Back to skill

Security audit

Sharpening

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent sharpening guide, but it asks for unnecessary filesystem access and uses an unpinned installer while giving hands-on sharp-tool instructions without strong safety framing.

Review this before installing. The sharpening content is not deceptive, but users should prefer a pinned or trusted installer, question why filesystem access is required, and add their own safety precautions such as eye protection, secured workpieces, disconnected power sources, careful hand placement, and following local rules and manufacturer guidance.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis
- Every cutting tool you own is probably dull. A sharp knife is safer than a dull one. Here's how to fix all of them in 10 minutes. display_name: "Sharpening" submitted_by: HowToUseHumans last_reviewed: "2026-03-19" openclaw: requires: tools: [filesystem] install: "npx clawhub install sharpening" ``` ### Technical Analysis The installation command invokes `clawhub` through `npx` without specifying an exact package version, lockfile, or integrity hash. When the package is not already available from a trusted local installation, `npx` can retrieve and execute the version currently resolved by the configured package registry. Because the resolved package is mutable independently of this reviewed skill, the code executed during installation may differ from the code available when the skill was audited. A compromised package publisher account, registry compromise, malicious replacement release, or unexpected future release could therefore introduce arbitrary installation-time behavior. The requested `filesystem` capability is also broader than the informational sharpening guidance appears to require. Although this does not establish exploitation by itself, unnecessary filesystem access could increase the consequences of a compromised dependency. ### Attack Path 1. An attacker compromises the `clawhub` package, its publisher account, or the package distribution path. 2. The attacker publishes a malicious version that can be selected by the unversioned `npx clawhub` invocation. 3. A user follows the installation metadata and executes: ```shell npx clawhub install sharpening ``` 4. `npx` resolves and downloads the attacker-controlled package version. 5. The malicious package code or its lifecycle behavior execute ...[truncated 763 chars]
Remediation
View remediation
install sharpening" ``` 2. Verify the selected release against an expected package integrity hash or trusted signed provenance before execution. 3. Use a lockfile where the installation workflow supports one, and commit the lockfile with the reviewed artifact. 4. Restrict dependency retrieval to an approved registry using authenticated and integrity-protected configuration. 5. Review package lifecycle scripts and installation behavior before publishing the command. 6. Prefer a preinstalled, organization-managed `clawhub` binary over downloading and executing a package during each installation. 7. Remove the declared `filesystem` requirement if the skill does not genuinely need file access. If storage is required, restrict access to a dedicated application directory and apply least privilege. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command invokes npx clawhub install sharpening without pinning a specific package version or integrity-checked artifact. That allows supply-chain drift: a future malicious or compromised release of the referenced package could be executed at install time with the user's privileges.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The localization note says to 'Apply all instructions regardless of jurisdiction,' which can improperly suppress locale-specific safety, legal, or standards-based differences. While sharpening technique is broadly universal, a blanket override may cause the agent to ignore regional constraints on tool handling, workshop practices, or product-specific safety expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This skill gives detailed instructions for sharpening knives, axes, mower blades, chisels, scissors, and similar edged tools, but lacks a clear, prominent safety section warning about laceration risk, PPE, safe hand placement, securing workpieces, and power-tool hazards. Because the content encourages hands-on manipulation of sharp edges and includes power-tool-adjacent tasks, omission of explicit safety guidance increases the chance of user injury.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.