Back to skill

Security audit

Skill Market Publisher

Security checks for vulnerabilities and agentic risk

Overview

This is a real marketplace publishing helper, but it needs review because some workflows run unpinned or PATH-resolved command-line tools while submitting skill data to public services.

Install only if you intend to publish skills to public marketplaces. Use a dedicated public repository or mirror, review generated bundles before live submission, avoid running the skills.sh path unless you pin and trust the skills CLI, and run publishing from a minimal environment or sandbox without unrelated credentials.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/skill_market_publish.py:1604
Finding

Unpinned npm Package Retrieval and Execution with Inherited Environment

Content
View full analysis
dict[str, Any]: try: command = build_skills_sh_command(context, args) except ValueError as exc: fail(str(exc)) if not execute: dry_run_output( "skills-sh", { "command": command, "temporary_project_directory": "created at execution time and deleted after the command exits", "source": skills_sh_source(context), "skill": context["skill"]["name"], }, ) return {"dry_run": True, "command": command} blockers = skills_sh_telemetry_blockers() if blockers: fail( "skills.sh indexing depends on anonymous skills CLI telemetry. " f"Unset these environment variables before executing: {', '.join(blockers)}" ) with tempfile.TemporaryDirectory(prefix="skills-sh-publish-") as temp_dir: temp_path = Path(temp_dir) result = subprocess.run( command, cwd=temp_path, stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True, check=False, ) temp_path_text = str(temp_path) ``` The command defaults to an unversioned npm package: ```python sub.add_argument( "--skills-sh-bin", default="npx -y skills", help="Command prefix for the skills CLI used by the skills.sh adapter", ) ``` The documentation also directs operators to use the same unpinned command: ```markdown - run `npx ...[truncated 2739 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Note
Location
scripts/skill_market_publish.py:1305
Finding

Review-Bundle Generation Executes a PATH-Resolved ClawHub Binary Without Explicit Execution Consent

Content
View full analysis
list[str]: base_command = split_command(clawhub_bin) candidates = [ (["publish"], ["publish", "--help"]), (["skill", "publish"], ["skill", "publish", "--help"]), ] for prefix, probe in candidates: try: result = subprocess.run( [*base_command, *probe], capture_output=True, text=True, timeout=10, check=False, ) except FileNotFoundError as exc: raise ValueError(f"clawhub executable not found: {clawhub_bin}") from exc except subprocess.TimeoutExpired as exc: raise ValueError(f"clawhub help probe timed out: {' '.join([*base_command, *probe])}") from exc if result.returncode == 0 and "Usage:" in (result.stdout or ""): return [*base_command, *prefix] raise ValueError("Could not detect a supported ClawHub publish command from the installed CLI help.") def build_clawhub_command(context: dict[str, Any], args: argparse.Namespace) -> list[str]: version = context["submission"]["version"] if not version: raise ValueError("clawhub requires --version.") command_prefix = detect_clawhub_publish_prefix(args.clawhub_bin) return [*command_prefix, context["skill"]["path"], "--version", version] ``` Bundle generation invokes that builder while preparing output files: ```python payload_builders = { "agent-skills-index.form.json": lambda: build_agent_skills_index_payload(context), "agent-skills-md.json": lambda: build_agent_skill ...[truncated 3057 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (44)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
python3 scripts/skill_market_publish.py recon

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
python3 scripts/skill_market_publish.py recon

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
python3 scripts/skill_market_publish.py recon

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
python3 scripts/skill_market_publish.py recon

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
Treat the publishable unit as one skill folder containing `SKILL.md`.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 168)May include surrounding context.

md
- Do not store live submission IDs, PR numbers, sample slugs, or dated field logs inside this skill.
- Put one-off execution evidence in the task conversation, a separate operator notebook, or a temporary bundle outside the reusable skill folder.
- Update this skill only when the reusable workflow changes.

## Bundled CLI

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly instructs use of scripts that perform network access, shell execution, file reads/writes, and likely environment access, yet the frontmatter declares no explicit tool scope or permission boundaries. In an agent setting, this increases the chance the skill is invoked with broader capabilities than necessary, enabling unintended publication, data leakage, or execution against live external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The operating rules state 'Keep skill content English-only unless a target market explicitly requires localized marketing copy.' This imposes a language policy by default rather than offering a user choice or clearly documenting a justified regional constraint, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This section states that anonymous submission imports every discoverable SKILL.md in a public repository, but it does not pair that behavior with a clear operator warning about unintended over-publication. In this skill context, the omission is more dangerous because the file is a procedural matrix for publishing, so operators may submit multi-skill or mixed-content repositories and accidentally expose more artifacts than intended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The document instructs use of npx -y skills without pinning a package version, which causes execution of whatever package version is current at runtime. In a publishing skill that may be run repeatedly and non-interactively, this creates supply-chain risk: a malicious or compromised future release could execute arbitrary code, collect repository data, or alter submission behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The telemetry-driven indexing flow notes that anonymous telemetry must be enabled, but it does not present this as a clear warning or consent checkpoint. That is risky in this context because the skill is designed to automate publication/discovery workflows, and operators may unknowingly disclose usage and repository metadata to a third-party telemetry system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The verification flow again relies on unpinned npx -y skills, so even a read-like discovery step executes the latest remote package code. Because this skill concerns marketplace publication and repository metadata, running an unpinned CLI increases exposure to supply-chain compromise and non-deterministic behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The playbook instructs operators to run npx -y skills add ..., which fetches and executes an unpinned package version from the npm registry. That creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking update could execute arbitrary code on the operator system during verification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command npx -y skills find <query> also relies on an unpinned npm package, so verification behavior depends on whatever version is latest at execution time. In a security-sensitive publishing workflow, this can lead to arbitrary code execution or silently altered verification results if the package is hijacked or modified upstream.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/open_manual_submit_pages.py (reported line 95)May include surrounding context.

python
def open_url(url: str) -> None:
    subprocess.run(["open", url], check=False)


def print_skill_links(skill_paths: list[str], repo_url: str | None, git_ref: str | None) -> None:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is explicitly designed to submit repository URLs, metadata, and sometimes local skill content to many external services, and also to execute external CLIs, but it provides no prominent user-facing consent or warning boundary before doing so. In a marketplace-publishing skill, hidden transmission is more dangerous because users may expect bundle generation or planning, not broad outbound sharing and local command execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/market-matrix.md (reported line 123)May include surrounding context.

md
USER_AGENT = "skill-market-publisher/1.0"
SKILLS_RE_RPC_BASE = "https://api.skills.re/rpc"
SKILLS_RE_BATCH_SIZE = 25

SKILLZ_CATEGORIES = [

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/market-matrix.md (reported line 124)May include surrounding context.

md
USER_AGENT = "skill-market-publisher/1.0"
SKILLS_RE_RPC_BASE = "https://api.skills.re/rpc"
SKILLS_RE_BATCH_SIZE = 25

SKILLZ_CATEGORIES = [

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/market-matrix.md (reported line 134)May include surrounding context.

md
USER_AGENT = "skill-market-publisher/1.0"
SKILLS_RE_RPC_BASE = "https://api.skills.re/rpc"
SKILLS_RE_BATCH_SIZE = 25

SKILLZ_CATEGORIES = [

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/verification-playbook.md (reported line 129)May include surrounding context.

md
USER_AGENT = "skill-market-publisher/1.0"
SKILLS_RE_RPC_BASE = "https://api.skills.re/rpc"
SKILLS_RE_BATCH_SIZE = 25

SKILLZ_CATEGORIES = [

Static analysis

No suspicious patterns detected.