Back to skill

Security audit

clawhub-skill-install

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed installer helper, but it bypasses ClawHub install confirmations and keeps retrying even when a skill is flagged as suspicious.

Review carefully before installing. This skill is useful only if you intentionally want an automated ClawHub installer that can bypass prompts; do not use it for untrusted skills, suspiciously flagged packages, or cases where you need to inspect publisher, version, permissions, or warnings first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/install_skill.sh:31
Finding

Forced Installation of Security-Flagged Third-Party Skills

Content
View full analysis

Vulnerability Details

File Location: scripts/install_skill.sh:31, with security-warning retry behavior at scripts/install_skill.sh:43-47
Vulnerability Type: Supply-chain safety control bypass
Risk Level: High

Vulnerable Code

bash
OUTPUT=$(clawhub install "$SKILL_NAME" --force 2>&1)

The script also detects the flagged as suspicious warning at lines 43-47 but continues retrying rather than terminating the installation.

Technical Analysis

The installer unconditionally passes --force to clawhub install for every user-provided skill. This bypasses the package registry's confirmation or safety barrier without requiring informed user approval.

The script explicitly recognizes when a skill has been flagged as suspicious, but its response is to wait and retry. Consequently, a registry warning does not establish a fail-closed security boundary. Because ClawHub skills may contain executable scripts or agent instructions, forcibly installing an untrusted skill creates a supply-chain path through which attacker-controlled content can enter the agent environment.

The skill name is quoted correctly, so no direct shell metacharacter injection was identified through the SKILL_NAME argument. The risk instead arises from trusting and forcibly installing the selected third-party package.

Attack Path

  1. An attacker publishes, compromises, or identifies a malicious ClawHub skill.
  2. ClawHub marks the skill as suspicious or otherwise requires explicit confirmation.
  3. The attacker persuades a user or agent to invoke this installer with that skill name.
  4. The script executes clawhub install with --force, bypassing the normal confirmation barrier.
  5. If the registry returns a suspicious-package warning, the script continues retrying for up to approximately 30 minutes instead of stopping.
  6. If installation succeeds, attacker-controlled skill instructions or scripts are introduced into t ...[truncated 1074 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove unconditional use of --force and perform normal installation by default.
  2. Treat a flagged as suspicious response as a terminal security failure rather than a retryable operational error.
  3. Require explicit, interactive user approval before any override, and display the exact skill name, publisher, version, source, integrity information, warning, and requested capabilities.
  4. Do not permit an autonomous agent to approve its own security override.
  5. Restrict installations to an allowlist of reviewed publishers and skills where practical.
  6. Pin approved package versions and verify cryptographic hashes or signatures before installation.
  7. Separate transient errors, such as rate limiting, from permanent and security-related errors. Retry only well-defined transient failures.
  8. Install and inspect untrusted skills in a sandbox with minimal filesystem, process, network, credential, and tool permissions before allowing normal use.
  9. Update SKILL.md so that it no longer directs the agent to force installation or retry suspicious packages and accurately documents which failures terminate execution.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill is designed to autonomously make installation decisions by auto-confirming prompts and retrying with --force, including when a package is flagged as suspicious. In the context of installing third-party skills, this suppresses safety checkpoints and can cause an agent to install potentially malicious content without meaningful human review.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: clawhub-skill-install
description: Automatically install skills from ClawHub with retry logic. Handles rate limits (waits 10s and retries), auto-confirms prompts (--force), and stops after 30 minutes if installation fails. Use when user provides a skill name to install.
---

# ClawHub Skill 安装工具

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly performs forced, non-interactive installation actions but does not warn the user that it will bypass confirmation prompts with --force. This is dangerous because it reduces informed user consent and can lead to unreviewed installation of untrusted or suspicious skills, especially when the input skill name is user-supplied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's comments and all user-facing status/error messages are in Chinese, including usage help and failure guidance. This imposes a specific language on users without opt-in or any documented justification for a locale-specific audience, which matches the language/locale policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The main instructional content and headings are written in Chinese, while the file metadata is in English, and there is no indication that the user can choose their preferred language. This can violate a language/locale policy when a specific language is imposed without opt-in or documented regional scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.