Back to skill

Security audit

EngageLab Omni Connect

Security checks for vulnerabilities and agentic risk

Overview

The EngageLab messaging skill is mostly coherent, but the package also contains an unrelated ClawHub package-management skill with broad install, update, force-update, and publish authority.

Review this package carefully before installing. The EngageLab messaging capability requires real provider credentials and can send SMS, WhatsApp, and email messages or change/delete templates. More importantly, the package contains an extra ClawHub skill-management component that can install, update, force-update, and publish skills; install only if you intended to grant that broader package-management authority.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
clawhub 2/SKILL.md:19
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: clawhub 2/SKILL.md, lines 19–29
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

yaml
"package": "clawhub",
"bins": ["clawhub"],
"label": "Install ClawHub CLI (npm)",
bash
npm i -g clawhub

Technical Analysis

The skill instructs users to install the clawhub npm package globally without specifying an exact version or validating its integrity or provenance. Consequently, the installed artifact is whichever version the npm registry resolves at installation time, rather than a version that was fixed and audited alongside the skill.

npm installations may execute package lifecycle scripts, such as preinstall, install, and postinstall. If the package or a transitive dependency is compromised, a malicious release could execute code during installation. The global installation option also places package files and executable shims into a shared tool location, increasing the installation's effect beyond the current project.

This finding does not establish that the current clawhub package is malicious. The vulnerability is the unsafe, mutable dependency-installation practice and the resulting supply-chain exposure.

Attack Path

  1. An attacker compromises the npm publisher account, package distribution process, or a resolved dependency and publishes a malicious release.
  2. A user or agent follows the skill instruction and runs npm i -g clawhub.
  3. npm resolves and downloads the attacker-controlled release because no exact version or integrity value is specified.
  4. Malicious lifecycle scripts execute with the privileges of the account running npm.
  5. The package can modify files available to that account, access its environment and credentials, and install or replace globally exposed command shims.
  6. Subsequent invocations of the globally installed clawhub executable may run attacker-controlled l ...[truncated 543 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package to a reviewed exact version, for example:
    bash
    npm install --global clawhub@<audited-exact-version>
    
  2. Record and verify the expected package integrity digest and validate package provenance before installation.
  3. Prefer a project-local, lockfile-controlled installation rather than a global installation where practical.
  4. Review the pinned release, its transitive dependencies, and all npm lifecycle scripts before approval.
  5. Disable lifecycle scripts during installation with --ignore-scripts when the package does not require them.
  6. Run installation as an unprivileged account and do not use sudo or an administrative shell.
  7. Establish an update process in which new versions are reviewed and integrity-checked before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown documents a DELETE operation that removes a WhatsApp template across all language versions, which is a destructive action. The surrounding skill description provides no warning, confirmation guidance, or cautionary note about irreversible impact on existing templates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The publish instructions show how to upload a local skill directory to a remote registry but do not warn that local files, metadata, and possibly sensitive embedded content may be transmitted externally. In a tool designed to publish packages, omission of an explicit data-transfer warning can cause accidental disclosure of proprietary code, secrets, or internal metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly includes --all --no-input --force update commands that can overwrite or upgrade installed skills non-interactively, increasing the chance of unintended changes at scale. In a skill/package management context, encouraging forceful unattended updates without prominent warnings or safer alternatives can lead to integrity, compatibility, or supply-chain risk if a bad or unexpected version is pulled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The WhatsApp template response example hard-codes the language as zh_CN, which can imply a default or expected locale in the skill guidance. The document does not state that language should be selected based on user preference or region, nor does it explain any justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.