Back to skill

Security audit

Body Mechanics Injury Prevention

Security checks for vulnerabilities and agentic risk

Overview

The skill's advice content is coherent, but it requests unnecessary filesystem access and uses an unpinned npx installer, so users should review it before installing.

Install only if you are comfortable with the package-manager setup path and can restrict filesystem access for this skill. Treat its movement advice as general prevention guidance, not medical care; stop if symptoms worsen and consult a licensed clinician for pain, numbness, injury history, pregnancy, balance issues, or other medical limitations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Supply-chain dependency risk
Risk Level: Medium

Vulnerable Code

yaml
metadata:
  openclaw:
    requires:
      tools: [filesystem]
    install: "npx clawhub install howtousehumans/body-mechanics-injury-prevention"

Technical Analysis

The installation command invokes clawhub through npx without specifying an audited package version or integrity digest. Depending on the local environment and package cache, npx can retrieve the current package release from a configured registry and execute its CLI code.

Consequently, the code executed during installation is not immutably tied to the version reviewed in this audit. A compromised package publisher, registry account, dependency, or later malicious release could alter installation behavior after the Skill has been approved.

The reviewed Skill does not itself contain a malicious payload. The vulnerability is the mutable, unverified supply-chain execution path created by the installation instruction.

Attack Path

  1. An attacker compromises the clawhub package, one of its executable dependencies, its publisher account, or the package source used by the victim.
  2. The attacker publishes a modified version containing malicious CLI or lifecycle behavior.
  3. A user follows the documented unpinned npx clawhub install ... instruction.
  4. npx resolves and downloads the attacker-controlled release rather than a previously audited version.
  5. The package executes with the operating-system privileges of the user running the installation command.
  6. The payload can access or modify resources available to that user.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include user-readable files, writable project files, environment variables, developer credentials, and network resources available to that account. Adm ...[truncated 175 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specific, audited version rather than relying on the current registry release.
  2. Verify the package using a cryptographic integrity digest or signed provenance before execution.
  3. Use a lockfile where supported and retain it with the reviewed Skill package.
  4. Configure installation to use an explicitly trusted registry.
  5. Disable or review dependency lifecycle scripts where operationally possible.
  6. Run installation as an unprivileged user in a sandbox with minimal filesystem, credential, and network access.
  7. Establish a controlled update process in which new package versions are reviewed before the pinned version is changed.

For example, use the platform-supported equivalent of:

text
npx clawhub@<audited-version> install howtousehumans/body-mechanics-injury-prevention

The exact version should be accompanied by an integrity value and should only be updated after security review.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-15
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code

yaml
metadata:
  openclaw:
    requires:
      tools: [filesystem]
    install: "npx clawhub install howtousehumans/body-mechanics-injury-prevention"

Technical Analysis

The Skill declares the filesystem tool as a requirement, but none of the reviewed instructions require reading, creating, modifying, or deleting local files. Its documented functionality consists of conversational body-mechanics guidance, a logical agent-state schema, and reminder definitions.

Granting an unused filesystem capability expands the Skill's authority beyond its stated functional requirements. The precise exposure depends on how the hosting agent scopes the tool. If the tool permits broad local access, a compromised future Skill version or manipulated instruction path could use it to access files unrelated to injury-prevention guidance.

No actual unauthorized filesystem operation was found in the reviewed file. The issue is the unnecessary permission boundary and the additional impact it could enable if other instructions were compromised.

Attack Path

  1. The host grants the Skill its declared filesystem capability.
  2. A future Skill update, supply-chain compromise, or successfully injected instruction causes the agent to invoke that capability.
  3. The agent reads or modifies files within the filesystem tool's permitted scope.
  4. Information may be exposed in agent output, or writable files may be altered.

This path is conditional on both malicious instruction influence and a host implementation that grants meaningful filesystem access.

Impact Assessment

Potential impact is limited by the host's filesystem sandbox and the privileges of the agent process. With broad access, exposed resources could include user documents, project source code, configuration files, and locally stored credentials readable by ...[truncated 208 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove filesystem from the required tools because the reviewed Skill does not use it.
  2. If persistence is needed for the agent-state fields, use a dedicated structured state API rather than general filesystem access.
  3. If file access later becomes necessary, grant access only to a dedicated Skill-specific directory.
  4. Prefer read-only access unless writes are explicitly required.
  5. Deny access to home directories, credentials, system configuration, unrelated projects, and temporary locations shared with other processes.
  6. Require explicit user confirmation before reading or modifying user-selected files.
  7. Add automated permission testing to ensure the Skill cannot access paths outside its approved scope.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command invokes npx clawhub without pinning an exact package version, which allows whatever version is current at execution time to run. If the upstream package is compromised or a breaking/malicious release is published, users installing the skill could execute untrusted code during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This skill provides detailed physical exercise and movement instructions, including warmups, lifting mechanics, and mobility drills, but it does not place an up-front medical safety warning before users act on the guidance. Because the skill explicitly targets users who may already have pain, minor strains, or prior injuries, a missing clear warning can lead users with contraindications to self-manage when they should first seek professional evaluation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.