Back to skill

Security audit

Grow Food Anywhere

Security checks for vulnerabilities and agentic risk

Overview

This gardening skill is coherent and disclosed, with routine cautions about saving a plan, creating reminders, and using an unpinned installer command.

Before installing, check the unpinned npx installer source or use a pinned/trusted install flow if available. When using the skill, confirm before saving the plan file and review any recurring calendar reminders so they match your local season and plants.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
install: "npx clawhub install howtousehumans/grow-food-anywhere"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact, audited package version or an integrity constraint. If the package is not already available locally, npx may retrieve it from the configured package registry and execute its CLI or package lifecycle code.

Because the referenced package version is mutable from the perspective of this project, the code executed during installation can change after the Skill has been reviewed. Security therefore depends on the continuing integrity of the package registry, the package publisher account, package resolution settings, and all transitive dependencies.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, a resolved dependency, or the package source used by the victim.
  2. The attacker publishes a malicious version containing hostile CLI or lifecycle code.
  3. A user runs the documented npx clawhub install howtousehumans/grow-food-anywhere command.
  4. npx resolves and downloads the mutable package version from the configured registry.
  5. The malicious package code executes with the permissions of the user running the installation command.

Impact Assessment

Successful exploitation could allow arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the malicious package could read or modify accessible files, access user-level credentials and environment variables, alter installed Skill content, invoke network resources, or execute additional processes.

The command does not itself request elevated privileges, so direct impact is normally limited to the current user's privile ...[truncated 132 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a reviewed exact version, for example:
    bash
    npx --yes clawhub@<audited-exact-version> install howtousehumans/grow-food-anywhere
    
  • Prefer a lockfile-backed installation workflow that records exact dependency and transitive dependency versions.
  • Verify package provenance and integrity through trusted registry metadata, checksums, signatures, or package-manager integrity fields before execution.
  • Review the pinned package's CLI entry point and lifecycle scripts before approving it for use.
  • Use a trusted registry explicitly and prevent dependency resolution from unapproved registries.
  • Run installation with an unprivileged account in a restricted environment that does not expose unrelated credentials or sensitive files.
  • Establish a controlled update process in which newer versions are reviewed and tested before changing the pinned version.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install command invokes npx clawhub without pinning a specific version, which allows whatever package version is current at execution time to run. If the upstream package is compromised or a breaking/malicious update is published, the installer could execute unintended code on the user's system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the agent to write a personalized file to ~/documents/food-growing/my-plan.md without requiring explicit user consent at the moment of write. Unprompted persistence to a user path can create privacy, trust, and safety issues, especially if the stored content includes location or schedule details gathered during the interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger season_start IS SET with schedule daily at 7am during growing season does not clearly define when the growing season begins or ends, so the reminder could activate more broadly than intended. The file provides no exclusion conditions or precise trigger boundaries for this automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description presents the skill as advice for novice growers, focused on realistic guidance about what to grow. In addition to guidance, the instructions explicitly direct the agent to persist user-specific output to the filesystem, and the file also defines automation triggers that imply calendar/reminder behavior beyond pure informational coaching.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The condition any plant age > 25 days is imprecise because it does not specify which tracked plants qualify, how age is calculated, or when the trigger should stop firing. Without tighter constraints or negative examples, this automation may produce repeated or unintended harvest reminders.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.