Back to skill

Security audit

Start A Micro Business

Security checks for vulnerabilities and agentic risk

Overview

The skill is ordinary micro-business guidance, but it asks for unnecessary local file access and uses an unpinned installer command, so it should be reviewed before installation.

Review this skill before installing. The business advice itself is straightforward, but the publisher should remove the filesystem requirement unless a clear file-based feature exists and should pin the installer package/version or provide integrity controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

yaml
install: "npx clawhub install start-a-micro-business"

Technical Analysis

The installation command invokes the clawhub npm package through npx without specifying an exact version or integrity constraint. Depending on the local npm configuration and cache state, npx can retrieve and execute the current package release from the configured registry.

Because the package reference is mutable, the code executed during installation can differ from the code that existed when this skill was reviewed. If the package, publisher account, or configured registry is compromised, malicious CLI or package lifecycle code could run under the installing user's account.

Attack Path

  1. An attacker compromises the package publisher, publishes a malicious release, or controls the npm registry configured on the target system.
  2. The user follows the documented installation flow.
  3. npx resolves the unversioned clawhub package to the attacker-controlled release.
  4. The package's CLI implementation or applicable lifecycle code executes locally.
  5. The malicious code operates with the filesystem access, environment variables, network access, and other privileges available to the invoking user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user running the installation command. Depending on that user's permissions, the malicious package could access local files, read exposed environment variables or credentials, modify user-owned data, install additional software, or communicate with external systems.

The issue does not independently establish administrative access. Its scope is bounded by the privileges and isolation controls applied to the installation process.

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to an exact, reviewed version rather than relying on the latest available release.
  • Use the expected form supported by the installer, such as npx clawhub@<exact-version> install start-a-micro-business.
  • Record and verify the package source and integrity metadata where the package manager and deployment process support it.
  • Use a committed lockfile for any maintained installation wrapper or project-level dependency.
  • Disable or restrict unnecessary package lifecycle scripts during automated installation where operationally possible.
  • Execute installation in a sandbox or least-privileged environment without sensitive environment variables.
  • Periodically review the pinned release before deliberately upgrading it.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:11
Finding

Filesystem Capability Declared Without a Documented Functional Need

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11-12
Vulnerability Type: Excessive tool permission
Risk Level: Medium

yaml
requires:
  tools: [filesystem]

Technical Analysis

The skill declares access to the filesystem tool, but its documented behavior consists of conversational guidance about selecting, marketing, and operating a micro-business. No instruction in the audited file requires reading, creating, modifying, or deleting local files.

Granting an unnecessary filesystem capability violates least-privilege principles and unnecessarily expands the skill's security boundary. Although the audited instructions do not directly misuse the tool, a later malicious modification, prompt-injection payload, or unsafe surrounding context could attempt to leverage the declared capability.

Attack Path

  1. The skill is loaded with the declared filesystem capability.
  2. Attacker-controlled content enters the agent context through a future skill modification or another prompt-injection source.
  3. The injected instructions direct the agent to invoke the available filesystem tool.
  4. If runtime authorization and path restrictions are insufficient, the agent reads or modifies files unrelated to the skill's legitimate purpose.
  5. Retrieved information may be exposed through subsequent output, or modified files may affect the user or other local processes.

This path requires an additional malicious or compromised instruction source; the existing audited text does not itself instruct the agent to access local files.

Impact Assessment

The potential impact depends on the filesystem tool's runtime restrictions. With broad user-level access, misuse could expose documents, configuration files, source code, or locally stored secrets accessible to the agent process. Write access could permit modification or deletion of user-owned files.

The declaration alone does not demonstrate successful file ac ...[truncated 160 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the current workflow does not use it.
  • Default the skill to no local-system capabilities and add permissions only when a documented feature requires them.
  • If future functionality requires file access, expose a narrowly scoped directory rather than the user's general filesystem.
  • Prefer read-only access unless file creation or modification is essential.
  • Require explicit user approval for each sensitive file operation.
  • Enforce runtime path allowlists, deny access to credential and configuration locations, and maintain an audit log of file operations.
  • Reassess the threat model and document the exact filesystem use case before restoring the capability.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install instruction uses npx clawhub install start-a-micro-business without pinning a specific package version. This causes execution of whatever version is current at install time, which creates a supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly. The rest of the skill is benign business guidance, so the danger comes from the metadata install path rather than the content domain.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.