Back to skill

Security audit

Clear Thinking

Security checks for vulnerabilities and agentic risk

Overview

The skill content is mainly clear-thinking guidance, but it asks for broad filesystem access and uses an unpinned npx installer that users should review before installing.

Review this before installing in an environment with sensitive files or credentials. Prefer a pinned, trusted installer version, and consider whether this skill really needs filesystem access for a reasoning-only workflow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install command invokes npx clawhub without pinning a specific version, which makes the supply chain nondeterministic and allows a compromised or newly published package version to be executed at install time. Because npx may fetch and run code directly, this creates a real risk of remote code execution if the upstream package or dependency chain is hijacked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The condition "user asks whether a claim is true or presents conflicting information" is ambiguous and expansive enough to overlap with many ordinary conversations, with no clear boundary for what kinds of claims or contexts should invoke the skill. The trigger list also provides no negative examples or exclusion conditions to narrow activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phrase "user describes being unable to make a decision or overthinking" is broad and could apply to a wide range of everyday user statements without distinguishing serious decision-support scenarios from casual indecision. The manifest does not provide constraints or negative examples to clarify scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.