Back to skill

Security audit

Argentina Fiscal Calendar (ARCA)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed offline Argentina tax-calendar skill with some usability and supply-chain caveats, but no evidence of hidden, destructive, credential-stealing, or exfiltration behavior.

Before installing, treat this as an offline reminder and reference aid, not legal tax advice. Avoid entering full CUITs, credentials, banking details, or third-party personal data in its local config, and verify legally binding deadlines directly with ARCA or a qualified accountant. If installing manually from git, pin a specific reviewed commit rather than copying from the current default branch.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:514
Finding

Unpinned Third-Party Skill Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:514, README.md:36, and README.md:42-43
Vulnerability Type: Unpinned dependency installation from mutable upstream sources
Risk Level: Medium

Relevant code snippets:

SKILL.md:514

bash
Instalar con: `clawhub install latam-timezone-briefing`

README.md:36

bash
clawhub install argentina-fiscal-calendar

README.md:42-43

bash
git clone https://github.com/centriqs-ai/skills.git
cp -r skills/argentina-fiscal-calendar ~/.openclaw/skills/

Technical Analysis

The documented installation commands retrieve Agent Skill content from mutable upstream sources without pinning an audited package version or Git commit. They also do not verify a cryptographic checksum or signature before installing the retrieved content.

The clawhub install commands do not specify immutable versions. The Git installation procedure clones the repository's current default branch and immediately copies its contents into the user's Skill directory. Consequently, the content installed by a user may differ from the version reviewed during this audit.

This is a supply-chain weakness rather than evidence that the currently audited files contain a malicious payload. Exploitation requires an upstream registry package, publisher account, repository, release process, or network delivery path to become compromised. The documented commands are not shown to run automatically.

Attack Path

  1. An attacker compromises an upstream publisher account, registry package, Git repository, or associated release process.
  2. The attacker publishes a modified Skill version containing malicious instructions or executable components.
  3. A user follows one of the documented unpinned installation commands.
  4. The package manager or Git retrieves the attacker-controlled current version rather than the audited revision.
  5. The content is copied into the local OpenCl ...[truncated 951 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every Skill installation to an explicit, audited release version rather than implicitly selecting the latest release.
  2. For Git-based installation, check out an immutable full commit hash before copying files:
    bash
    git clone https://github.com/centriqs-ai/skills.git
    cd skills
    git checkout --detach FULL_AUDITED_COMMIT_HASH
    cp -r argentina-fiscal-calendar ~/.openclaw/skills/
    
  3. Publish SHA-256 checksums or signed release manifests and instruct users to verify them before installation.
  4. Cryptographically sign releases and verify signatures against a documented, independently distributed publisher key.
  5. Avoid copying directly from a repository's mutable default branch into an active Skill directory.
  6. Stage downloaded content in a review directory, inspect its instructions and scripts, and activate it only after verification.
  7. Apply the same version-pinning and integrity-verification requirements to recommended related Skills.
  8. Document the exact version or commit corresponding to the security-reviewed release.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text includes very broad natural-language triggers such as 'impuesto', 'AFIP', 'qué pagar', 'esta semana' and 'este mes', which can cause the skill to activate in contexts where the user did not explicitly request fiscal-calendar help. Unintended activation can hijack unrelated conversations, increase exposure of local workspace data such as configured CUIT metadata, and lead the agent to provide authoritative-sounding tax guidance when it is not appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The behavior rules require dates to be shown "siempre en DD/MM/AAAA" and "nunca" in another format. This is a language/locale presentation constraint applied unconditionally, with no user choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.