Back to skill

Security audit

Family Emergency Planning

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly emergency-planning guidance, but it asks for broad filesystem access it does not need and uses an unpinned npx installer.

Install only if you are comfortable with the installer resolving the current `clawhub` package through npx and with the skill being granted filesystem capability. Prefer a pinned or verified installer if available, and do not let the agent read or store scans of IDs, Social Security cards, financial records, medical records, or insurance documents unless you explicitly choose that action and understand where the data is going.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation
install howtousehumans/family-emergency-planning" ``` 2. Pin the installed skill version or immutable artifact reference as well, if the package manager supports it. 3. Use a lockfile and integrity verification for all package and transitive dependency resolutions. 4. Verify package provenance, registry ownership, signatures, and published checksums before installation. 5. Prefer installing the verified package separately and invoking it with `npx --no-install`, preventing an implicit download at execution time. 6. Run installation with a non-administrative account in a restricted environment without unrelated credentials or sensitive files. 7. Incorporate dependency review and automated supply-chain monitoring into the release process. ]]>

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Filesystem Capability Requested Without a Demonstrated Functional Need

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command invokes npx clawhub without pinning a specific package version, which can cause whatever version is current at execution time to be fetched and run. That creates a supply-chain risk: a compromised upstream release, dependency hijack, or breaking change could result in execution of unreviewed code on the user's system.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

In the manifest-style trigger block, both annual_plan_review and seasonal_disaster_prep activate whenever overall_status IS NOT null, which is ambiguous because any non-null value could satisfy it regardless of whether the plan is actually complete or ready for review. The trigger scope lacks constraints or negative conditions, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.