as a cognition engine, that hidden capability is especially dangerous because it enables command execution, local file access, and abuse of host-installed toolchains with only weak regex-based filtering.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document makes a strong safety claim of 'no background process' while other sections explicitly describe an automatically launched, resident MCP daemon and wrapper process. This kind of contradiction can mislead operators into approving or running software under false assumptions about persistence and runtime behavior, which is a real security transparency issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Claiming the system is a 'pure cognitive engine' with 'no side effects' is inconsistent with documented daemon startup and persistent memory layers. This is dangerous because users may treat the skill as read-only or ephemeral when it can create state and keep resident processes, affecting trust, auditability, and deployment decisions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as a cognitive/memory/emotion engine, while the described runtime behaviors include local file reads/writes, bootstrapping, health checks, cache handling, daemon/process management, and configuration changes. That description-behavior gap is dangerous because it can cause users and orchestrators to approve a high-privilege tool under misleading assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/ensure-mcp.js:84

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code/code-engine.js:68

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code/code-executor.js:246

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/code/code-verifier.js:99

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/core/code/code-engine.js:1586

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core/code/code-planner.js:1665

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core/intent-layer.js:56

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/core/search/hybrid-search.js:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/core/code/code-planner.js:1745

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/core/search/hybrid-search.js:421