Back to skill

Security audit

Fermentation Food Preservation

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent food-preservation guide, but it requests unnecessary filesystem access and uses an unpinned installer, so users should review it before installing.

Before installing, prefer a pinned or trusted ClawHub installer and deny or remove filesystem access if the platform allows it. Treat the food-safety content as high-stakes guidance: use tested recipes and official preservation references, and review or disable scheduled reminders if you do not want proactive prompts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install howtousehumans/fermentation-food-preservation"

Technical Analysis

The installation command invokes clawhub through npx without specifying a reviewed package version or integrity digest. If the package is not already available locally, npx can retrieve it from the configured package registry and execute it with the installing user's privileges.

Because the package version is not pinned, the code executed during installation can differ from the version assessed when this Skill was reviewed. Compromise of the package, its registry account, or a transitive dependency could therefore introduce attacker-controlled code without requiring any change to SKILL.md.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, or an unpinned dependency used by the package.
  2. The attacker publishes a malicious version under the package name resolved by npx.
  3. A user follows the documented installation command.
  4. npx downloads the current package version from the configured registry.
  5. Attacker-controlled CLI, lifecycle, or dependency code executes under the user's account.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user running the installation command. Depending on that user's permissions, the malicious package could access local files and credentials, alter user-level configuration, install persistence, or make network requests.

The reviewed Skill does not itself contain such a payload; the risk arises from mutable, unpinned supply-chain content.

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specific, reviewed version rather than allowing npx to resolve the latest release.
  • Verify package provenance and integrity through registry checksums, signed attestations, or an approved lockfile where supported.
  • Prefer a trusted, preinstalled CLI when available.
  • Disable or carefully review dependency lifecycle scripts during installation.
  • Reassess the pinned package and its dependency tree before upgrading.

Example hardened form:

yaml
install: "npx --yes clawhub@<reviewed-version> install howtousehumans/fermentation-food-preservation"

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install howtousehumans/fermentation-food-preservation"

Technical Analysis

The Skill declares access to the filesystem tool, but its reviewed functionality consists of conversational food-preservation guidance, declarative state, and reminder triggers. No instruction in the 526-line file requires reading, creating, modifying, or deleting local files.

Granting filesystem access where it is not required violates the principle of least privilege. Although no current instruction was found that abuses this capability, the unnecessary permission increases the consequences of a future Skill compromise, malicious update, or successful instruction-manipulation attempt.

Attack Path

  1. The Skill is installed and receives the declared filesystem capability.
  2. A future malicious update or manipulated instruction causes the Agent to invoke that capability.
  3. The Agent reads or modifies files unrelated to the legitimate food-preservation task.
  4. Data may be exposed through subsequent output or local content may be altered within the filesystem tool's effective scope.

Impact Assessment

The attainable privileges depend on the filesystem tool's sandbox and the permissions of the hosting process. Potential scope includes unauthorized access to user-readable files and modification of user-writable content.

There is no evidence in the reviewed version of actual filesystem access, data theft, or file modification. This finding concerns unnecessary capability exposure and the resulting expansion of the attack surface.

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from openclaw.requires.tools because the current Skill does not need it.
  • If future functionality requires persistent storage, grant access only to a dedicated Skill-owned directory.
  • Separate read and write permissions where the platform supports granular capabilities.
  • Deny access to credentials, home-directory configuration, system paths, and unrelated project files.
  • Document each required capability and test that the Skill functions with all unnecessary permissions disabled.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · SKILL.md (reported line 415)May include surrounding context.

text
BOTULISM — what it is and how to prevent it

WHAT:
Clostridium botulinum bacteria produce a toxin that causes paralysis
and death. The spores survive boiling (212F/100C). They thrive in
anaerobic (no oxygen), low-acid, moist environments — which describes
the inside of an improperly canned jar perfectly.

PREVENTION RULES (non-negotiable):

Harmful Content Injection

Critical
Category
Prompt Injection
Confidence
95% confidence
Finding

This content may contain harmful instructions that could cause physical harm if followed. CRITICAL: Review carefully before use.

Content

Scanner excerpt · SKILL.md (reported line 434)May include surrounding context.

text
BOTULISM — what it is and how to prevent it

WHAT:
Clostridium botulinum bacteria produce a toxin that causes paralysis
and death. The spores survive boiling (212F/100C). They thrive in
anaerobic (no oxygen), low-acid, moist environments — which describes
the inside of an improperly canned jar perfectly.

PREVENTION RULES (non-negotiable):

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill references installation via npx clawhub install ... without pinning a specific package version. This creates a supply-chain risk because a future malicious or compromised release of the referenced tool could be fetched and executed unexpectedly during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The annual trigger activates on broad garden or harvest context rather than clear preservation intent. This can cause inappropriate or intrusive skill invocation, increasing the chance the agent gives food-preservation guidance in the wrong context or spams users seasonally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.