Back to skill

Security audit

Survival Basics

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent home repair, plumbing, and cooking guide with some ordinary privacy and install-supply-chain cautions, but no evidence of deception or harmful behavior.

Before installing, use a trusted or pinned installer where possible, and avoid letting the skill permanently store household locations, budget details, dietary restrictions, or food-insecurity information unless you want that remembered.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation
install survival-basics" ``` 2. Use a lockfile and verify package integrity through the package manager's supported integrity metadata. 3. Configure and document the expected trusted registry rather than relying on ambient registry configuration. 4. Review the pinned package and its transitive dependencies before publication. 5. Prefer a locally installed, verified installer over automatically downloading and executing the latest remotely resolved package. 6. Run installation with the least-privileged account possible and without unnecessary secrets in the environment. 7. Establish an update process in which new package versions are audited before the pinned version is changed. ]]>

other

Note
Location
SKILL.md:566
Finding

Unbounded Cross-Session Retention of Household and Personal-Vulnerability Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase "Use when someone needs practical self-sufficiency skills for home and food" is very broad and not tied to specific trigger phrases or exclusion conditions. Because "practical self-sufficiency" can cover many everyday requests, this may cause the skill to be invoked outside its intended repair/plumbing/cooking scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The install command invokes npx clawhub install survival-basics without pinning a specific package version. That allows the fetched package or transitive behavior to change over time, creating a supply-chain risk where a later malicious or compromised release could be executed in the user's environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Items like "Wants to eat well on a tight budget" and "New homeowner or renter who's never fixed anything" are common situations rather than specific activation criteria. Without explicit limits or negative examples, the skill could be selected for a wide range of generic food, budgeting, or home questions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.