Back to skill

Security audit

Hygiene Without Infrastructure

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is emergency hygiene guidance, but its install metadata uses an unpinned npx installer whose executed code can change after review.

Review or replace the install command before installing. Prefer a pinned and verified ClawHub CLI version or an already trusted local installer, and run installation with minimal privileges and no unrelated secrets in the environment. The actual skill content is ordinary emergency sanitation guidance.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution During Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install hygiene-without-infrastructure"

Technical Analysis

The installation command invokes clawhub through npx without pinning an audited package version or specifying an integrity hash. Depending on the local package state and npm configuration, npx may retrieve the current version of the package from a configured registry and execute its CLI or package lifecycle code.

Because the dependency is mutable after the Skill has been reviewed, the effective installation behavior is not fully represented by the audited project contents. A compromised registry account, malicious replacement release, dependency confusion condition, or unexpected upstream update could therefore introduce arbitrary code into the installation process.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution channel, or another component involved in resolving the unpinned clawhub package.
  2. The attacker publishes a malicious or compromised version that contains harmful CLI or lifecycle code.
  3. A user follows the documented command:
    shell
    npx clawhub install hygiene-without-infrastructure
    
  4. npx resolves and downloads the mutable package version from the configured registry.
  5. The downloaded package executes with the permissions of the user running the installation command.
  6. The malicious package can access resources available to that user before or while installing the requested Skill.

Impact Assessment

Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on those privileges and the host environment, the compromised package could read or alter user-accessible files, obtain credentials exposed to the process, modify ...[truncated 436 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specifically reviewed version rather than relying on mutable registry resolution, for example:
    shell
    npx clawhub@<audited-version> install hygiene-without-infrastructure
    
  • Verify the selected package version and its transitive dependencies before publishing the installation instruction.
  • Use a lockfile and registry-provided integrity metadata where the installation workflow supports them.
  • Document the expected trusted registry and reject untrusted or unexpected package sources.
  • Prefer a preinstalled, administratively managed CLI or a verified local binary over dynamically downloading and executing a package during installation.
  • Run installation with the minimum necessary privileges and without unrelated credentials in the process environment.
  • Periodically re-audit the pinned version before intentionally upgrading it.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill metadata includes an install command that runs npx clawhub install hygiene-without-infrastructure without pinning a specific package version. Because npx resolves and executes code from the registry at install time, a compromised upstream package, typo-squatted dependency, or unexpected latest-version change could result in arbitrary code execution on the installing system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.