Back to skill

Security audit

Small Engine Repair

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward small-engine repair guide, with a disclosed but unpinned install command users should treat cautiously.

Review the install path before use, especially in privileged or credential-rich environments. Prefer a pinned or otherwise trusted ClawHub installer when available; the repair guidance itself is coherent and limited to small-engine troubleshooting.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation
install small-engine-repair" ``` 2. Verify the selected release against the package publisher's trusted documentation, provenance, and registry integrity metadata before adoption. 3. Use a lockfile or an equivalent immutable dependency manifest where the installation framework supports one. 4. Prefer a trusted internal registry or package mirror with allowlisting and retention controls for audited artifacts. 5. Enforce package signatures, provenance attestations, or cryptographic checksum verification where supported. 6. Run installation in a sandbox or least-privileged account without production credentials, sensitive environment variables, or unnecessary filesystem access. 7. Review updates explicitly and repeat the security audit before changing the pinned version. 8. Avoid relying on a mutable package tag such as `latest`, including implicitly through an omitted version. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill metadata instructs installation via npx clawhub install small-engine-repair without pinning a specific version or immutable package reference. This creates a supply-chain risk: a later malicious or compromised release of the CLI or dependency chain could be fetched and executed at install time, and npx commonly executes remote package code immediately.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.