Back to skill

Security audit

Clawlendar

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent calendar-conversion skill, but users should install its external MCP package cautiously because the recommended pip command is not version-pinned.

Before installing, prefer a pinned reviewed version of clawlendar and its dependencies, inspect the package source, and run the MCP server with only the filesystem and network access it needs. The skill itself does not show malicious behavior, but the install path depends on external package integrity.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned Third-Party Package Installed and Registered as an MCP Server

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 37–44
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

bash
python3 -m pip install -U "clawlendar[all]"
clawlendar

One-line registration in Claude Code:

bash
python3 -m pip install -U "clawlendar[all]" && claude mcp add clawlendar -- clawlendar

Technical Analysis

The documented installation command uses pip install -U without an exact version constraint, integrity hashes, or a reviewed lockfile. It therefore installs the latest available release of clawlendar and the dependencies included through its all extra. The effective code can change after this skill has been audited.

The second command immediately registers the externally installed clawlendar executable as an MCP server. An MCP server can receive requests from the agent and execute with the permissions of the user who launched it. The submitted artifact contains only SKILL.md; it does not contain the package implementation, dependency metadata, or executable source needed to verify filesystem, network, subprocess, and request-handling behavior.

No malicious package behavior is demonstrated by the submitted file. The risk arises from the unpinned and unauditable supply-chain execution path.

Attack Path

  1. An attacker compromises a future clawlendar release or one of the dependencies installed by the all extra.
  2. A user follows the documented command, and -U resolves the compromised release because no exact version or hash is enforced.
  3. Package installation or subsequent executable startup runs attacker-controlled code under the installing user's account.
  4. The command registers that executable as an MCP server.
  5. Future agent requests invoke or communicate with the compromised server, allowing its code to act within the operating-system permissions and accessible environment of that user.

Impact Assessment

Successful exploitation could execute arbitrar ...[truncated 556 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the unconstrained upgrade with an exact, reviewed version, such as clawlendar[all]==X.Y.Z.
  2. Require package hashes through a locked requirements file and install with pip --require-hashes.
  3. Lock and audit all transitive dependencies, including dependencies introduced by the all extra.
  4. Avoid installing unnecessary optional dependencies; document and install only the extras required for the intended deployment.
  5. Include the corresponding implementation and dependency manifests in the reviewed artifact, or provide a reproducible source-to-package verification process.
  6. Separate installation from MCP registration so users can inspect and verify the installed executable before granting agent access.
  7. Run the MCP server in a restricted environment with minimal filesystem access, sanitized environment variables, constrained network access, and no elevated privileges.
  8. Document the server's required permissions and expected network, filesystem, and subprocess behavior.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L028 instructs agents to always pass locale and lists only en, zh-CN, and zh-TW as supported values for user-facing text. This is a natural-language locale policy concern because the skill appears to force a narrow set of languages/locales rather than presenting locale selection as user-driven or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.