Back to skill

Security audit

Cook From Scratch

Security checks for vulnerabilities and agentic risk

Overview

The skill is a normal budget-cooking guide, but it asks for unnecessary file access and uses an unpinned installer, so it should be reviewed before installation.

Review this skill before installing. Ask the publisher to remove the unnecessary filesystem requirement and provide a pinned or verified installer command. If you use the cooking advice, also follow current food-safety guidance for meat, eggs, rice, leftovers, refrigeration, and cross-contamination.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned npm Installer Creates a Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–13
Vulnerability Type: Unpinned third-party installer execution
Risk Level: Medium

Complete Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install howtousehumans/cook-from-scratch"

Technical Analysis

The installation command invokes clawhub through npx without specifying an audited package version or integrity hash. If the package is not available locally, npx can retrieve and execute the version currently resolved from the configured npm registry.

Consequently, the executable code used during installation can change after this Skill has been audited. A compromise of the clawhub npm package, its publisher account, the dependency-resolution process, or the configured package registry could cause a future installation to execute code that was not present during this review. The Skill source does not provide a lockfile, checksum, signature, or other mechanism for verifying the installer artifact.

The declared filesystem tool requirement also appears unnecessary for the documented cooking-guidance workflow. Although the declaration alone does not demonstrate privilege escalation, removing unused capabilities would improve least-privilege compliance.

Attack Path

  1. An attacker compromises the npm publisher account, package distribution channel, or another component controlling resolution of the unpinned clawhub package.
  2. The attacker publishes or causes resolution to a malicious package version.
  3. A user runs the documented command: npx clawhub install howtousehumans/cook-from-scratch.
  4. npx retrieves the currently resolved package when it is not already available in the execution environment.
  5. The downloaded package executes with the privileges of the user running the installer.
  6. Malicious installer code could access or modify data available to that user, s ...[truncated 761 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specific, reviewed version rather than allowing npx to resolve the current release:
    yaml
    install: "npx clawhub@<reviewed-version> install howtousehumans/cook-from-scratch"
    
  2. Verify the selected package artifact using a trusted lockfile, registry integrity metadata, a cryptographic checksum, or a verified signature.
  3. Prefer a separately installed and centrally managed installer whose version is controlled by the deployment environment.
  4. Disable automatic acceptance of newly published versions and require security review before updating the pinned installer.
  5. Execute installation in a sandbox or restricted account without administrative privileges, sensitive environment variables, or unnecessary filesystem access.
  6. Remove the filesystem tool requirement unless the Skill has a documented runtime need for filesystem operations.
  7. Review both the installer and the referenced Skill package whenever either pinned version or verified artifact changes.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install command uses npx clawhub without pinning a specific version, so the fetched package can change over time. If the upstream package or dependency chain is compromised, users may execute unexpected code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is in scope for vague-trigger review. Phrases like 'Wants to eat better but doesn't know where to start' and 'Recently on their own for the first time' are broad and common enough that they could cause the skill to be selected for loosely related conversations, with no explicit boundaries or negative examples to limit invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill gives actionable instructions for cooking chicken, eggs, reheating rice, and multi-day meal prep, but it does not present prominent safety guidance on minimum safe temperatures, refrigeration windows, cross-contamination, or leftover handling. In a beginner-focused cooking skill, omission of these safeguards increases the chance of foodborne illness because users may follow simplified directions literally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.