Back to skill

Security audit

Debt Survival

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned and not malicious, but it stores very sensitive debt, account, and legal-strategy information without clear consent or protection controls.

Install only if you are comfortable with the agent saving detailed debt, account, collector, lawsuit, and settlement information locally and across sessions. Prefer masking account numbers, asking before any file is saved or reminder is created, and deleting stored debt records when no longer needed; also consider using a pinned installer version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned npx Package Execution Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippet:

yaml
install: "npx clawhub install howtousehumans/debt-survival"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version or integrity hash. Depending on the local npm environment, npx can retrieve and execute the package version currently resolved by the configured package registry.

The project contains no lockfile, vendored installer, checksum, signature verification instructions, or other mechanism that binds installation to a previously audited release. Consequently, the code executed during installation can change independently of the reviewed SKILL.md file.

This is a supply-chain weakness rather than evidence that the current clawhub package is malicious.

Attack Path

  1. An attacker compromises the package registry account, publishing pipeline, package namespace, or another component involved in resolving the unpinned clawhub package.
  2. The attacker publishes a malicious or compromised release that is selected by npx.
  3. A user follows the documented installation command.
  4. npx downloads and executes the selected package.
  5. Malicious package lifecycle or CLI code runs with the privileges of the user performing the installation.

Impact Assessment

Successful exploitation could execute arbitrary code under the installing user's account. Depending on that account's permissions, the payload could read or modify user-accessible files, access environment variables and credentials, make network requests, or install additional software. The reviewed project does not itself request elevated operating-system privileges, so administrative compromise is not established unless the user runs the command with elevated privileges.

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to a specific audited version, for example by using npx clawhub@<exact-version>.
  • Use a lockfile or equivalent immutable dependency-resolution mechanism.
  • Verify the downloaded package using a trusted signature or published integrity digest.
  • Avoid automatically accepting a mutable registry release during installation.
  • Document the expected package publisher, version, checksum, and trusted registry.
  • Review package lifecycle scripts and transitive dependencies before updating the pinned version.
  • Run installation with an unprivileged account and, where practical, inside a restricted environment.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:355
Finding

Sensitive Financial and Legal Information Is Persisted Without Defined Protection Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:355-405
Vulnerability Type: Unprotected persistent storage of sensitive information
Risk Level: Medium

Vulnerable Code Snippet:

yaml
## Agent State

Persist across sessions:

```yaml
financial_situation:
  monthly_income: null
  monthly_expenses: null
  total_available_cash: null
  income_change_date: null
  income_change_reason: ""

debts:
  - creditor_name: ""
    original_creditor: ""
    account_number: ""
    debt_type: ""
    claimed_amount: 0
    minimum_payment: 0
    priority_tier: null
    date_of_last_payment: null
    state: ""
    statute_of_limitations_years: null
    statute_expires: null
    statute_expired: false
    in_collections: false
    collector_name: ""
    collector_contact_date: null
    validation_letter_sent: false
    validation_letter_date: null
    validation_received: false
    settlement_offer_amount: null
    settlement_offer_date: null
    settlement_accepted: false
    settlement_terms_received: false
    payment_settled: false
    hardship_program_requested: false
    hardship_program_active: false
    lawsuit_filed: false
    lawsuit_response_deadline: null
    fdcpa_violations: []
    status: "new"
    communications_log: []

payment_hierarchy_created: false
emergency_budget_active: false
benefits_screened: false
text

Related file-writing instructions also direct the agent to save debt records under predictable paths such as:

```text
~/documents/debt-survival/payment-priority.txt
~/documents/debt-survival/{creditor}-consequences.txt
~/documents/debt-survival/{creditor}-validation-letter.txt
~/documents/debt-survival/{creditor}-settlement-offer.txt

Technical Analysis

The skill explicitly instructs the agent to persist detailed financial and legal information across sessions. The retained fields include income, expenses, av ...[truncated 2192 chars]

