Back to skill

Security audit

Vehicle Survival Kit

Security checks for vulnerabilities and agentic risk

Overview

This roadside-help skill is mostly coherent, but it needs review because its install command is unpinned and it defines persistent accident/reminder data without clear controls.

Install only if you are comfortable with the unpinned `npx` install path and the agent possibly retaining vehicle and accident details. Prefer a pinned, reviewed installer and avoid storing police report numbers, insurance claim numbers, or precise accident locations unless you know how to delete them later.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution Through npx Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

yaml
metadata:
  category: skills
  tagline: >-
    Change a tire, jump a battery, handle a breakdown and a fender bender — the 10 car skills every driver needs before they need them.
  display_name: "Vehicle Survival Kit"
  submitted_by: HowToUseHumans
  last_reviewed: "2026-03-19"
  openclaw:
    requires:
      tools: [filesystem]
    install: "npx clawhub install vehicle-survival-kit"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version, package integrity hash, or trusted registry. If the package is not already available locally, npx can retrieve the current package release from the configured package registry and execute it.

Consequently, the code executed during installation is not necessarily the same code that was available when this skill was audited. A compromised package maintainer account, malicious future release, registry compromise, or dependency substitution could alter the effective installation behavior. Package lifecycle scripts may also execute automatically with the permissions of the user running the installation.

This is a supply-chain weakness rather than evidence that the currently referenced package is malicious.

Attack Path

  1. An attacker compromises the clawhub package, one of its dependencies, its publisher account, or the package distribution channel.
  2. The attacker publishes a malicious version or modifies a mutable dependency used by the package.
  3. A user follows the skill installation metadata and runs npx clawhub install vehicle-survival-kit.
  4. npx resolves and downloads the unpinned package version from the configured registry.
  5. Malicious package code or lifecycle scripts execute under the installing user's ...[truncated 662 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to a specific, reviewed version, for example through an exact-version invocation rather than an unqualified package name.
  • Use a trusted, explicitly configured package registry.
  • Verify package integrity with a lockfile, cryptographic digest, or signed provenance before execution.
  • Audit both direct and transitive dependencies for the pinned release.
  • Disable package lifecycle scripts where they are unnecessary, or document and review every script that will execute.
  • Prefer installing the audited package separately and invoking the known local binary instead of allowing npx to resolve a mutable release at runtime.
  • Add automated dependency monitoring so version updates require review before becoming available to users.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:418
Finding

Persistent Storage Schema Includes Sensitive Accident and Location Data Without Protection Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 418-448
Vulnerability Type: Excessive persistent collection of sensitive incident information
Risk Level: Low

Vulnerable Code

yaml
## Agent State

vehicle:
  year: null
  make: null
  model: null
  tire_pressure_spec_psi: null
  oil_weight: null
  emergency_kit_complete: false
  emergency_kit_missing: []
  last_oil_change_date: null
  last_oil_change_miles: null
  tire_tread_ok: null
  battery_age_years: null
  roadside_assistance_provider: null
  roadside_assistance_number: null
skills_practiced:
  tire_change: false
  jump_start: false
  oil_check: false
  coolant_check: false
  wiper_replacement: false
incident:
  type: null
  date: null
  location: null
  police_report_number: null
  insurance_claim_number: null
  documentation_complete: false

Technical Analysis

The Agent State schema provides persistent fields for an incident location, police report number, and insurance claim number. These values can identify a user's movements and link the user to accident, police, and insurance records.

The skill does not specify user consent, purpose limitation, data minimization, encryption, access control, retention periods, deletion behavior, or redaction requirements for these fields. Retaining these identifiers is not necessary for most immediate roadside instructions. The risk arises when an Agent implementation automatically persists populated state or exposes it to later sessions.

No storage implementation is included in the project, so the audit does not establish that the values are stored in plaintext on disk or remotely transmitted. The confirmed issue is that the state design permits retention of sensitive data without defining the controls necessary to protect it.

Attack Path

  1. A user asks the Agent for assistance after a vehicle accident.
  2. During the interaction, the Agent obt ...[truncated 957 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove incident.location, incident.police_report_number, and incident.insurance_claim_number from persistent state unless continued storage is essential.
  • Keep sensitive accident information in ephemeral session context by default.
  • Obtain explicit, informed user consent before retaining any incident details.
  • Store only minimally necessary values; use coarse location data and masked or tokenized identifiers where possible.
  • Define a short retention period and provide automatic deletion after the immediate claim-support task is complete.
  • Provide users with clear commands to inspect, correct, and delete stored incident data.
  • Encrypt sensitive state at rest and in transit, and restrict access to the originating user and authorized processes.
  • Prevent sensitive state from appearing in logs, analytics, reminders, or unrelated future conversations.
  • Document the storage destination, retention policy, access model, and deletion guarantees.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill metadata includes an install command using npx clawhub install vehicle-survival-kit without pinning a specific package version. Unpinned npx execution can fetch and run whatever version is current at install time, which creates a supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly. The skill context makes this somewhat more dangerous because the command is embedded as official installation guidance, increasing the chance that users or agents will trust and execute it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.