T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent layoff triage guide, but it tells users to copy broad employer and third-party information and persist sensitive financial, health, and employment details without clear limits.
Before installing, treat this as sensitive crisis guidance: do not copy employer, client, vendor, CRM, address book, proprietary, or confidential records unless your employer policies and legal obligations clearly allow it. Prefer requesting employment, pay, benefits, and severance records through HR, and avoid storing exact financial and health-related details in agent memory unless you explicitly want that retained and can later delete it.
SKILL.md:15Unpinned Package Execution Through npx
SKILL.md:96Overbroad Transfer of Employer and Third-Party Contact Information
SKILL.md:286Uncontrolled Cross-Session Retention of Sensitive Financial and Employment Data
The skill includes an install command using npx clawhub without pinning a specific version, which creates a supply-chain risk because whatever version is current at execution time will be fetched and run. In a security-sensitive agent ecosystem, this can allow a compromised or malicious package update to affect users or agent environments unpredictably.
The skill instructs users to forward workplace materials to personal email or cloud storage, including broad contact lists and accomplishment documentation, which can easily cause exfiltration of employer-controlled data, personal data of third parties, or confidential business information. Even though the text warns against taking trade secrets, the operational guidance is broad and given during a stressful moment, making over-collection and policy violations likely.
The skill defines persistent state and automations that retain extensive sensitive information about layoffs, finances, insurance, legal matters, and deadlines across sessions, increasing the privacy and breach impact if agent memory, logs, or connected systems are accessed improperly. Much of this data exceeds strict minimization for immediate task completion and could expose a user during an already vulnerable life event.
No suspicious patterns detected.