Back to skill

Security audit

Values Clarification

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent values-coaching skill with some install and state-tracking cautions, but no evidence of hidden, destructive, or exfiltrating behavior.

Before installing, consider pinning or otherwise verifying the `clawhub` installer package. Expect the skill to ask for personal reflections about values, family, work, budget, calendar, and life direction; avoid sharing anything you do not want your agent environment to retain, especially if state or follow-up reminders are enabled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned npm Package Execution in Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install values-clarification"

Technical Analysis

The installation command invokes clawhub through npx without specifying a package version, integrity hash, or trusted registry. If the package is not already available locally, npx may retrieve and execute the package currently resolved by the configured npm registry.

Consequently, the code executed during installation is not immutable and can change after this Skill has been reviewed. The risk materializes if the resolved clawhub package or its dependency chain is compromised, replaced, or altered maliciously. The audit did not establish that the current package is malicious; the vulnerability is the absence of dependency pinning and provenance controls.

Attack Path

  1. An attacker compromises the resolved clawhub npm package, one of its executable dependencies, or the package publication account.
  2. The attacker publishes a malicious version that includes code executed by the package's CLI or lifecycle behavior.
  3. A user or automated installation process runs:
    shell
    npx clawhub install values-clarification
    
  4. npx resolves and downloads the unpinned package from the configured registry.
  5. The malicious package code executes with the privileges and environment access of the user running the installation command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could access readable files, environment variables, credentials, project data, and network resources or modify user-owned files.

The direct scope is limited to the permissions of the process invoking npx; no privile ...[truncated 189 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specific reviewed version rather than allowing npx to resolve an unspecified release:
    yaml
    install: "npx --package clawhub@<reviewed-version> clawhub install values-clarification"
    
  2. Document and enforce the expected npm registry, particularly in automated installation environments.
  3. Verify package provenance and integrity before execution, using npm provenance information, lockfiles where applicable, and registry integrity metadata.
  4. Review the pinned package and its transitive dependency tree before approving upgrades.
  5. Execute installation with a least-privileged account in an isolated environment, without unnecessary credentials or sensitive environment variables.
  6. Configure automated dependency monitoring and require security review before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · SKILL.md (reported line 418)May include surrounding context.

md
## Rules

- Never tell the user what their values should be. Not even subtly. "Power" and "pleasure" are as valid as "service" and "compassion."
- Do not assume Western individualist framing. Values of family, tradition, loyalty, and community obligation are not less evolved — they're different.
- Push back on "should" values. If the user says "I should value X," ask whether they actually do or whether they're performing a value they inherited.
- Distinguish between values and goals. "Make a million dollars" is a goal. The value underneath might be security, achievement, freedom, or recognition. Find the value.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The condition user_seeking_values_work is broad and undefined, so it is unclear exactly what user statements or contexts should activate this skill versus other reflective or coaching skills. Because this is a markdown file and the trigger lacks explicit boundaries or negative examples, it risks unintended invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.