Back to skill

Security audit

Budget Meal Prep

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent meal-planning guide with disclosed local state and reminder behavior, with only an install-time pinning caution.

Before installing, consider whether you are comfortable with the unpinned npx-based install command and with the skill storing meal-planning details such as budget, dietary restrictions, pantry state, and reminders.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13
Vulnerability Type: Supply-chain risk from unpinned, remotely retrieved executable dependencies
Risk Level: Medium

Vulnerable Code

yaml
install: "npx clawhub install howtousehumans/budget-meal-prep"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact reviewed version or integrity hash. Depending on the local environment and package cache, npx can retrieve executable package content from a remote registry at installation time.

Because the retrieved package is mutable and is not cryptographically bound to the version reviewed during this audit, the code ultimately executed may differ from the audited skill content. A compromised registry account, malicious package release, or upstream supply-chain compromise could therefore cause the command to execute attacker-controlled package code.

The project does not provide a lockfile, checksum, signature-verification procedure, or other mechanism for validating the retrieved CLI package and installed skill artifact.

Attack Path

  1. An attacker compromises the package publishing account, distribution source, or another relevant upstream component.
  2. The attacker publishes a malicious release under the package name resolved by npx, or replaces mutable skill content at the referenced source.
  3. A user follows the installation instruction in SKILL.md.
  4. npx resolves and downloads the current package content rather than a specifically reviewed and integrity-verified version.
  5. Malicious CLI, lifecycle, or installation code executes with the privileges of the user running the command.
  6. That code can access resources available to the invoking account and may install modified skill content or alter local files.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user who runs the installation command. The resulting ...[truncated 511 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installation CLI to an exact reviewed version, for example by using an explicit version rather than allowing npx to resolve the latest release.
  2. Pin the skill artifact itself to an immutable release, commit digest, or content hash where the package manager supports it.
  3. Publish and verify cryptographic checksums or signatures before executing downloaded components.
  4. Use a lockfile or equivalent dependency manifest to preserve the reviewed dependency graph.
  5. Disable or avoid dependency lifecycle scripts when they are not required.
  6. Prefer installing from an official, authenticated registry with protected publisher accounts and provenance attestations.
  7. Run installation with a nonprivileged account in a restricted environment, granting only the filesystem and network access necessary for installation.
  8. Document the expected package version, artifact digest, publisher identity, and verification procedure so users can confirm that the installed content matches the audited release.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The skill metadata includes an install command using npx clawhub install ... without pinning a specific package version or immutable reference. That means whoever runs the install may fetch and execute whatever version is current at install time, creating a supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.