Back to skill

Security audit

mathematical audit skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an offline code analyzer, but it repeatedly promises read-only behavior while its CLI can overwrite a user-specified output file.

Review this carefully before installing. It appears offline and focused on Python code analysis, but do not treat it as read-only: avoid using `--output` on existing or sensitive paths, prefer stdout, and run it in a workspace where overwriting a writable file would not cause damage.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.py:2908
Finding

Unrestricted Report Output Can Overwrite Arbitrary Writable Files

Content
View full analysis

Vulnerability Details

File Location:

  • skill.py:2908, 2944-2948
  • release_v3.6.1/skill.py:2908, 2944-2948

Vulnerability Type: Unrestricted file overwrite through a user-controlled output path
Risk Level: Medium

Vulnerable Code

python
parser.add_argument('--output', '-o', help='Output file path')
python
if args.output:
    Path(args.output).write_text(report, encoding='utf-8')
    print(f"\nReport saved to: {args.output}")
else:
    print(report)

The same implementation is present in both the active source file and the bundled release copy.

Technical Analysis

The --output argument accepts an unrestricted filesystem path. That value is passed directly to Path.write_text(), which opens the destination for writing and truncates an existing file before replacing its contents with the generated report.

The implementation does not:

  • Restrict reports to a dedicated output directory.
  • Reject absolute paths or parent-directory traversal.
  • Check whether the destination already exists.
  • Reject symbolic links.
  • Use exclusive file creation.
  • Request confirmation before overwriting a file.

Consequently, anyone who can control or influence the command-line arguments can replace any file writable by the Skill process. This behavior also contradicts the package's repeated security guarantee that analysis is read-only and cannot write or modify files.

Attack Path

  1. An attacker controls or influences the invocation of the Skill, directly or through an automation wrapper.
  2. The attacker supplies the path of an existing writable file through --output, for example a project configuration or source file.
  3. The Skill completes its analysis and enters the if args.output branch.
  4. Path.write_text() truncates the selected file and replaces it with report data.
  5. The affected application or project may subsequently fail, use corrupted configuration, ...[truncated 834 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove filesystem output for strict read-only operation

    • Remove the --output option.
    • Emit console or JSON reports exclusively through standard output.
    • Let a trusted caller handle redirection when persistence is explicitly required.
  2. If report files are required, constrain the destination

    • Use a dedicated report directory controlled by the application.
    • Resolve and validate the destination with Path.resolve().
    • Verify that the resolved path remains inside the approved directory.
    • Reject absolute user-supplied paths and parent-directory traversal.
  3. Prevent unintended replacement

    • Create reports using exclusive creation mode, such as open(path, "x", encoding="utf-8").
    • Reject destinations that already exist unless an explicit, documented overwrite option is supplied.
    • Require interactive confirmation where appropriate.
  4. Defend against symbolic-link attacks

    • Reject symbolic-link destinations and validate relevant parent directories.
    • Where supported, use operating-system primitives that prevent following symbolic links.
    • Avoid check-then-write sequences that introduce time-of-check/time-of-use races.
  5. Align documentation and configuration

    • If file output remains available, remove the claims that the Skill performs no file writes.
    • Clearly document the exact write behavior, destination restrictions, and overwrite policy.
    • Apply the same correction to the duplicated files under release_v3.6.1/.
  6. Add regression tests

    • Verify that existing files cannot be overwritten by default.
    • Test absolute paths, .. traversal, symbolic links, and destinations outside the approved report directory.
    • Ensure the active and bundled release implementations remain synchronized.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Hidden Instructions

High
Category
Prompt Injection
Confidence
90% confidence
Finding

The file begins with a UTF-8 BOM/invisible character, which can be used to conceal content or interfere with parsing and line-based security tooling. In this skill's context, the changelog also contains multiple trust-seeking security claims like 'expected BENIGN scan result' and 'Ready for ClawHub submission,' which increases suspicion because hidden characters can help disguise adversarial or misleading documentation.

Content

Scanner excerpt · CHANGELOG.md (reported line 1)May include surrounding context.

md
# Changelog

All notable changes to the Pure Mathematical Audit skill will be documented in this file.

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The file begins with a Unicode BOM/invisible character, which can be used to conceal content differences or interfere with parsers and security tooling. In this changelog, the risk is amplified by repeated self-attestations such as 'expected BENIGN scan result' and 'no network access,' which are adversarially relevant because they attempt to shape trust in surrounding content rather than provide verifiable security guarantees.

Content

Scanner excerpt · release_v3.6.1/CHANGELOG.md (reported line 1)May include surrounding context.

md
# Changelog

All notable changes to the Pure Mathematical Audit skill will be documented in this file.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# Pure Mathematical Audit Skill - Professional Edition

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · release_v3.6.1/SKILL.md (reported line 1)May include surrounding context.

md
# Pure Mathematical Audit Skill - Professional Edition

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Lines L025-L027 say the skill removed all Chinese characters and that all files are now '100% English' due to a platform requirement. This is natural-language locale policy that enforces a specific language rather than offering a choice, and the document does not present it as a user-selectable option or narrowly justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Lines L061-L063 include '100% English: All files in English only' under compliance language. This is a natural-language policy statement mandating a single language, with no indication of user choice or a narrowly scoped regional/compliance justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes broad auditing capabilities but does not clearly define when it should activate, what targets it may inspect, or what boundaries apply to analysis. Ambiguous invocation scope can cause over-broad access to user-supplied paths or unintended analysis of sensitive files, increasing the chance of data exposure or misuse even if the skill is nominally read-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The text states that all Chinese characters were removed and that all files are now '100% English' to satisfy a requirement. This is a natural-language locale policy constraint presented as mandatory, with no user opt-in or documented justification beyond platform compliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The compliance bullets declare '100% English: All files in English only,' which enforces a single language without offering user choice. Under the policy, forcing a specific language without opt-in is a reportable natural-language policy violation.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
?**No network calls** - Cannot access localhost or any network

?**No dynamic execution** - Cannot execute any code (no eval/exec/compile)

?**No background processes** - No daemon, no monitoring, no services

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · release_v3.6.1/SKILL.md (reported line 109)May include surrounding context.

md
?**No network calls** - Cannot access localhost or any network

?**No dynamic execution** - Cannot execute any code (no eval/exec/compile)

?**No background processes** - No daemon, no monitoring, no services

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The text states that skill files 'must not contain any Chinese characters' and that all descriptions, comments, and documentation must be in English. This is a natural-language locale policy constraint that forces a specific language without any opt-in, alternative, or region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The phrase "DO NOT USE" is an imperative English-language instruction embedded in the skill documentation. Under the policy provided, only natural-language locale or language constraints should be flagged, and this file otherwise does not impose a language/locale requirement. Therefore no confident policy violation is present here, but if interpreted as mandatory English-only instruction it could raise a weak concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The release metadata includes 'English Compliance: 100% English files,' reiterating a mandatory single-language stance. This continues the same language-policy issue by presenting English-only content as a compliance requirement without opt-in or contextual justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This Python skill performs a file write via Path(args.output).write_text(report, encoding='utf-8') when --output is provided. Although the CLI argument name implies output generation, the write operation itself has no adjacent confirmation, print-before-action notice, or explicit warning comment/docstring describing that the skill will create or overwrite the target file.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

With no manifest available, the only stated intent comes from the code/docs describing a mathematical code analyzer. The recursive directory-wide traversal via rglob("*.py") expands the capability from analyzing provided content or a single file to bulk inspection of all Python files under a path, which is a broader capability not independently justified by any declared skill scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.