Back to skill

Security audit

Anxiety Emergency

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly anxiety-support guidance, but it asks for calendar and filesystem access and uses an unpinned installer even though those are not needed for its stated purpose.

Review before installing. The anxiety guidance itself is purpose-aligned, but the package should remove calendar/filesystem requirements or clearly justify and scope them, and the installer should pin a reviewed `clawhub` version. Install only from a trusted source and avoid granting file or calendar access unless a specific user-approved feature needs it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install howtousehumans/anxiety-emergency"

Technical Analysis

The installation command invokes clawhub through npx without specifying an audited package version or integrity digest. When the package is not already available locally, npx can retrieve executable package content from the configured package registry. Because the resolved version is mutable, the code executed at installation time may differ from the code available when this skill was reviewed.

This creates a supply-chain trust boundary: compromise of the package publisher, registry account, package contents, or dependency resolution path could turn the documented installation command into a code-execution vector. The audited project itself contains no embedded malicious script, so exploitation depends on compromise or unexpected modification of the external package source.

Attack Path

  1. An attacker compromises the package publisher, registry account, package distribution channel, or a dependency resolved by the unpinned clawhub package.
  2. The attacker publishes a malicious or modified version that remains eligible for default npx resolution.
  3. A user runs the installation command from SKILL.md.
  4. npx downloads and executes the externally supplied package version.
  5. Malicious package lifecycle or application code executes with the privileges of the user running the command.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, network resources, and other capabilities available to that account. Elevated system-level impact would require the command to be run with ...[truncated 68 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specific, reviewed version rather than relying on default registry resolution.
  • Use a lockfile where supported to pin transitive dependencies.
  • Verify package integrity using a trusted digest, signature, or package provenance mechanism.
  • Obtain the package only from an authenticated and approved registry.
  • Review package lifecycle scripts and install behavior before deployment.
  • Run installation as an unprivileged user in a sandbox or otherwise restricted environment.
  • Establish an update process that requires security review before changing the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Unnecessary Calendar and Filesystem Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-15
Vulnerability Type: Excessive tool permissions that violate least privilege
Risk Level: Medium

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [calendar, filesystem]
  install: "npx clawhub install howtousehumans/anxiety-emergency"

Technical Analysis

The skill declares access to both calendar and filesystem, but its documented behavior consists of conversational anxiety-management guidance, crisis screening, grounding exercises, and resource referrals. No instruction in the reviewed file requires reading or modifying calendar data or filesystem content.

These unnecessary capabilities expand the authority available to the skill beyond its legitimate functional requirements. The declaration does not itself prove that either tool is invoked, and the reviewed project contains no instruction that actively accesses user data. Nevertheless, if the runtime automatically grants declared tools, a future compromised version, injected instruction, or unintended agent action would have access to capabilities that should not be available to this task.

Attack Path

  1. The host runtime installs or loads the skill and grants the declared calendar and filesystem tools.
  2. The skill session is subsequently affected by malicious instructions, a compromised update, or another instruction-manipulation vector.
  3. The malicious instructions invoke one or both unnecessarily authorized tools.
  4. Subject to the host tool's own access controls, the agent reads or modifies accessible files or calendar records.
  5. Retrieved information could then be exposed through agent output or used to perform unauthorized changes.

Impact Assessment

Potential impact is limited by the actual permissions and safeguards implemented by the host runtime. If broadly scoped, filesystem access could expose or alter user-accessible documents, configuration file ...[truncated 296 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove both tool requirements because the documented skill workflow does not use them:
    yaml
    openclaw:
      requires:
        tools: []
    
  • If a future feature requires a tool, grant only that specific capability and restrict it to the minimum necessary operations and resources.
  • Require explicit, informed user approval before accessing files or calendar records.
  • Configure filesystem access with path allowlists and read-only access unless modification is essential.
  • Configure calendar access with minimal scopes, preferring event availability over full event details where possible.
  • Ensure the host runtime does not automatically grant sensitive capabilities solely because they are declared in skill metadata.
  • Log and visibly disclose sensitive tool invocations so users can identify unauthorized access attempts.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requests calendar and filesystem tools even though the documented anxiety-support workflow does not require either capability. Overbroad tool access violates least privilege and could enable unnecessary access to sensitive user data or local files if the skill is invoked or later modified to use those tools in ways unrelated to mental-health support.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The install command uses npx clawhub without pinning a specific version, which can pull whatever package version is current at execution time. That creates a supply-chain risk: a compromised or breaking upstream release could execute unexpected code during installation, and the crisis-support context increases concern because users may install or rely on this skill quickly without careful review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.