Back to skill

Security audit

Navigation Without Screens

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly straightforward navigation guidance, but it asks for unnecessary filesystem access and uses an unpinned npx installer that could execute changing upstream code.

Review the install command and permissions before installing. Prefer a pinned or trusted installer path, avoid running it with elevated privileges, and grant filesystem access only if the platform can limit it to a narrow workspace. Do not rely on the skill as a substitute for local emergency services, maps, training, or search-and-rescue guidance.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13
Vulnerability Type: Supply-chain exposure caused by an unpinned executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install navigation-without-screens"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version or integrity value. Depending on the local npm configuration and cache state, npx can retrieve and execute the package version currently resolved from the configured registry.

Consequently, the code executed during installation is not immutable and may differ from the version that was available when this Skill was reviewed. This creates a supply-chain trust boundary in which compromise of the package, publisher account, registry resolution, or a subsequently released version could introduce attacker-controlled installation behavior.

No evidence in the reviewed project shows that the current clawhub package is malicious. The risk arises from the unpinned execution mechanism.

Attack Path

  1. An attacker compromises the package publisher, publishing process, registry account, or another relevant dependency-resolution component.
  2. The attacker publishes a malicious or backdoored version of the package resolved as clawhub.
  3. A user runs the documented installation command.
  4. npx retrieves or resolves the compromised package because no reviewed version is pinned.
  5. Package lifecycle or command code executes with the operating-system privileges of the user running the installer.
  6. The malicious package could access data or modify resources available to that user.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope would depend on that account's privileges, filesystem permissions, avail ...[truncated 401 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to an exact, reviewed version rather than allowing unconstrained package resolution.
  • Use package-locking and integrity verification mechanisms supported by the installation environment.
  • Resolve packages only from an explicitly trusted registry.
  • Avoid running installation commands with administrator or root privileges.
  • Review package lifecycle scripts and the resolved dependency tree before distribution.
  • Where feasible, install from a verified artifact with a cryptographic checksum or signature.
  • Establish an update process that requires security review before changing the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:10
Finding

Filesystem Capability Requested Without a Demonstrated Need

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-12
Vulnerability Type: Excessive tool permission violating least privilege
Risk Level: Low

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [filesystem]

Technical Analysis

The Skill declares filesystem access, but its reviewed behavior consists of providing physical-navigation guidance, emergency instructions, practice exercises, state fields, and conversational automation triggers. No documented operation requires reading, creating, changing, or deleting local files.

Granting a capability beyond the Skill's demonstrated requirements violates the principle of least privilege. Although the reviewed instructions do not attempt to misuse the filesystem, the unnecessary capability increases the potential impact of a future compromise, malicious update, or unsafe dependency.

Attack Path

  1. The Skill is installed or loaded with the declared filesystem capability.
  2. A later malicious modification, compromised dependency, or injected instruction causes the agent to invoke that capability.
  3. The compromised component requests reads or writes against files accessible within the tool's configured scope.
  4. If the platform does not enforce additional path restrictions or user approval, accessible local data could be disclosed or modified.

This is a defense-in-depth attack path. The current file contains no instruction that actively performs unauthorized filesystem operations.

Impact Assessment

The maximum impact depends on the filesystem tool's sandbox and path restrictions. Under a narrowly confined workspace, exposure may be limited to project files. Under a broad grant, a compromised Skill could potentially read sensitive user-accessible files or modify local content.

The declaration does not itself provide operating-system privilege escalation, and no evidence shows that it bypasses existing access controls. The confirmed ...[truncated 69 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented Skill behavior does not need local file access.
  • If future functionality requires map-file handling, request access only when that functionality is invoked.
  • Restrict access to a user-selected file or a dedicated application directory rather than granting broad filesystem scope.
  • Require explicit user confirmation before reading or modifying files.
  • Prefer read-only access when modification is unnecessary.
  • Document the precise files, operations, and retention behavior required by any future filesystem feature.
  • Apply platform sandboxing and deny access to credentials, configuration directories, and unrelated user data.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command invokes npx clawhub without pinning a specific package version, so installation behavior can change over time or be influenced by a compromised upstream release. This creates a supply-chain risk: a user or agent installing the skill could execute unreviewed code from the latest published package.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The lost_emergency trigger activates on any indication that the user is 'currently lost' and emits prescriptive emergency guidance without validating context, severity, location type, or whether the user is in immediate danger. In a safety-critical domain like wilderness navigation, overly broad automation can misfire on jokes, hypotheticals, or urban contexts and provide advice that is incomplete or inapplicable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.