Back to skill

Security audit

Parenting Psychology

Security checks for vulnerabilities and agentic risk

Overview

This skill provides disclosed parenting guidance and crisis-escalation advice, with ordinary install supply-chain cautions but no evidence of hidden or malicious behavior.

Before installing, consider pinning or otherwise verifying the ClawHub installer version. If your agent persists skill state or scheduled follow-ups, avoid storing more family or child information than needed and use crisis or medical professionals for safety, abuse, self-harm, substance-use, eating-disorder, or severe behavioral situations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned npm Package Execution During Skill Installation

Content
View full analysis
Remediation
View remediation
install parenting-psychology" ``` 2. Verify the selected package version and its transitive dependencies through a lockfile or an equivalent reproducible dependency mechanism. 3. Validate the package against a known integrity digest before execution where the installation platform supports integrity verification. 4. Explicitly configure and document the trusted npm registry to reduce dependency-confusion and registry-substitution risks. 5. Review the package's lifecycle scripts and CLI entry point before approving a version. Disable lifecycle scripts where compatible with the installation workflow. 6. Run installation under a least-privileged account or sandbox with restricted filesystem, credential, and network access. 7. Establish a controlled update process in which newer package versions are audited before the pinned version is changed. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level description is broad enough to match many everyday parenting or emotional-support conversations, which can cause the skill to activate outside narrowly intended contexts. Over-broad routing increases the chance of inappropriate specialization, unnecessary collection of sensitive family information, or the skill overshadowing safer/general response logic.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install instruction invokes npx clawhub install parenting-psychology without pinning a specific package version. That makes installation dependent on whatever version is current at execution time, creating a supply-chain risk where a compromised or breaking upstream release could execute unintended code during install.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'When to Use' section lists many common, loosely bounded situations without guardrails or negative examples, which broadens invocation scope. In a sensitive domain involving children, that can lead to over-triggering on distress or family-conflict conversations and produce advice in cases that may actually require crisis, legal, or clinical escalation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.