Back to skill

Security audit

Childcare Essentials

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly static childcare guidance, but it asks for filesystem access it does not appear to need and uses an unpinned npx installer path.

Review this before installing: the childcare guidance itself is visible and purpose-aligned, but the skill should not need filesystem access for static advice. Prefer a version with the filesystem requirement removed and a pinned installer command. Also treat the medical and emergency guidance as general support, not a substitute for local emergency services, poison control, or a pediatric clinician.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install howtousehumans/childcare-essentials"

Technical Analysis

The installation command invokes clawhub through npx without specifying a fixed package version or verifying package integrity. Depending on the local environment and npx behavior, the command can download and execute the currently published version of the CLI package from its configured package registry.

Because the executable dependency is not pinned to an audited version, the code executed at installation time may differ from the code that was reviewed. This creates a supply-chain trust boundary in which a compromised maintainer account, registry package, release process, or dependency could introduce arbitrary behavior after the Skill itself has been audited.

The finding does not establish that the current clawhub package is malicious. The vulnerability is the installation process's reliance on mutable, unverified third-party executable content.

Attack Path

  1. An attacker compromises the package publisher, registry entry, release pipeline, or a transitive dependency associated with the unpinned clawhub CLI.
  2. The attacker publishes a modified package version containing malicious installation or runtime behavior.
  3. A user follows the documented installation procedure.
  4. npx resolves and downloads the attacker-controlled or compromised package version.
  5. The downloaded package executes with the operating-system permissions of the user running the installation command.
  6. The malicious package can perform any action permitted to that user, independently of the reviewed contents of SKILL.md.

Impact Assessment

Successful exploitation could ...[truncated 508 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer CLI to a specifically reviewed version, for example by using an explicit version in the npx package specification.
  • Pin the Skill package to an immutable release, commit identifier, or cryptographic digest where the package manager supports it.
  • Use a lockfile and registry integrity metadata so unexpected package changes cause installation to fail.
  • Run installation in a sandbox or low-privilege environment with no sensitive credentials available.
  • Configure an approved package registry and verify package provenance, signatures, and publisher identity.
  • Review both direct and transitive dependencies whenever the pinned version is intentionally updated.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:13
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13-16
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install howtousehumans/childcare-essentials"

Technical Analysis

The Skill declares the filesystem tool as a required capability. However, the documented functionality consists of providing static childcare, first-aid, feeding, childproofing, and emergency guidance. No documented workflow in the reviewed 559-line file requires reading, creating, modifying, or deleting local files.

Granting a filesystem capability without a demonstrated functional requirement expands the Skill's authority beyond least privilege. The exact practical scope depends on how the host platform implements and confines the filesystem tool. If the tool is broadly scoped, later prompt injection, malformed context, or unintended agent behavior could cause access to unrelated local files.

The reviewed Skill does not itself contain instructions to exploit the filesystem capability, and no unauthorized file operation was observed. The risk arises from exposing an unnecessary privileged tool to the agent session.

Attack Path

  1. The Skill is installed or loaded with its declared filesystem requirement.
  2. The host grants the agent filesystem access according to its local permission policy.
  3. The session later receives adversarial or malformed instructions, or the agent otherwise invokes the unnecessary tool incorrectly.
  4. The filesystem tool is used to access data unrelated to childcare guidance.
  5. If write access is available, accessible files could also be altered or deleted.

This path is conditional on the host granting meaningful filesystem access and on a separate trigger causing misuse; the reviewed artifact does not contain that trigger.

Impact Assessment

Potential impact is l ...[truncated 362 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented Skill behavior does not use it.
  • If a future feature genuinely requires file access, document the specific operation and request only the minimum necessary access.
  • Restrict any necessary access to a dedicated application directory rather than the user's general filesystem.
  • Prefer read-only access where writes are unnecessary.
  • Require explicit user confirmation before accessing files and deny access to credentials, configuration directories, and other sensitive locations.
  • Enforce capability grants at invocation time rather than granting broad filesystem authority for the entire session.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill when someone is a new parent, babysitter, grandparent, or 'anyone suddenly responsible for a young child and needs immediate practical guidance.' This is a very broad natural-language invocation scope without explicit boundaries or exclusion conditions, which could cause the skill to activate for many routine childcare discussions rather than clearly defined requests.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The install command uses npx clawhub without pinning a specific package version, so future installs may resolve to a different release than the one reviewed. If the upstream package is compromised or a breaking/malicious version is published, users installing this skill could execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.