T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Remote Installation Command Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent financial-crisis advice guide, but it asks for calendar and filesystem access without explaining why.
Install only if you are comfortable with the declared calendar and filesystem access, or ask the publisher to remove those permissions and provide a pinned, reproducible install command. Treat the advice as US-focused unless you confirm local equivalents for your country.
SKILL.md:11Unpinned Remote Installation Command Creates a Supply-Chain Risk
SKILL.md:11Skill Requests Calendar and Filesystem Tools Without a Demonstrated Functional Need
The install command invokes npx clawhub without pinning an exact package version, which allows the latest published package to be fetched at install time. If the upstream package is compromised, typosquatted, or updated with malicious code, users installing the skill could execute untrusted code in their environment.
The instructions state that programs and phone numbers are US-specific and tell the agent to adapt for other countries, but the skill otherwise presents a default US-centric workflow. This can create a locale-policy issue because users are funneled into a specific national context without an explicit choice or a clearly documented scope limitation such as 'for US users only'.
No suspicious patterns detected.