Back to skill

Security audit

Wage Theft Defense

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent wage-theft help guide, with one installation hygiene issue users should be aware of.

Before installing, consider using a pinned or otherwise verified ClawHub installer and run installation with least privilege. When using the skill, keep wage records on personal devices/accounts as it suggests, and verify jurisdiction-specific legal advice with current official sources or legal aid.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 16
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Complete Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install wage-theft-defense"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version or integrity digest. Depending on the local npm environment, npx can retrieve and execute the currently published version of the package from a configured package registry.

Because the package reference is mutable, the code executed during installation may differ from the code that was available when this skill was audited. This creates a supply-chain trust boundary in which compromise of the package, its publisher account, or the configured registry could result in attacker-controlled code being executed.

The audit found no evidence that the current clawhub package is malicious. The vulnerability is the installation process's inability to guarantee that users execute a specifically reviewed package artifact.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, or a package source trusted by the user's npm configuration.
  2. The attacker publishes a modified package version containing a malicious CLI entry point or installation lifecycle script.
  3. A user follows the documented command: npx clawhub install wage-theft-defense.
  4. npx resolves and downloads the mutable package version rather than a known, reviewed version.
  5. The malicious package code executes with the permissions of the user running the command.
  6. The code can access resources available to that user, subject to operating-system and runtime restrictions.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope m ...[truncated 453 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed version rather than relying on the latest registry version:
    yaml
    install: "npx clawhub@<reviewed-exact-version> install wage-theft-defense"
    
  2. Publish and verify a cryptographic integrity digest for the package artifact before execution.
  3. Use an npm lockfile or equivalent immutable dependency manifest where the installation workflow supports it.
  4. Require installation from an official, authenticated registry and document the expected package publisher and provenance.
  5. Disable or avoid dependency lifecycle scripts where they are unnecessary.
  6. Prefer a preinstalled, independently verified CLI over downloading and executing a package at installation time.
  7. Run installation with least privilege in a restricted environment, without sensitive environment variables or administrative permissions.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The install instruction uses npx clawhub install wage-theft-defense without pinning a specific package/version, which allows whatever version is current at execution time to run. Because npx fetches and executes code, a compromised upstream package, namespace takeover, or unexpected breaking update could result in arbitrary code execution during installation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.