Back to skill

Security audit

Public Speaking Embodied

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly public-speaking coaching, but it asks for filesystem access and uses an unpinned installer, so users should review it before installing.

Install only if you are comfortable with the unpinned `npx` installer and the declared filesystem requirement; prefer a pinned or verified install path and run installation with least privilege. Treat the medication mention as a prompt to consult a licensed clinician, not as medical advice from the skill.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned npx Package Execution Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 14–17
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable code:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install public-speaking-embodied"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact, reviewed version or package integrity value. If the package is not already available locally, npx can retrieve it from the configured package registry and execute its command-line entry point.

Consequently, the code executed during installation may differ from the code that existed when this skill was reviewed. The effective behavior depends on the package version resolved at installation time, its transitive dependencies, registry configuration, and any package lifecycle behavior. The external clawhub package was not included in the audited project, so its implementation and integrity could not be verified as part of this audit.

This is a supply-chain weakness rather than evidence that the current skill contains an intentionally malicious payload.

Attack Path

  1. An attacker compromises the publishing account, package registry, package release process, or a transitive dependency associated with clawhub.
  2. The attacker publishes a malicious version that is eligible for resolution by the unpinned npx clawhub invocation.
  3. A user or installation system executes the command specified in SKILL.md.
  4. npx downloads or resolves the attacker-controlled package version.
  5. The malicious package code executes with the operating-system privileges and environmental access of the user running the installation.
  6. Depending on those privileges, the package could access local files, environment variables, credentials available to the process, or modify user-accessible system state.

Impact Assessment

Successfu ...[truncated 689 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact version that has been reviewed, rather than relying on the registry's current version resolution.
  2. Use a lockfile or equivalent immutable dependency manifest to pin transitive dependencies.
  3. Verify package integrity through registry integrity hashes, signed provenance, or an approved internal artifact repository.
  4. Disable or tightly control package lifecycle scripts where the installation workflow permits it.
  5. Run installation with a dedicated, least-privileged account in a sandbox or disposable environment.
  6. Prevent the installation process from accessing unrelated credentials and sensitive environment variables.
  7. Continuously scan and periodically re-review the pinned package and its transitive dependency graph before approving upgrades.
  8. Document the trusted package source and reject packages resolved from unexpected registries.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install instruction uses npx clawhub install public-speaking-embodied without pinning a specific package version. If the upstream package is changed, hijacked, or a malicious version is published, anyone following the instruction could execute unintended code at install time. The skill is otherwise benign in topic, but install commands are high-trust execution points, so the context does not reduce the supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill recommends a prescription beta-blocker for performance anxiety without sufficient safety framing, contraindication warnings, or a clear directive to rely on individualized medical advice. Even though it says 'prescribed by your doctor,' the guidance may still inappropriately normalize medication use for anxiety in a non-medical skill and could encourage unsafe self-directed treatment discussions. In this context, the public-speaking topic makes the advice less inherently suspicious than in unrelated harmful content, but it is still risky because it crosses into medical recommendation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.