Back to skill

Security audit

Sleep Hygiene Overhaul

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for sleep coaching, but it asks the agent to retain sensitive sleep and lifestyle information across sessions without clear user consent or deletion controls.

Install only if you are comfortable with the agent keeping sleep schedule, caffeine, alcohol, screen-use, and possible health-flag information across sessions. Prefer a pinned or trusted installer source, and ask the agent or platform how to inspect and delete the saved sleep state after the two-week protocol.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution Through npx

Content
View full analysis
- Fix your sleep in two weeks using evidence-based protocols — wind-down rituals, sleep anchoring, caffeine timing, and environment optimization display_name: "Sleep Hygiene Overhaul" openclaw: requires: tools: [calendar, filesystem] install: "npx clawhub install sleep-hygiene-overhaul" ``` ### Technical Analysis The installation command executes `clawhub` through `npx` without specifying a package version or integrity hash. When the package is not already available locally, `npx` can retrieve executable package content from the configured npm registry. Because the effective package version is resolved at installation time, the code executed by this command can differ from the version that was available when the Skill was audited. This creates a supply-chain trust dependency on the npm package, registry configuration, package maintainers, and any package lifecycle behavior. The finding does not establish that the current `clawhub` package is malicious. The vulnerability is the absence of controls that make installation reproducible and constrain which package artifact may execute. ### Attack Path 1. An attacker compromises the publishing account or supply chain for the unpinned `clawhub` package, takes over an abandoned package, or causes package resolution to use an untrusted registry. 2. The attacker publishes a malicious version that contains harmful CLI or package lifecycle behavior. 3. A user invokes the documented installation procedure. 4. `npx` resolves and downloads the attacker-controlled package version. 5. The malicious package code executes under the account and environment used to run the installer. ### Impact Assessment Successfully exploited package code would run with the privileges of the user invokin ...[truncated 502 chars]
Remediation
View remediation
` package reference. 2. Use a lockfile or an internally approved immutable package artifact so installation resolves reproducibly. 3. Verify the package integrity hash or signature before executing downloaded content. 4. Configure the command to use an explicitly trusted registry rather than inheriting an arbitrary user or CI registry configuration. 5. Review package lifecycle scripts and disable them where they are unnecessary. 6. Run installation with the least-privileged account available and avoid exposing unrelated environment secrets. 7. In CI environments, isolate installation in a restricted container with limited filesystem and network access. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:252
Finding

Persistent Storage of Sensitive Health and Lifestyle Information Without Defined Safeguards

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install instruction uses npx clawhub install sleep-hygiene-overhaul without pinning a specific package version or integrity reference. If the upstream package or dependency chain is compromised, users may execute unexpected code during installation, and the health-focused context does not reduce that supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly persists sleep patterns, alcohol use, anxiety indicators, possible sleep apnea flags, and adherence data across sessions, but it provides no user-facing disclosure, consent flow, retention policy, or minimization controls. This creates privacy risk because sensitive health and behavioral data may be stored longer than the user expects or exposed through state access, logs, backups, or downstream tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.