Back to skill

Security audit

Romantic Relationship Maintenance

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly relationship guidance, but it requests filesystem access it does not need and uses an unpinned npx install command.

Review this before installing because it grants filesystem capability that is not explained by the relationship-guidance purpose. Prefer a version-pinned install path, and only use it in an environment where unnecessary file access is removed or tightly sandboxed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install romantic-relationship-maintenance"

Technical Analysis

The installation command invokes the clawhub package through npx without specifying a reviewed version or integrity hash. Depending on the local npm environment and cache state, npx can retrieve and execute the package version currently resolved by the configured registry.

This creates a supply-chain trust boundary outside the audited project. The behavior of the command can change after this skill has been reviewed if the package, package owner, registry account, dependency tree, or configured registry is compromised. The project does not provide a lockfile, checksum, signature, or version constraint that would bind installation to a known artifact.

Attack Path

  1. An attacker compromises the clawhub package, one of its executable dependencies, its publisher account, or a registry used by the victim.
  2. The attacker publishes a malicious package version containing harmful CLI or lifecycle behavior.
  3. A user follows the skill installation metadata and runs the unpinned npx clawhub install romantic-relationship-maintenance command.
  4. npx resolves and downloads the attacker-controlled version.
  5. The malicious package executes with the permissions of the user running the installation.

This path depends on a supply-chain or registry compromise; the audited file does not itself contain a malicious payload.

Impact Assessment

Successful exploitation could execute arbitrary code with the installing user's privileges. Depending on that user's permissions, the payload could read or modify accessible files, obtain environment variables and credentials, alter installed skills, make network requests, or compromise the user's development envir ...[truncated 96 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specific reviewed version, for example by using an explicit version in the npx invocation.
  • Prefer an installation workflow backed by a lockfile and verified package integrity metadata.
  • Configure npx to reject unexpected package installation where operationally appropriate.
  • Use only a trusted registry and document the expected registry source.
  • Review the resolved package and its transitive dependencies before updating the pinned version.
  • Where supported, verify signed package provenance or publish and validate a cryptographic checksum for the expected artifact.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:11
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11-15
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install romantic-relationship-maintenance"

Technical Analysis

The skill declares access to the filesystem tool, but its documented behavior consists of providing relationship guidance, check-in procedures, communication scripts, therapy referrals, and safety resources. No instruction in the reviewed file establishes a legitimate need to read, create, modify, or delete local files.

Granting a capability that is unrelated to the skill's purpose violates the principle of least privilege. The declaration is not, by itself, evidence that local files are accessed or exfiltrated. However, it unnecessarily expands the available attack surface if hostile conversation content, another loaded instruction, or a future modification induces the agent to use the capability.

Attack Path

  1. The relationship-maintenance skill is loaded with its declared filesystem capability.
  2. Attacker-controlled conversation content or another conflicting instruction attempts to induce filesystem operations.
  3. Because the unrelated permission is already available, the agent may attempt to read or modify files that are not necessary for relationship guidance.
  4. Any retrieved data could be exposed in the session, or writable files could be altered within the filesystem tool's authorization boundary.

Exploitation requires an additional instruction-manipulation condition; no direct filesystem access instruction was found in the audited skill.

Impact Assessment

The maximum impact is bounded by the filesystem tool's sandbox and the privileges of the agent process. If broadly configured, the capability could expose user-readable local information or permit modification of user-writable files. The reviewe ...[truncated 122 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented workflow does not depend on local file access.
  • Declare no tools unless a concrete feature requires them.
  • If future functionality genuinely requires filesystem access, request the narrowest possible permission, restrict access to a dedicated application directory, and prefer read-only access where feasible.
  • Require explicit user approval before accessing files and disclose the exact path and purpose.
  • Add automated policy checks that reject capabilities not referenced by the skill's documented actions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install instruction uses npx clawhub install romantic-relationship-maintenance without pinning a specific package version, so execution depends on whatever version is current at install time. If the upstream package is compromised, typo-squatted, or updated with malicious behavior, users could execute unreviewed code during installation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.