Back to skill

Security audit

Teaching Physical Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a straightforward teaching guide, but it asks for unnecessary filesystem access and uses an unpinned npx install command.

Review this before installing. The teaching content itself is aligned with its stated purpose, but install it only through a trusted, pinned ClawHub CLI path if possible, and avoid granting filesystem access unless the publisher explains why it is needed. For swimming, driving, knives, and tools, treat the skill as planning guidance only and use qualified supervision, protective equipment, and local legal requirements.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-15
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install teaching-physical-skills"

Technical Analysis

The installation metadata invokes clawhub through npx without specifying an exact reviewed version or package integrity value. When the package is not already available locally, npx may download and execute the currently resolved registry version. Consequently, the code executed during installation can differ from the code that was available when this Skill was audited.

Package entry points and lifecycle behavior execute with the privileges of the user running the installation. Compromise of the package, its registry account, or a transitive dependency could therefore introduce arbitrary code into the installation process.

The Skill also declares access to the filesystem tool, although its documented physical-skill teaching workflows do not identify a feature that requires filesystem access. This unnecessarily increases the potential scope of damage if the installation dependency or runtime behavior is compromised.

Attack Path

  1. An attacker compromises the clawhub package, its maintainer account, its dependency chain, or the package source selected by the user's registry configuration.
  2. The attacker publishes a malicious version that remains compatible with the unversioned package resolution.
  3. A user follows the installation metadata and runs npx clawhub install teaching-physical-skills.
  4. npx resolves and downloads the attacker-controlled version because no exact version or integrity constraint is specified.
  5. The malicious package executes through its command entry point or installation lifecycle with the invoking user's privileges.
  6. The payload may read, create, alter, or delete files accessible to that user, ...[truncated 936 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed version rather than relying on the latest registry resolution:
    yaml
    install: "npx --yes clawhub@X.Y.Z install teaching-physical-skills"
    
  2. Prefer a lockfile-backed installation process with package integrity hashes. Commit the lockfile and enforce immutable or frozen dependency installation in CI.
  3. Avoid implicit package downloading during execution. Install the verified CLI through a controlled provisioning step and invoke the trusted local binary afterward.
  4. Verify package provenance, registry source, signatures or attestations, and published integrity metadata before installation.
  5. Audit the pinned package and its complete transitive dependency tree, including lifecycle scripts and command entry points.
  6. Run installation with a non-privileged account in a sandbox or container that has no production credentials and only narrowly scoped filesystem access.
  7. Remove tools: [filesystem] unless a documented workflow genuinely requires it. If it is required, restrict access to a dedicated working directory and prohibit access to credentials, home-directory secrets, and unrelated project files.
  8. Add automated dependency monitoring and require explicit review before updating the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This skill provides detailed instruction for hazardous activities such as swimming, knife use, driving, and tool use, but the top-level description does not prominently foreground safety limits or clearly state that remote guidance is not a substitute for qualified in-person supervision. Because the content targets embodied skills with real injury risk, users may over-rely on the skill in contexts where professional instruction or direct supervision is necessary.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The install metadata invokes npx clawhub install teaching-physical-skills without pinning a specific package version. If the referenced package or one of its transitive dependencies is updated maliciously or unexpectedly, consumers may execute unreviewed code during installation, creating a supply-chain risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.