Back to skill

Security audit

Boundaries Saying No

Security checks for vulnerabilities and agentic risk

Overview

This is a conversational boundary-setting skill with no artifact-backed evidence of hidden execution, exfiltration, persistence, or destructive behavior.

Before installing, consider whether you trust the `npx clawhub` installation path and whether the skill really needs filesystem permission. Use a sandboxed or least-privilege environment where possible; the reviewed skill content itself is boundary-setting advice and safety referral guidance.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:11
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
# Boundaries & Saying No

Boundaries are not walls, not punishment, not ultimatums, and not "being difficult." They're clear statements about what you will and won't accept, communicated directly. Most people who struggle with boundaries were trained — by family, by culture, by workplaces — to believe that their own needs are less important than other people's comfort. That training is wrong, and unlearning it is a skill, not a personality transplant. This skill provides actual scripts you can use verbatim, because when you're in the moment and your brain is screaming "just say yes to avoid conflict," you need words ready to go, not abstract concepts.

This skill references and extends: difficult-conversations, safe-exit-planner.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

text
WHAT BOUNDARIES ARE:
- Clear statements about what YOU will and won't do.
- About your behavior, not controlling theirs.
- "I won't stay in a conversation where I'm being yelled at."
  (This is about what YOU will do — leave.)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says to use the skill when someone 'can't say no,' 'feels constantly drained,' or 'needs to establish limits' across family, work, friends, or partners. These are very broad, everyday situations without explicit boundaries or exclusion conditions, which could cause the skill to activate for many generic emotional-support conversations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install command invokes npx clawhub without pinning a specific package version, which creates a supply-chain risk: a future compromised or malicious release could be executed at install time. Because npx fetches and runs packages dynamically, this is a real integrity risk even though the rest of the skill content is benign.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.