Back to skill

Security audit

Neighbor Mutual Aid

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it encourages creating and distributing sensitive neighbor contact, emergency, and home-access information without enough privacy controls.

Review this skill carefully before installing or using it. Use it only with explicit opt-in from each neighbor, collect the minimum information needed, keep medical or vulnerability details out of general shared sheets, do not broadly share keys or lockbox codes, store documents in access-controlled places, and define how old copies are destroyed and access is revoked when someone leaves the network.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned CLI Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable code:

yaml
install: "npx clawhub install neighbor-mutual-aid"

Technical Analysis

The installation instruction invokes clawhub through npx without specifying an exact package version, integrity digest, or trusted registry. When the package is not already available locally, npx can retrieve and execute the package currently resolved by the configured npm registry.

This creates a supply-chain risk because the code executed during installation can differ from the code reviewed at audit time. A compromised package release, maintainer account, registry configuration, or dependency could cause attacker-controlled CLI or package lifecycle code to run.

The instruction does not itself prove that the current package is malicious. The vulnerability is the absence of controls that ensure users execute the same audited artifact.

Attack Path

  1. An attacker compromises the package, one of its dependencies, its publisher account, or the package source selected by the user's npm configuration.
  2. The attacker publishes a malicious version or replaces a dependency used by the CLI.
  3. A user follows the documented npx clawhub install neighbor-mutual-aid command.
  4. npx resolves and downloads the attacker-controlled version because no exact version or integrity value is required.
  5. Malicious CLI or lifecycle code executes with the privileges of the user running the command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the attacker could access user-readable files, modify project files, steal locally available credentials, install additional packages, or alter the installed skill. This instruction does not independently provi ...[truncated 116 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to an exact, audited version rather than relying on the latest registry resolution.
  • Use package-lock or equivalent lock metadata and verify package integrity hashes.
  • Explicitly configure and document the trusted package registry.
  • Disable or carefully review lifecycle scripts where feasible.
  • Prefer a separately verified installation process that does not implicitly download and execute mutable remote code.
  • Regularly audit the installer and its complete transitive dependency tree.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:124
Finding

Unsafe Collection and Distribution of Sensitive Personal and Physical-Access Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:124, SKILL.md:142, SKILL.md:199, and SKILL.md:246-249
Vulnerability Type: Insecure handling of plaintext sensitive information
Risk Level: Medium

Vulnerable code excerpts:

text
Phone: _______________   Email (optional): _______________
text
   with mobility issues, medication-dependent, etc.)
text
PRINT THIS. Put it on your fridge. Give a copy to every
participating household.
text
1. Exchange house keys or provide lockbox codes
2. Each pet owner writes a one-page care sheet:
   - Feeding schedule, amounts, brand
   - Medication if any

Technical Analysis

The workflow solicits and processes multiple classes of sensitive data, including telephone numbers, email addresses, home addresses, health or mobility needs, medication dependency, resource and equipment inventories, and pet medication information. It also recommends exchanging physical keys or lockbox codes.

The resulting contact sheet is intended to be printed, placed on refrigerators, and copied to all participating households. Other portions of the skill suggest shared notes, documents, spreadsheets, and group messaging, but no access-control, encryption, retention, secure-disposal, participant-removal, or credential-revocation requirements are defined.

SKILL.md:333 states that the contact sheet should remain within the network and should not be shared with outside parties. That policy reduces intended disclosure but does not protect against misplaced paper copies, compromised online accounts, unauthorized household members, former participants, or screenshots and forwarded messages. Physical-access secrets such as lockbox codes require stronger controls than a general neighborhood contact list.

Attack Path

  1. Residents provide contact details, addresses, medical support needs, equipment information, medication details, or lockbox acces ...[truncated 1561 chars]
Remediation
View remediation

Remediation Suggestions

  • Apply data minimization: collect only information necessary for a specific, consented purpose.
  • Do not place health details, medication information, keys, or lockbox codes in the general contact sheet.
  • Store physical-access credentials separately and disclose them only to individually authorized caregivers.
  • Require explicit, field-level consent before collecting or distributing personal information.
  • Use authenticated, access-controlled, and encrypted storage instead of publicly accessible shared links or unrestricted spreadsheets.
  • Define retention periods and require secure deletion or destruction of obsolete digital and paper copies.
  • Establish a participant-removal procedure that revokes document access and rotates affected lockbox codes.
  • Maintain a key-custody record and require prompt replacement of lost or unreturned keys.
  • Provide an incident-response procedure for lost sheets, compromised accounts, exposed codes, and unauthorized disclosure.
  • Use role-specific emergency lists so each participant receives only the information needed for their assigned responsibilities.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill specifies installation via npx clawhub install neighbor-mutual-aid without pinning a package version or integrity reference, which makes execution depend on whatever version is current at install time. If the upstream package is compromised, typosquatted, or changed maliciously, users could execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This skill encourages collecting, storing, and redistributing neighbors' phone numbers, addresses, emergency needs, key-exchange status, and household vulnerability information in a shared contact sheet. Even though the skill says participation is voluntary and the sheet stays within the network, it lacks strong data-minimization, consent, retention, and secure-storage guidance, so misuse or accidental disclosure could expose sensitive personal and physical-security information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.