Back to skill

Security audit

Mentorship

Security checks for vulnerabilities and agentic risk

Overview

The mentorship guidance itself is benign, but the package asks for unnecessary filesystem access and uses an unpinned npx install command.

Review this before installing. The written mentorship content is ordinary guidance, but the skill should not need filesystem access, and the npx-based install should ideally be pinned or otherwise verified. Install only in a constrained environment or after confirming the package source and permissions are acceptable.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned npx Package Execution Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install mentorship"

Technical Analysis

The installation instruction invokes clawhub through npx without specifying a package version or integrity constraint. If the package is not already available locally, npx can retrieve executable package content from the configured package registry.

Because the retrieved package version is mutable and its source is not included in this project, the effective installation code cannot be verified as part of this audit. A compromised package release, registry account, dependency, or registry configuration could consequently cause arbitrary code to run during installation.

The project contains no evidence that the package is currently malicious. The vulnerability is the unpinned trust relationship and execution of externally supplied package code.

Attack Path

  1. An attacker compromises the clawhub package, one of its dependencies, its publishing account, or the package source selected by the user's registry configuration.
  2. The attacker publishes a malicious version containing an installation hook or malicious runtime behavior.
  3. A user follows the declared installation instruction:
    shell
    npx clawhub install mentorship
    
  4. npx retrieves the attacker-controlled or compromised package version.
  5. The malicious package executes with the privileges of the user running the installation command.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could read or modify user-accessible files, steal credentials or tokens, alter installed skills, ex ...[truncated 310 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specific reviewed version rather than allowing npx to resolve a mutable current version.
  • Use a trusted and explicitly configured package registry.
  • Record and verify package integrity hashes where the installation system supports them.
  • Review and lock the package's transitive dependency graph.
  • Avoid running the installation command with administrator or root privileges.
  • In CI/CD environments, execute installation in an isolated container with restricted filesystem access, network access, and credentials.
  • Establish a controlled upgrade process in which new versions are reviewed before updating the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:14
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Excessive tool permission
Risk Level: Medium

Vulnerable Code

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install mentorship"

Technical Analysis

The Skill declares the filesystem tool as a required capability, but its documented behavior consists entirely of conversational mentorship guidance. No instruction in the audited file identifies a legitimate need to read, create, modify, or delete local files.

Granting a capability that is unrelated to the Skill's purpose breaks the principle of least privilege. The practical severity depends on how the host platform constrains the filesystem tool. If access is broad, prompt injection or hostile user content encountered while the Skill is active could influence the Agent to perform filesystem operations outside the legitimate mentorship task.

No direct instruction to misuse the filesystem was found. This finding concerns the unnecessary access exposed by the configuration.

Attack Path

  1. The host loads the Skill and grants the declared filesystem capability.
  2. A malicious user, untrusted document, or injected instruction asks the Agent to inspect or modify an unrelated local file.
  3. Because the Skill has filesystem access despite not needing it, the Agent may issue the requested filesystem operation.
  4. If the host does not independently enforce path and operation restrictions, the attacker can access or alter files available to the Agent's operating-system identity.

Exploitation depends on both successful influence over the Agent and insufficient host-level authorization controls.

Impact Assessment

The attainable scope is determined by the filesystem tool's sandbox and the privileges of the Agent process. Potential impact includes disclosure of user-readable files, modification or deletion of writable data, exposu ...[truncated 304 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from openclaw.requires.tools because no audited Skill behavior requires it.
  • If future functionality genuinely requires file access, grant access only when that functionality is invoked.
  • Restrict access to explicitly approved paths and prefer read-only access.
  • Deny access to credentials, home-directory secrets, system files, and unrelated projects.
  • Require explicit user confirmation before writes, deletions, or access outside a task-specific workspace.
  • Enforce authorization in the host tool layer rather than relying exclusively on conversational instructions.
  • Add tests confirming that the Skill functions correctly without filesystem access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 307)May include surrounding context.

md
- Don't judge. They're going to make choices you wouldn't. That's

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill metadata includes an install command using npx clawhub install mentorship without a pinned package version or integrity control. This creates a supply-chain risk because a future malicious or compromised release of the package could be executed at install time, especially since npx fetches and runs code dynamically.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
## Instructions

### Step 1: Find a Mentor Without Asking "Will You Be My Mentor?"

**Agent action**: Explain why the direct ask backfires and provide the better approach.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The automation triggers use broad natural-language conditions such as 'user wants to find a mentor' or 'asks how to approach someone,' which can cause the skill to activate in loosely related contexts without strong scoping. Overbroad triggering is risky because it can lead to unintended workflow execution, context capture, or inappropriate guidance when the user's request is ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.