Back to skill

Security audit

Someone Is Struggling

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent mental-health conversation guide, but it asks for filesystem access it does not appear to need and uses an unpinned npx installer.

Read this carefully before installing. The guidance content itself appears purpose-aligned, but the skill should not need filesystem access for this task, and the installation command should ideally pin the installer version or use an integrity-verified workflow. Install only if you trust the publisher and your host environment limits filesystem access appropriately.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Unnecessary Filesystem Permission Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-14
Vulnerability Type: Excessive tool permission
Risk Level: Medium

Complete Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]

Technical Analysis

The skill declares access to the filesystem even though its documented functionality consists entirely of conversational mental-health guidance. No instruction in the skill requires reading, writing, or modifying local files.

Granting a capability that is unrelated to the declared task violates the principle of least privilege. Although the reviewed file does not contain an instruction that actively abuses this access, exposing the filesystem unnecessarily increases the consequences of a future malicious update, indirect prompt injection, or unintended agent behavior.

Attack Path

  1. A user installs or activates the skill.
  2. The hosting agent grants the declared filesystem tool to the skill context.
  3. A later malicious skill update, injected instruction, or unintended model action directs the agent to access local files.
  4. The agent may read or modify files allowed by the filesystem tool's effective sandbox and operating-system permissions.
  5. Retrieved information could subsequently be exposed through agent output or used to influence later actions.

The reviewed version does not implement steps 3-5; the finding concerns the unnecessary capability that makes such a path possible.

Impact Assessment

The maximum scope depends on the host's filesystem sandbox and the privileges of the process running the agent. Potentially exposed assets include files available within that scope, such as project data, configuration files, or user documents. If write access is included, files within the permitted scope could also be altered or deleted. This declaration does not itself grant operating-system privilege escalation beyond the host process.

Remediation
View remediation

Remediation Suggestions

  • Remove the filesystem requirement because the current skill does not use it:

    yaml
    openclaw:
      requires:
        tools: []
    
  • If the surrounding platform permits omission of the requires block, remove the block entirely.

  • If a future feature genuinely requires file access, request it only when needed and restrict it to explicitly approved paths and operations.

  • Prefer read-only access over read-write access where possible.

  • Enforce host-level sandboxing so skill permissions cannot exceed the minimum directories required for operation.

  • Add a review check that rejects tool declarations unsupported by documented skill behavior.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Mutable and unverified installation dependency
Risk Level: Medium

Complete Code Snippet:

yaml
install: "npx clawhub install someone-is-struggling"

Technical Analysis

The installation metadata invokes npx without pinning an audited version of the clawhub package. Depending on the local npm configuration and cache state, npx can retrieve the currently published package from a registry and execute its command-line entry point.

Because neither a version nor an integrity value is specified, the effective installer code can change after this skill has been reviewed. The project contains no lockfile, checksum, vendored installer, or other mechanism that allows the executed package contents to be verified against a known-good artifact.

No evidence was found that the current clawhub package is malicious. The vulnerability is the unsafe trust model: mutable third-party code may be downloaded and executed during installation without cryptographic pinning at the skill level.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution channel, or another component involved in package resolution.
  2. The attacker publishes a malicious version under the package name resolved as clawhub.
  3. A user follows the installation metadata and runs the unversioned npx command.
  4. npx resolves and downloads the attacker-controlled release.
  5. The package's command-line entry point or lifecycle behavior executes with the privileges of the user running the installation command.
  6. The malicious package can perform actions allowed to that user, such as accessing files, modifying user-level configuration, installing additional components, or initiating network connections.

Exploitation requires compromise or malicious control of the resolved dependency or its distribution path; no such compr ...[truncated 552 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to a specific reviewed version, for example:

    yaml
    install: "npx --yes clawhub@<reviewed-version> install someone-is-struggling"
    
  • Use npm lockfiles and integrity metadata where the installation workflow supports them.

  • Verify the package source, publisher identity, registry, and cryptographic integrity before execution.

  • Prefer installing the package as a pinned dependency and invoking its locally resolved binary rather than downloading mutable code on demand.

  • Run installation in a restricted environment with minimal filesystem, credential, and network access.

  • Establish an update process in which each new package version is reviewed before the pinned version is changed.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill metadata includes an install command using npx clawhub install someone-is-struggling without pinning a specific package version. Because npx resolves and executes code at install/runtime from the registry, an upstream compromise, typo-squatted package, or malicious new release could cause unreviewed code execution in the user's environment. The skill's subject matter is benign, but that does not reduce the supply-chain risk from the unpinned installer reference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.