Back to skill

Security audit

Blue Collar Mental Health

Security checks for vulnerabilities and agentic risk

Overview

This is a mental health guidance skill with no embedded code or hidden behavior, but its install command and declared filesystem access deserve ordinary caution.

Before installing, consider using a least-privileged or sandboxed environment and confirm the ClawHub installer source/version if your machine has sensitive files or credentials. Treat the skill as supportive guidance, not a replacement for licensed care or emergency services.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Package Execution During Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

yaml
install: "npx clawhub install howtousehumans/blue-collar-mental-health"

Technical Analysis

The documented installation command invokes clawhub through npx without specifying an exact package version or integrity hash. If the package is not already available locally, npx can retrieve and execute the currently resolved version from the configured npm registry.

Consequently, the code executed during installation is mutable and falls outside the reviewed artifact. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could cause arbitrary package CLI or lifecycle code to run when a user follows this instruction.

The finding is limited to the unpinned npx dependency. The reviewed project itself contains only SKILL.md; no embedded scripts, malicious payloads, persistence mechanisms, credential access, or data-exfiltration behavior were found.

Attack Path

  1. An attacker compromises the upstream clawhub package, its publisher account, or the package-distribution channel.
  2. The attacker publishes a malicious version under the package name resolved by npx.
  3. A user follows the installation command from SKILL.md.
  4. npx resolves and downloads the mutable package version.
  5. The malicious package CLI or applicable lifecycle code executes with the privileges of the user running the command.
  6. That code can perform actions permitted to the installation process, potentially including reading user-accessible files, modifying local files, accessing available environment variables, or installing additional payloads.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope is bounded ...[truncated 508 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed version rather than allowing npx to resolve the latest release.
  2. Use a lockfile or other immutable dependency manifest where the installation mechanism supports it.
  3. Verify package integrity using registry-provided integrity metadata, checksums, signatures, or provenance attestations.
  4. Retrieve dependencies only from an approved and authenticated registry.
  5. Review the resolved package, transitive dependencies, CLI entry point, and lifecycle scripts before execution.
  6. Prefer a download-and-verify workflow that separates package retrieval from execution.
  7. Run installation with the least-privileged account in a sandbox or isolated environment, without unnecessary credentials or sensitive environment variables.
  8. Disable dependency lifecycle scripts where feasible and not required.
  9. Document the expected publisher, version, checksum, and verification procedure alongside the installation command.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install command uses npx clawhub install howtousehumans/blue-collar-mental-health without pinning a specific version of the package or tool, so execution will resolve to whatever version is current at install time. That creates a supply-chain risk: if the package, a dependency, or the publishing account is compromised, users could execute unreviewed code simply by installing the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.