Back to skill

Security audit

best-skill-recommendations

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly discloses that it recommends, installs, and optionally replaces ClawHub skills only after user confirmation.

Before approving actions, review the exact skill names, versions, source, risk signals, and any proposed uninstall. Do not approve replacement of security-critical or workflow-critical skills unless you are comfortable with the impact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Self-Modification

High
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill is designed to recommend replacing existing skills and later directs the agent to uninstall old skills before installing a new one once the user confirms. Even with a confirmation gate, this creates a self-modification pathway that can remove protective or required skills, weaken the agent's security posture, or disrupt workflows if the recommendation logic is wrong, manipulated, or based on incomplete compatibility signals.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
### 4) Recommend Replace vs Coexist
Per candidate, output one decision:
- Replace existing skill(s)
- Coexist with boundaries
- Do not install

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Present the candidate list (from upstream or self-discovered), annotated with source and version.

3) Evaluate Installed Skills and Compatibility

Enumerate installed skills by running:

text
clawhub list

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · _meta.json (reported line 10)May include surrounding context.

json
"requires": {
    "binaries": ["clawhub"],
    "auth": "Run 'clawhub login' before use. Credentials are stored by the clawhub CLI in its default config path. No environment variables are required by this skill.",
    "permissions": ["read installed skill list via 'clawhub list'", "install/uninstall skills via 'clawhub install/uninstall' (only with explicit user confirmation)"]
  },
  "tags": [
    "skill-store",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file title includes 'ClawHub 版' and the document begins with a Chinese-only introduction before later providing English, which suggests a locale-specific variant. The skill does not explicitly state that language is optional or user-selectable, nor does it justify a required locale constraint, so it may conflict with language-choice policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.