Back to skill

Security audit

Death Preparation

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed end-of-life planning guide with no embedded code, but users should be careful with sensitive documents, passwords, and optional reminders.

Install only through a trusted or pinned ClawHub CLI when possible. Use this skill as planning guidance, but keep control over where any death file is saved and do not paste master passwords, private keys, or complete account credentials into the agent. Enable annual or proactive reminders only if you explicitly want them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned npm Package Execution During Skill Installation

Content
View full analysis
Remediation
View remediation
install howtousehumans/death-preparation" ``` 2. Use a trusted npm registry explicitly and ensure organizational registry configuration cannot redirect the package name to an untrusted source. 3. Verify the downloaded package using registry integrity metadata, a lockfile, signed provenance, or a published checksum before execution. 4. Prefer installing the reviewed CLI version through a controlled dependency-management process and then invoking the locally pinned binary, rather than allowing `npx` to retrieve changing code at installation time. 5. Run installation with a non-privileged account and restrict access to sensitive credentials and environment variables. 6. Periodically review the pinned dependency for security updates and update it only after validating the new version and its provenance. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install command invokes npx clawhub without pinning a specific version, so execution may pull whatever package/version is current at install time. This creates a supply-chain risk: a compromised upstream package, malicious update, or typosquatted dependency could execute code on the installing system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The automation triggers are broad and can initiate sensitive end-of-life prompts based purely on internal state rather than a fresh, explicit user request. In this context, unsolicited prompting about death, legal planning, or family conversations can cause harmful or inappropriate agent behavior, especially for grieving, distressed, or unrelated-user contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.