Back to skill

Security audit

Negotiation Trade

Security checks for vulnerabilities and agentic risk

Overview

This skill is mainly negotiation advice, but it requests unnecessary filesystem access and uses an unpinned external installer, so it should be reviewed before installation.

Install only if you are comfortable with the unpinned `npx` installer and the requested filesystem capability. Prefer a pinned, integrity-verified install path and remove or restrict filesystem access unless a concrete file-based feature is added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Package Execution During Skill Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install negotiation-trade"

Technical Analysis

The installation command invokes clawhub through npx without specifying a package version or integrity hash. If the package is not available locally, npx can retrieve and execute the version currently resolved by the configured package registry.

Consequently, the executable installation behavior is not fully represented by the reviewed project contents and may change after the audit. Compromise of the package publisher, registry account, package distribution channel, or a future package release could cause arbitrary code to run during installation.

Attack Path

  1. An attacker compromises the package publisher, registry account, or package distribution process associated with the resolved clawhub package.
  2. The attacker publishes a malicious or backdoored package version.
  3. A user executes the documented installation command.
  4. npx resolves and downloads the unpinned package version.
  5. Package lifecycle behavior or the package executable runs with the installing user's privileges.
  6. The malicious package can access or modify resources available to that user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing installation. Depending on the local environment, this could expose user-readable files, authentication material available to the process, project data, and writable system resources. The package could also alter files or install additional components within the user's permission boundary.

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specifically reviewed version rather than relying on the latest registry resolution.
  • Use an explicit trusted registry and enforce lockfile or equivalent package-resolution controls.
  • Verify package integrity using a trusted checksum, signature, or registry integrity metadata before execution.
  • Review package lifecycle scripts and transitive dependencies for the pinned release.
  • Run installation in a restricted environment without unnecessary credentials or access to sensitive files.
  • Prefer a distribution mechanism that separates package retrieval from execution and allows the retrieved artifact to be inspected first.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-14
Vulnerability Type: Excessive tool permission
Risk Level: Low

yaml
openclaw:
  requires:
    tools: [filesystem]

Technical Analysis

The Skill requests general filesystem tooling, but its documented functionality consists of conversational negotiation guidance, declarative state fields, and reminder triggers. No reviewed instruction establishes a legitimate need to read or modify arbitrary local files.

Granting a capability that is unnecessary for the stated task increases the effect of any future instruction compromise, malicious update, prompt injection, or unintended agent behavior. The declaration does not show a path restriction or a read-only boundary, so the available access may be broader than required.

Attack Path

  1. The Skill is installed or loaded with its declared filesystem capability.
  2. The agent encounters attacker-controlled content, compromised Skill instructions, or a malicious future update.
  3. The hostile instructions direct the agent to invoke the filesystem tool.
  4. The agent reads or modifies accessible local files even though such access is unrelated to negotiation guidance.
  5. Information may then be exposed through agent output, or writable files may be altered within the tool's permission boundary.

Impact Assessment

The attainable privileges depend on the filesystem tool's runtime sandbox and the host user's permissions. If unrestricted, exploitation could expose local documents, configuration files, project content, or credentials readable by the process. If write access is available, an attacker could modify user-writable files. No direct malicious filesystem operation is present in the reviewed Skill, so this finding concerns excessive capability and increased attack surface rather than demonstrated exploitation.

Remediation
View remediation

Remediation Suggestions

  • Remove the filesystem tool requirement because it is not necessary for the documented negotiation workflow.
  • If state persistence is required, replace general filesystem access with a narrowly scoped structured state store.
  • Restrict any unavoidable file access to an application-specific directory and explicitly deny access outside it.
  • Prefer read-only access unless file modification is essential.
  • Require user confirmation before accessing files and disclose the exact path and intended operation.
  • Avoid storing sensitive negotiation, medical, financial, landlord, or contractor information in plaintext local files.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install command invokes an external package via npx clawhub without pinning an exact version, which makes the skill dependent on whatever package version is current at install time. If the upstream package is compromised, typo-squatted, or publishes a malicious update, users could execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L069 says the skill applies when someone is facing "any price negotiation and feels unprepared," which is much broader than the concrete scenarios elsewhere in the file. This can overlap with ordinary conversation and makes it unclear where the skill should not activate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.