Back to skill

Security audit

Fishing Basics

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent beginner fishing guide, but its unpinned installer and under-scoped live regulatory/reminder behavior should be reviewed before installing.

Review this skill before installing. The fishing guidance itself is ordinary and purpose-aligned, but installation relies on an unpinned external CLI, and the skill expects live legal/regulatory lookups despite declaring only filesystem tooling. Users should verify fishing licenses, seasons, size limits, stocking schedules, and fish-consumption advisories with official agencies, and should not let an agent store license-expiration reminder data without explicit consent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party CLI Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install howtousehumans/fishing-basics"

Technical Analysis

The installation instruction invokes clawhub through npx without specifying an exact package version or verifying package integrity. If the package is not already available locally, npx may retrieve and execute the currently published version from the configured package registry.

Consequently, the code executed during installation is not fixed to the content reviewed in this project. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream update could alter the effective installation behavior after this Skill has been audited. The external CLI implementation and its lifecycle behavior are not included in the audited project, so they cannot be verified from the repository contents.

Attack Path

  1. An attacker compromises the publication process, maintainer account, registry entry, or another relevant component in the clawhub package supply chain.
  2. The attacker publishes a malicious version under the package name resolved by npx.
  3. A user or automation system follows the installation instruction in SKILL.md.
  4. npx resolves and downloads the attacker-controlled package version because no exact version or integrity constraint is present.
  5. The package's CLI entry point or applicable installation lifecycle code executes on the local system.
  6. The malicious package performs actions with the privileges and environmental access of the installing process.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account performing the installation. The resulting scope may ...[truncated 480 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed version rather than resolving the latest available release, for example by using an explicit version supported by the installation environment.
  2. Verify the downloaded package against a trusted integrity hash, signed release, or provenance attestation before execution.
  3. Restrict installation to an approved registry and enable registry namespace protections where available.
  4. Audit the pinned CLI package, including its dependencies and package lifecycle scripts.
  5. Run installation with the minimum necessary privileges in a sandbox or isolated environment without unrelated credentials.
  6. Use a lockfile or equivalent immutable dependency manifest when the surrounding installation system supports one.
  7. Prefer a trusted, preinstalled CLI binary so installation does not automatically download and execute mutable code.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest markets this as a general beginner fishing skill, but the actual instructions operationalize real-time licensing, regulatory, and stocking-schedule retrieval. This hidden expansion of scope can mislead reviewers about the skill's runtime behavior and trust assumptions, especially where live compliance advice affects legal or safety outcomes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install command invokes npx clawhub without pinning a specific version or integrity-checked package reference. That creates a supply-chain risk because a future malicious or compromised package release could execute unexpected code at install time.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill declares only filesystem tooling yet instructs the agent to perform live external lookups and provide direct purchase links. This mismatch can cause agents or orchestrators to overreach tool boundaries, encourage unsafe browsing behavior, or produce fabricated links and regulatory guidance when network access is unavailable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The statement 'Every US state requires a freshwater fishing license. No exceptions.' is a locale-specific directive embedded in otherwise general skill instructions. This can violate language/locale policy expectations because the skill is presented for multiple jurisdictions and does not clearly limit this statement to users in the US at the point of instruction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The markdown includes instructions for filleting fish with a knife and earlier guidance on hook handling, but it does not provide any clear user-facing warning about injury risk, sanitation, or safe handling precautions. Under the markdown-file criteria for missing user warnings, this omits warnings about behavior that could affect user safety and health.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger 'user mentions wanting to fish trout or a specific stocked species' is fairly open-ended and could match casual discussion rather than a request for assistance. The manifest does not provide exclusion conditions or negative examples to narrow when the automation should actually run.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The license renewal reminder assumes knowledge of a user's expiration status without specifying consent, source of that data, or storage controls. That creates a privacy and state-management risk because the system may infer, retain, or act on regulated personal status data without clear authorization.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The condition 'user mentions a specific fish species or water body' overlaps with normal conversation and does not require an explicit request for regulatory help. This is a vague activation condition for a markdown/manifest trigger because it lacks clear boundaries and negative examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.