Back to skill

Security audit

Shift Work Recovery

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its shift-work recovery purpose, but it asks for unnecessary filesystem access and gives specific supplement/medication-related health guidance that should be reviewed carefully.

Before installing, consider waiting for a version that removes filesystem access, pins the installer, and adds clear medical disclaimers and screening around supplements or medications. The current artifact does not show data theft or destructive behavior, but these issues make it appropriate for careful review.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned npm CLI Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
install: "npx clawhub install shift-work-recovery"

Technical Analysis

The installation command invokes clawhub through npx without specifying a reviewed package version or integrity constraint. If the package is not already installed locally, npx may retrieve the current package release from the configured npm registry and execute it with the installing user's privileges.

Because the effective executable can change after this Skill has been reviewed, the repository alone does not establish which implementation will run. The project also contains no lockfile, package manifest, integrity hash, or vendored implementation with which to verify the fetched dependency. This creates a mutable dependency boundary and exposes installation to upstream account compromise, malicious package publication, registry substitution, or an unexpectedly unsafe future release.

No evidence indicates that the current clawhub package is malicious. The vulnerability is the installation mechanism's inability to guarantee that the reviewed dependency is the one ultimately executed.

Attack Path

  1. An attacker compromises the upstream clawhub package, its publisher account, or the package source selected by the user's npm configuration.
  2. The attacker publishes a malicious or compromised version under the package name resolved by npx.
  3. A user follows the Skill installation metadata and runs npx clawhub install shift-work-recovery.
  4. npx retrieves the mutable package version because no exact version or integrity value is specified.
  5. Package installation hooks or CLI code execute with the privileges of the user performing the installation.
  6. The malicious dependency can access data and resources available to th ...[truncated 619 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the CLI to an exact, reviewed version, for example through a command equivalent to npx clawhub@<reviewed-version> ....
  • Use a lockfile and registry-supported integrity verification where applicable.
  • Document the expected official package registry and publisher identity.
  • Prefer installing the CLI as a declared, locked dependency and invoking its local binary rather than dynamically retrieving the latest package.
  • Review package lifecycle scripts and the complete transitive dependency tree before approving updates.
  • Execute installation in an isolated, unprivileged environment without production credentials or unnecessary filesystem access.
  • Introduce an update process that reviews and tests each new pinned version before changing the installation metadata.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: Excessive tool permission
Risk Level: Low

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install shift-work-recovery"

Technical Analysis

The Skill declares access to the filesystem tool, but its documented behavior consists of providing shift-work sleep guidance, calculating schedules from user-provided information, maintaining a logical session-state schema, and defining reminder triggers. No instruction in the audited file requires reading or writing arbitrary local files.

The session-state block at lines 289-301 defines fields such as shift pattern, sleep hours, and completion flags, but it does not specify a legitimate need for unrestricted filesystem operations. Granting a capability that is not necessary for the stated task expands the Skill's authority beyond least privilege.

This declaration is not itself evidence that files are currently accessed or exfiltrated. The risk arises because a future compromised revision, injected instruction, or unsafe runtime interpretation could use the already granted capability without requiring an additional permission decision.

Attack Path

  1. The Skill is installed or loaded with its declared filesystem capability.
  2. The runtime grants the Skill access to a filesystem tool even though normal shift-recovery guidance does not require it.
  3. A malicious future modification, prompt-injection path, or compromised dependency causes the agent to issue filesystem operations.
  4. The tool reads or modifies files available within its runtime scope.
  5. Retrieved data could subsequently influence responses or be disclosed through any output or communication channels available to the agent.

This path requires additional malicious or unsafe behavior; none was found in the current Skill instructions. Removing the unu ...[truncated 673 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented workflow does not need file access.
  • Store transient session fields through the platform's dedicated, scoped state mechanism rather than arbitrary files.
  • If persistence is genuinely required, grant access only to a dedicated application-state directory.
  • Restrict permitted operations to the minimum necessary set, such as read-only or write-only access to named files.
  • Require explicit user authorization before expanding the filesystem scope.
  • Add automated validation that rejects Skills requesting tools that are not exercised by their documented actions.
  • Reassess permissions whenever new functionality is introduced rather than granting capabilities preemptively.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The install command invokes npx clawhub install shift-work-recovery without pinning a specific package version, which creates a supply-chain risk: the resolved package can change over time or be replaced by a compromised release. Because installation commands may be executed by users or automation, a malicious upstream package update could lead to arbitrary code execution during setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill gives concrete melatonin dosing/timing guidance and later references prescription wakefulness and sleep medications without an upfront medical disclaimer or strong clinician-escalation framing. In a health-oriented skill for fatigued shift workers, this can cause users to self-medicate, overlook contraindications, or delay evaluation for depression, sleep apnea, medication interactions, pregnancy, or other medical issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.