Oathe Security Badge

Is skill/aleph-vm-replication safe?

Use with caution. skill/aleph-vm-replication is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the aleph-vm-replication skill by skill a trust score of 72/100 with 5 findings, none critical or high. Report updated

https://clawhub.ai/skill/aleph-vm-replication

72
CAUTION

Is skill/aleph-vm-replication safe to install?

This skill enables legitimate but high-risk autonomous AI agent replication across Aleph Cloud infrastructure. While the functionality appears to be for genuine cloud automation purposes, the recursive self-deployment capabilities and credential propagation mechanisms create significant potential for misuse.

What security issues were found in skill/aleph-vm-replication?

Category Scores

Prompt Injection 85/100 · 30%
Data Exfiltration 70/100 · 25%
Code Execution 75/100 · 20%
Clone Behavior 90/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 45/100 · 5%

Findings (5)

MEDIUM Autonomous Agent Replication System -35

This skill enables AI agents to autonomously replicate themselves across Aleph Cloud infrastructure without human oversight. The documentation explicitly states agents can 'read this SKILL.md and create new instances — recursively', which could lead to uncontrolled proliferation.

MEDIUM Sensitive Credential Propagation -30

The skill includes detailed instructions for transferring private keys, SSH keys, and API credentials between instances. While legitimate for the intended purpose, this creates pathways for credential exposure across multiple systems.

MEDIUM Resource Consumption Attack Vector -20

Uncontrolled deployment could consume significant cloud resources and financial costs. While the skill includes cost warnings, a malicious actor could exploit this for resource-based attacks or to exhaust victim's cloud credits.

LOW Extensive System-Level Code Execution -25

The skill contains numerous shell scripts and Python code that perform system administration tasks, SSH operations, and cloud API interactions. While documented and apparently legitimate, this represents significant system access.

INFO Agent Behavior Modification Instructions -15

The skill teaches agents how to modify their own deployment and replication behavior. While not traditional prompt injection, it provides instructions for autonomous operational changes.

Should I install skill/aleph-vm-replication?

Oathe's verdict for skill/aleph-vm-replication is CAUTION with a trust score of 72/100. Recommendation: Install with caution.