T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned npm CLI Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent first-aid guide, but it asks to retain sensitive injury details across sessions without clear user consent, retention, or deletion controls.
Install only if you are comfortable with the agent retaining injury details for follow-up. Prefer a version with explicit opt-in persistence, clear deletion commands, short retention, and a pinned or verified installer.
SKILL.md:13Unpinned npm CLI Package Execution During Installation
SKILL.md:318Persistent Storage of Sensitive Health Data Without Defined Safeguards
The install command uses npx clawhub install minor-injury-first-response without pinning a specific package version. npx may fetch and execute the latest published package at install time, which creates a supply-chain risk if the package is updated maliciously, compromised, or unexpectedly changed.
No suspicious patterns detected.