Back to skill

Security audit

Play Physical Instrument

Security checks for vulnerabilities and agentic risk

Overview

The skill is a straightforward beginner instrument guide, but it asks for broad filesystem access and uses an unpinned npx installer that are not needed for that purpose.

Review this before installing because it requests filesystem capability despite being an educational guide, and its installer runs an unpinned npx package. Prefer a pinned or trusted installer version and avoid granting filesystem access unless the publisher explains why it is needed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

yaml
install: "npx clawhub install play-physical-instrument"

Technical Analysis

The installation instruction invokes the clawhub npm package through npx without specifying an exact package version or integrity hash. Depending on the local npm configuration and cache state, npx may download the currently published package and execute its CLI code.

This creates a supply-chain risk because the code executed during installation can differ from the code that was available when the Skill was reviewed. A compromised package publisher account, malicious replacement release, or registry compromise could therefore introduce arbitrary code into the installation process.

Attack Path

  1. An attacker compromises the npm package, its publisher account, or the configured package registry.
  2. The attacker publishes a malicious version under the package name resolved by npx clawhub.
  3. A user follows the documented installation command.
  4. npx retrieves the malicious or compromised package version.
  5. Package lifecycle scripts or CLI initialization code execute with the privileges of the user running the command.
  6. The malicious package can access files, environment variables, credentials, and network resources available to that user.

Impact Assessment

Successful exploitation could result in arbitrary code execution under the installing user's account. The accessible scope would include that user's files, environment variables, development credentials, and network permissions. If the command were run from an elevated shell, the impact could extend to system-wide modification. The file itself does not demonstrate that the current package is malicious; the risk arises from mutable, unpinned package resolution.

Remediation
View remediation

Remediation Suggestions

  • Pin the installer package to an exact, reviewed version, for example by using an explicit version rather than the latest registry release.
  • Enforce package integrity verification through a lockfile, cryptographic checksum, signed release, or trusted package provenance mechanism.
  • Document and enforce the expected package registry to prevent resolution through an untrusted registry or mirror.
  • Review package lifecycle scripts before installation and disable them where they are unnecessary.
  • Prefer a reviewed local installer or a distribution mechanism whose contents are immutable after security review.
  • Run installation with a non-privileged account and in a sandbox with only the filesystem and network access needed for installation.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12-15
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install play-physical-instrument"

Technical Analysis

The Skill requests access to the filesystem tool, but its documented purpose is to provide instrument-selection, practice, and learning guidance. The reviewed instructions do not identify a legitimate operation that requires reading or modifying arbitrary local files.

Granting a capability beyond the Skill's functional requirements violates the principle of least privilege. The declaration is not itself evidence that files are currently accessed maliciously. However, it increases the impact of future instruction injection, compromised Skill content, unsafe automation, or an implementation defect by making a sensitive local capability available unnecessarily.

Attack Path

  1. The Skill is installed or loaded with its declared filesystem capability.
  2. Malicious instructions are subsequently introduced through compromised Skill content, an injected interaction, or a vulnerable surrounding agent workflow.
  3. Those instructions direct the agent to invoke the already-authorized filesystem tool.
  4. The agent reads or modifies files within the filesystem tool's permitted scope.
  5. Local information may be disclosed, corrupted, or used to support further attacks.

Exploitation depends on an additional mechanism capable of influencing the agent's instructions; no such mechanism was identified in the reviewed file. The unnecessary permission nevertheless expands the potential blast radius.

Impact Assessment

The obtainable privileges are limited by the host platform's filesystem-tool policy and the operating-system account running the agent. If the tool permits broad access, exposed data could include user documents, project sourc ...[truncated 244 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented educational workflow does not require local file access.
  • If persistent progress tracking is required, use a dedicated state-storage interface rather than a general-purpose filesystem capability.
  • If a file is strictly necessary, constrain access to one Skill-owned, non-sensitive state file or directory.
  • Separate read and write permissions and grant only the specific operation required.
  • Require explicit user confirmation before accessing files outside a dedicated Skill data directory.
  • Add runtime policy enforcement that rejects filesystem operations unrelated to the Skill's declared instrument-learning purpose.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level description is broad enough to match many ordinary wellness, hobby, stress-relief, and parenting requests. Over-broad activation increases the chance this skill is invoked when a narrower or more appropriate skill should handle the request, which can degrade routing quality and cause unnecessary tool use or state handling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install metadata invokes npx clawhub install play-physical-instrument without pinning a specific package version. npx resolves and executes code from the registry at install time, so a compromised upstream package, typo-squatted dependency, or unexpected latest release could result in arbitrary code execution in the user's environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The When to Use section lists many broad triggers like stress relief, creative outlet, screen-free hobby, and activities with kids, without saying when not to activate. This can cause over-triggering on common conversational requests and make the agent select this skill in contexts only loosely related to physical instrument instruction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.