Back to skill

Security audit

Textile Clothing Repair

Security checks for vulnerabilities and agentic risk

Overview

This clothing-repair skill is mostly instructional, but it asks for unnecessary filesystem access and defines an ongoing location-based reminder without clear user opt-in.

Install only if you are comfortable reviewing the requested permissions. The publisher should remove filesystem access, make location-based recommendations user-directed, and require explicit consent with a cancellation path for recurring reminders.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:13
Finding

Unnecessary Filesystem Permission Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13-15
Vulnerability Type: Excessive tool permission
Risk Level: High

Vulnerable Code:

yaml
  openclaw:
    requires:
      tools: [filesystem]
    install: "npx clawhub install textile-clothing-repair"

Technical Analysis

The skill explicitly requests access to the filesystem, but its documented functionality consists of providing textile-repair instructions and maintaining simple repair-related state. No operation described in the skill requires reading, creating, modifying, or deleting local files.

Granting an agent a filesystem capability that is not necessary for its stated purpose violates the principle of least privilege. If the skill's instructions, runtime state, or execution context were subsequently manipulated, the unnecessary capability could provide a path to access files outside the legitimate clothing-repair workflow.

Attack Path

  1. A user installs or activates the skill.
  2. The agent runtime processes the requires.tools declaration.
  3. The runtime grants the skill filesystem access.
  4. A maliciously modified skill version, injected instruction, or compromised execution context directs the agent to invoke the filesystem tool.
  5. The agent reads or modifies files unrelated to clothing repair, subject to the filesystem tool's sandbox and operating-system permissions.

Impact Assessment

The accessible scope depends on restrictions enforced by the host runtime. In an insufficiently sandboxed environment, the capability could expose user documents, application configuration, source code, cached data, or other files available to the agent process. If write operations are permitted, it could also enable unauthorized file modification or deletion.

The reviewed skill does not itself contain instructions to access such files; the risk arises from granting an unnecessary high-impact capability that could be abused ...[truncated 30 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the skill's required tools because the documented workflow does not need file access.
  • If a future feature legitimately requires file operations, request access only when that feature is invoked and after explicit user approval.
  • Restrict any necessary access to a dedicated application directory rather than the user's general filesystem.
  • Enforce read-only access unless writes are essential.
  • Add runtime policy checks that reject undeclared paths, traversal sequences, symbolic-link escapes, and access to credentials or configuration directories.
  • Document each requested capability and its concrete functional justification.

T06 · System Persistence

Error
Location
SKILL.md:442
Finding

Location-Dependent Recurring Cross-Session Automation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 442-446
Vulnerability Type: Persistent scheduled automation
Risk Level: High

Vulnerable Code:

yaml
  - name: seasonal_wardrobe_check
    condition: "user_location IS SET"
    schedule: "March 15 and September 15 annually"
    action: "Season change coming. Good time to inspect stored clothing for moth damage, check buttons on coats, and treat any stains before they set permanently."

Technical Analysis

The skill defines an annually recurring trigger conditioned on user_location. If the host runtime interprets this block operationally, the trigger outlives the immediate skill invocation and causes future actions on fixed dates.

This behavior is not necessary to answer an on-demand clothing-repair request. It introduces cross-session persistence and implies that location-related state must remain available for later evaluation. The trigger contains no explicit consent requirement, expiration date, cancellation workflow, or retention policy.

Although the scheduled message is benign in content, the persistence mechanism creates an unnecessary long-lived execution hook. A later malicious package update or unauthorized modification could potentially alter the action while an existing recurring trigger remains registered.

Attack Path

  1. The user activates the skill and location information becomes available to the agent.
  2. The condition user_location IS SET evaluates as true.
  3. A runtime that supports the declared automation registers the annual schedule.
  4. The original skill session ends, but the scheduled trigger remains active.
  5. On March 15 and September 15, the runtime executes or emits the configured action without a new user request.
  6. If the stored automation definition or referenced skill content can later be modified, a compromised update could change what the persistent trigger performs.

Impact Assessment

...[truncated 562 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the seasonal_wardrobe_check recurring trigger from the default skill behavior.
  • Present reminders as an optional feature and obtain explicit, informed consent before registering one.
  • Show the exact schedule, retained data, inherited permissions, and cancellation method during consent.
  • Avoid using or retaining precise location; allow the user to select a season or hemisphere directly.
  • Add an expiration date and require periodic renewal rather than creating an indefinite annual trigger.
  • Ensure scheduled actions run without filesystem or other unnecessary tool permissions.
  • Store an immutable copy of the approved action so that later package updates cannot silently change existing scheduled behavior.
  • Provide a visible interface for listing and deleting all reminders created by the skill.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Resolution and Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Mutable third-party installation dependency
Risk Level: Medium

Vulnerable Code:

yaml
    install: "npx clawhub install textile-clothing-repair"

Technical Analysis

The installation command invokes clawhub through npx without specifying an audited package version or integrity digest. Depending on the local npm configuration and cache, npx may resolve and execute package content from a remote registry.

Because the resolved package is mutable, the code executed when a user installs the skill may differ from the code that was previously reviewed. Registry compromise, maintainer-account compromise, package takeover, or a malicious future release could therefore introduce arbitrary installation-time behavior.

The project contains only SKILL.md; it does not vendor the installer implementation or provide a lockfile or integrity metadata that would allow the effective installer payload to be verified from this artifact. This finding identifies unsafe dependency resolution, not evidence that the current clawhub package is itself malicious.

Attack Path

  1. An attacker compromises the registry package, its publisher account, or the relevant package-distribution path.
  2. The attacker publishes a malicious version under the package name resolved by npx.
  3. A user follows the documented installation command.
  4. npx resolves the mutable package version and downloads its content.
  5. Package lifecycle or command code executes with the privileges of the user running the installer.
  6. The malicious package can access resources available to that process before or while installing the requested skill.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the installing user's privileges. Potential consequences include reading user-accessible files, modifying configuration, insta ...[truncated 310 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to an explicitly audited version, for example by using an exact package version rather than an unqualified package name.
  • Verify the package using an expected registry integrity digest or signed provenance before execution.
  • Prefer a trusted, preinstalled installer whose version is managed by the host platform.
  • Disable or audit npm lifecycle scripts where possible.
  • Execute installation in a sandbox with restricted filesystem, network, environment-variable, and credential access.
  • Avoid running the installer with administrative privileges.
  • Maintain a lockfile or equivalent immutable dependency manifest and review dependency changes before release.
  • Use registry allowlists and package-signing or provenance controls to reduce package-substitution risk.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install instruction uses npx clawhub install textile-clothing-repair without pinning a specific version or immutable package reference. That creates a supply-chain risk: future package changes, dependency compromise, or typosquatted resolution could cause different code to run at install time than what reviewers evaluated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to detect the user's country and tailor store recommendations, but it does not require disclosure, consent, or a less invasive alternative. Inferring or using location data without user awareness can violate privacy expectations and enable unnecessary collection or processing of sensitive contextual information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scheduled trigger runs whenever user_location IS SET, which is unrelated to a current clothing-repair request. This can cause unsolicited invocation based on retained user data, increasing privacy risk and creating unexpected agent behavior that may surface location-tailored prompts without clear user intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.