Back to skill

Security audit

Fire Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed fire-safety guidance package with a minor install-time supply-chain caution, but no artifact-backed malicious behavior.

Before installing, prefer a pinned or otherwise integrity-verified ClawHub installer and skill version if available. Review and approve any reminder or stored-state behavior, especially if your agent persists home-safety details across sessions. For real fires or burns, use local emergency services and professional safety guidance rather than relying only on the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
SKILL.md:15
Finding

Unpinned npx Package Execution in Installation Metadata

Content
View full analysis
Remediation
View remediation
install howtousehumans/fire-skills ``` 2. Pin the installed skill to an immutable version, commit digest, or content hash if the installer supports it. 3. Prefer a lockfile-backed installation process with verified registry integrity metadata. 4. Configure npm to use an explicitly trusted registry and avoid environment-controlled registry substitution in privileged automation. 5. Install and review the CLI separately, then use `npx --no-install` or a directly referenced trusted local binary so installation cannot silently download a new release. 6. Run installation under a least-privileged account without unrelated credentials or sensitive environment variables. 7. Re-audit and verify checksums whenever either the CLI version or skill artifact changes. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill specifies an installation command using npx clawhub install howtousehumans/fire-skills without pinning an exact package version or immutable artifact. If the referenced package or one of its resolved dependencies is updated, compromised, or republished maliciously, consumers may execute unintended code at install time, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.