Back to skill

Security audit

Water Safety Swimming

Security checks for vulnerabilities and agentic risk

Overview

The skill gives coherent water-safety guidance, but it requests filesystem access it does not appear to need and uses an unpinned executable install command.

Review this before installing. The guidance content itself appears focused on water safety, but you should avoid granting filesystem access unless the publisher explains why it is needed, and prefer a pinned or verified install path. Enable recurring reminders only if you want the agent to retain related family and CPR state.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:11
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11-15
Vulnerability Type: Excessive tool permission
Risk Level: Medium

Vulnerable Code:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install water-safety-swimming"

Technical Analysis

The skill declares the filesystem tool as a required capability, but its documented water-safety workflow does not require reading, creating, modifying, or deleting local files. The remainder of the audited file consists of informational guidance, state definitions, and reminder conditions.

Granting a filesystem capability without a demonstrated operational requirement violates the principle of least privilege. The precise exposure depends on the host platform's filesystem sandbox and tool policy. If the capability is broadly scoped, malicious instructions introduced through prompt injection or a compromised skill update could attempt to access files unrelated to water-safety guidance.

Attack Path

  1. A user installs and activates the skill.
  2. The host grants the declared filesystem capability.
  3. Attacker-controlled content reaches the Agent through a later prompt, compromised update, or another untrusted context.
  4. The malicious instructions direct the Agent to invoke the filesystem tool.
  5. If host-level access controls permit the request, the Agent reads or modifies files within the capability's accessible scope.

This file does not itself contain instructions that perform such access; exploitation requires attacker-controlled instructions and a permissive host policy.

Impact Assessment

The capability could expose the confidentiality and integrity of files available through the host's filesystem tool. Potential impact includes reading local configuration or user data and modifying accessible files. It does not inherently provide operating-system administrator privileges, and the actual scope is bounde ...[truncated 57 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from openclaw.requires.tools because the documented workflow does not use it.
  • If future functionality genuinely requires file access, grant access only to a dedicated skill-owned directory.
  • Enforce read-only access unless writes are explicitly necessary.
  • Require user confirmation for sensitive file operations.
  • Add runtime allowlists that prevent access to credentials, home-directory secrets, system configuration, and unrelated project files.
  • Document each required tool and the exact operations for which it is needed.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Registry Package Execution in Installation Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 15
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: Medium

Vulnerable Code:

yaml
install: "npx clawhub install water-safety-swimming"

Technical Analysis

The installation metadata invokes npx with the package name clawhub but does not pin an audited version or specify an integrity digest. Depending on the local npm configuration and cache, npx can resolve and execute package code obtained from the configured package registry.

Because package resolution is not fixed to a reviewed artifact, the code executed at installation time can differ from the code that was originally audited. A compromised maintainer account, registry compromise, malicious future release, dependency substitution, or unsafe registry configuration could cause attacker-controlled package code to run.

The project contains only SKILL.md; no lockfile, vendored installer, checksum, or other mechanism is present to verify the installer artifact.

Attack Path

  1. A user or automation system follows the declared installation command.
  2. npx resolves clawhub using the configured npm registry and local cache.
  3. An attacker publishes or causes resolution to a compromised package version, or compromises a transitive dependency used by that version.
  4. npx downloads the unverified package and executes its CLI code.
  5. The malicious code runs with the operating-system privileges and environment access of the user executing the installation.

Exploitation depends on compromise or substitution of the resolved package or its dependency chain; the audited file does not itself contain a malicious package payload.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope may include access to that user's files, environment variables, developer credentials, ne ...[truncated 192 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the installer to a reviewed immutable version, for example npx clawhub@<audited-version> ....
  • Use a trusted registry explicitly and prevent fallback to untrusted package sources.
  • Verify package provenance and integrity before execution.
  • Use lockfiles or an equivalent immutable dependency manifest for the installer and its dependency graph.
  • Run installation in a sandbox with minimal filesystem, network, credential, and environment-variable access.
  • Disable package lifecycle scripts where compatible with the installer.
  • Document the expected package publisher, version, checksum, and update-review process.
  • Require a fresh security review before changing the pinned installer version.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The install metadata invokes npx clawhub install water-safety-swimming without pinning a specific package version. That makes installation dependent on whatever version is current at execution time, increasing supply-chain risk if the package is updated maliciously, compromised, or changed incompatibly.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The trigger block defines several activation conditions and scheduled actions, but it does not provide negative examples or explicit boundaries preventing use outside the intended context. In particular, broad state-based conditions like having children or a missing swim level could cause routine reminders or recommendations without enough specificity about when the skill should remain inactive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.