Back to skill

Security audit

Tool Fluency

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain educational guide for using basic tools, with no hidden runtime behavior found in the artifact.

Before installing, consider running the install in a low-privilege environment and prefer a pinned, reviewed `clawhub` package version if available. The skill content itself is ordinary tool-use guidance, but the unpinned `npx` install path means trust also depends on the package resolved at install time.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:14
Finding

Unpinned npm CLI Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install tool-fluency"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version or integrity value. If the package is not already available in the local npm cache, npx may retrieve a currently resolved release from the configured npm registry and execute it.

Consequently, the code executed during installation can differ from the code that was available when this Skill was reviewed. The project contains no lockfile, vendored CLI implementation, package integrity hash, or other mechanism that constrains the resolved clawhub package to a reviewed artifact.

Exploitation requires control over, or compromise of, the package distribution path—for example, compromise of the package publisher, registry account, registry infrastructure, or the user's registry configuration. The command alone does not demonstrate that the current clawhub package is malicious, but its unpinned execution creates an avoidable supply-chain exposure.

Attack Path

  1. An attacker compromises the clawhub npm package, its publisher account, or another component of the configured package-resolution path.
  2. The attacker publishes or serves a modified package version containing malicious installation or CLI code.
  3. A user or automation system processes the Skill's installation metadata and runs npx clawhub install tool-fluency.
  4. npx resolves and downloads the attacker-controlled package because the command does not constrain the version or verify an integrity hash.
  5. The package executes with the privileges and environment of the user running the installation command.

Impact Assessment

Successful exploita ...[truncated 677 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed version rather than relying on the registry's current resolution:

    yaml
    install: "npx --yes clawhub@<reviewed-exact-version> install tool-fluency"
    
  2. Verify the selected package artifact against an approved integrity hash or signed provenance before execution.

  3. Use a trusted, explicitly configured registry and enforce dependency allowlisting in automated installation environments.

  4. Prefer installing dependencies through a lockfile-controlled workflow and invoke the locked local binary rather than allowing npx to download a package dynamically.

  5. Run installation with minimum privileges in a sandbox or isolated container, without unrelated credentials or sensitive environment variables.

  6. Periodically review the pinned package version and update it only after inspecting the new artifact and validating its provenance.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The install command uses npx clawhub install tool-fluency without pinning a specific package version, which means execution depends on whatever version is current at install time. If the upstream package, dependency chain, or publishing account is compromised, users could execute unintended code during installation; this is somewhat mitigated by the skill being about tools rather than privileged infrastructure, but the risk remains because npx fetches and runs code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.