Back to skill

Security audit

Austerity Living

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed financial hardship planning skill with proportionate reminders and state tracking, though users should review the installer and recurring reminder behavior before use.

Before installing, verify that `npx clawhub` is coming from a trusted registry or use a pinned installer if available. If you use the skill, be mindful that it may track sensitive financial state and create recurring calendar reminders; enable those only if you want them and disable them when the calls are complete.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

yaml
install: "npx clawhub install howtousehumans/austerity-living"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact reviewed version or integrity digest. If the package is not already available locally, npx may retrieve a mutable package release from the configured package registry and execute it with the privileges of the installing user.

Because the effective clawhub implementation can change after this Skill has been reviewed, the audit does not fully constrain the code that will execute during installation. Compromise of the package publisher, registry account, publication pipeline, or package distribution channel could therefore introduce malicious behavior without modifying SKILL.md.

Attack Path

  1. An attacker compromises the clawhub package publisher, release pipeline, registry account, or another relevant distribution component.
  2. The attacker publishes a malicious package release under the package identity resolved by npx clawhub.
  3. A user runs the documented installation command.
  4. npx resolves and downloads the mutable malicious release because no exact version or integrity value is specified.
  5. Package lifecycle or command code executes locally with the installing user's privileges.
  6. The malicious release can access resources available to that user, subject to operating-system and runtime restrictions.

Impact Assessment

Successful exploitation could permit arbitrary code execution in the installing user's security context. Potentially exposed resources include files readable or writable by that user, environment variables, accessible credentials, and network services available from the host.

The command does not explicitly request elevated privileges, so administrative o ...[truncated 173 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to an exact, reviewed package version rather than allowing npx to resolve the latest mutable release.
  • Use a lockfile and verified package integrity metadata where supported.
  • Verify package provenance, publisher identity, signatures, and registry source before execution.
  • Disable or carefully review dependency lifecycle scripts when they are not required.
  • Execute installation in a sandbox or least-privileged environment without unnecessary credentials or sensitive filesystem access.
  • Establish an update-review process so dependency upgrades are audited before the pinned version is changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
## Rules

- Never moralize or shame. Austerity is a response to circumstances, not a character flaw.
- Be specific about dollar amounts — "cut expenses" means nothing, "$200/month for food" means something
- Always prioritize housing and food above all debts
- Mention that food banks and assistance programs exist without making the user ask

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The install command invokes npx clawhub without pinning a specific package version, so the fetched code may change over time or be replaced by a malicious upstream release. In a skill-installation context, this creates a supply-chain risk because users may execute unreviewed code during install.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger condition any bill in tier 3 not yet negotiated is underspecified and may evaluate true repeatedly without a clear state transition or completion guard. That can cause repetitive prompting or automation churn, which is especially risky in a high-stress financial-advice skill because it may spam or pressure users unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The daily recurring schedule daily until all calls made lacks strong activation and scoping constraints, so it could trigger broadly or continue indefinitely if state is incomplete or miscomputed. In this context the main risk is notification fatigue, coercive-feeling reminders, or accidental over-automation rather than direct system compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.