Back to skill

Security audit

Weather Reading Outdoor Awareness

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent weather-safety guidance, but it asks for filesystem access it does not use or scope.

Review before installing because the weather guidance itself is coherent, but the filesystem permission is broader than the documented function requires. Prefer a version that removes filesystem access or clearly restricts it, and use a pinned or trusted ClawHub CLI install path.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:12
Finding

Unnecessary Filesystem Capability Violates Least Privilege

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis
Remediation
View remediation
install weather-reading-outdoor-awareness" ``` - Verify the selected release using registry integrity metadata or an independently recorded cryptographic digest. - Prefer invoking a preinstalled, organization-approved CLI rather than allowing `npx` to fetch code at installation time. - Use a trusted registry and enforce package allowlisting in managed environments. - Review the pinned package, its transitive dependencies, and lifecycle scripts before approving it. - Upgrade only through a controlled review process that records the new version and integrity information. - Do not run the installation command with administrator or root privileges. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use' section lists very broad situations such as planning outdoor activities, seeing clouds, or being outdoors in deteriorating conditions. Without tighter boundaries or exclusion examples, these triggers could cause the skill to activate in many ordinary conversations about weather or outdoor plans.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger fires whenever the current activity contains the word 'outdoor', which is a very loose condition and may match many benign contexts. The trigger lacks scope constraints or negative conditions to distinguish true preparation/safety requests from incidental mentions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This trigger activates whenever temperature exceeds 90 and any activity is set, regardless of whether the user is seeking safety guidance or even going outdoors. That makes invocation scope unclear and risks unsolicited activation during ordinary discussion of warm conditions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The condition matches generic terms like 'darkening' or 'thunder', which can appear in many descriptions and may not reliably indicate that this skill should activate. The trigger does not specify whether the user is currently outside, at risk, or requesting guidance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.