Back to skill

Security audit

Outdoor Recreation Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill content is ordinary outdoor advice, but its unpinned npx install command asks users to execute mutable remote installer code.

Review this skill before installing and prefer a pinned, reviewed installer version or a controlled ClawHub installation path. The outdoor guidance itself is coherent, but avoid running the unpinned npx command in an environment with sensitive files, credentials, or production access.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned npm CLI Package Allows Mutable Supply-Chain Execution

Content
View full analysis
Remediation
View remediation
install outdoor-recreation-skills" ``` 2. Verify the selected package version against a trusted integrity digest and preserve that verification in a lockfile or controlled installation manifest. 3. Require the official npm registry explicitly in controlled automation, and reject unexpected registry configuration or package provenance. 4. Run installation under a dedicated least-privilege account without access to production credentials, sensitive user files, or privileged system locations. 5. Prefer a preinstalled and centrally managed installer over downloading and executing an npm package at installation time. 6. Review each installer upgrade before changing the pinned version, including its CLI entry point, lifecycle scripts, transitive dependencies, and published provenance. 7. Where supported, use a trusted internal package mirror or allowlist that exposes only approved package versions. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install instruction uses npx clawhub install outdoor-recreation-skills without pinning a specific package/version, so consumers may execute whatever version npx resolves at install time. That creates a supply-chain risk: a compromised upstream package, typo-squatted dependency, or malicious new release could run arbitrary code during installation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.