Remediation
View remediation

Remediation Suggestions

  • Default to session-only processing and require explicit informed consent before retaining information across sessions.
  • Remove the full account_number field or retain only a masked identifier such as the final four digits.
  • Store only fields necessary for active user-requested workflows.
  • Encrypt persistent state and generated documents at rest using platform-supported secret or secure-storage facilities.
  • Create files with owner-only permissions, such as mode 0600, and directories with mode 0700.
  • Define a short retention period and automatically delete resolved, expired, or abandoned case data.
  • Provide users with commands to inspect, export, redact, and permanently delete retained information.
  • Avoid including unnecessary account details, addresses, or complete collection correspondence in filenames and logs.
  • Exclude the storage directory from cloud synchronization and unencrypted backups unless the user explicitly opts in.
  • Isolate state by user and session, and prevent unrelated skills or sessions from reading it.
  • Validate and sanitize creditor-derived filename components before constructing output paths.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Drafting validation letters and logging collector details can capture names, addresses, account numbers, debt disputes, and communication history, all of which are sensitive legal-financial data. Persisting that information and setting reminders without user-facing disclosure increases the risk of privacy leakage, profiling, and misuse if local files or agent state are exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Statute-of-limitations findings and drafted legal letters encode dispute strategy, last-payment dates, jurisdiction, and whether a debt may be time-barred. This is particularly sensitive because exposure could materially affect the user's legal posture or reveal exploitable facts to anyone with access to local storage or persisted agent state.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 333)May include surrounding context.

md
If your debt situation is not improving or escalating:

1. **Collector violating your rights?** File a complaint at [consumerfinance.gov/complaint](https://www.consumerfinance.gov/complaint/) and consider contacting a consumer rights attorney (many work on contingency for FDCPA cases — they get paid from the collector, not you).
2. **Being sued and can't afford a lawyer?** Contact legal aid at [lawhelp.org](https://www.lawhelp.org). ALWAYS respond to a lawsuit — a default judgment is the worst outcome and is avoidable by showing up. Many courthouses have self-help centers that assist with responses.
3. **Debt is overwhelming all strategies?** Bankruptcy is a legal protection, not a moral failure. Chapter 7 eliminates most unsecured debt; Chapter 13 creates a managed repayment plan. Consult a bankruptcy attorney (many offer free consultations). Also search for your local bar association's pro bono program.
4. **Creditor won't negotiate?** Try again at month-end (quota pressure increases flexibility). If still refused, file a CFPB complaint and try the creditor's executive customer service office.
5. **Financial stress affecting your mental health?** Call or text 988 (Suicide & Crisis Lifeline). Financial crises are solvable — there is always a path through.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill recommends installation via npx clawhub install ... without pinning a specific version or immutable package reference. That creates a supply-chain risk because a future compromised or maliciously updated package could be executed at install time with the agent user's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This instruction directs the agent to persist highly sensitive financial triage data to local storage without explicit user consent, retention notice, or minimization guidance. Stored debt, housing, and hardship details can expose private financial circumstances to other local processes, later prompts, backups, or unauthorized users on the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Saving creditor-specific consequence analyses ties legal and financial risk assessments to an identifiable debt situation, again without a privacy warning or consent flow. Because the skill is designed for users in crisis, these records may contain especially sensitive and exploitable information about debts, state, and collection posture.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Settlement drafts and reminders contain negotiation positions, hardship claims, creditor names, and possibly settlement amounts, all of which are sensitive financial data. Persisting them silently can expose a user's bargaining strategy and debt details through files, reminders, or cross-session state.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 343)May include surrounding context.

md
- Always establish the payment hierarchy before discussing any individual debt. People in crisis try to pay credit cards while skipping meals.
- Never shame anyone for being in debt. The system is designed to keep people in it.
- Never acknowledge a debt is valid in any letter or communication until it has been validated.
- Never advise making a payment on potentially time-barred debt without checking the statute of limitations first.
- If someone mentions they're being sued, emphasize: RESPOND TO THE LAWSUIT. A default judgment is the worst possible outcome and is almost always avoidable by simply showing up.
- If someone mentions suicidal thoughts related to debt stress, provide the 988 Suicide and Crisis Lifeline immediately (call or text 988).

Static analysis

No suspicious patterns detected.