Back to skill

Security audit

Woodworking Maker Basics

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a plain woodworking guide, but it asks for unnecessary filesystem access and uses an unpinned npx install command, so it should be reviewed before installation.

Review this skill before installing. The woodworking content itself is coherent, but install it only if you trust the ClawHub CLI resolution path and are comfortable granting filesystem access; prefer a pinned, verified install command and restrict filesystem permissions if your host allows it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 13
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
install: "npx clawhub install woodworking-maker-basics"

Technical Analysis

The installation command invokes clawhub through npx without specifying an exact package version or integrity hash. If the package is not already available from a trusted local installation, npx can retrieve and execute a package from the configured registry.

Consequently, the code executed during installation can differ from the code reviewed during this audit. Compromise of the package publisher, registry account, package distribution infrastructure, or a future package release could introduce arbitrary installation-time code. The project does not document package provenance, a trusted version, integrity verification, or a requirement to use a previously verified local CLI.

Attack Path

  1. An attacker compromises the package publisher or distribution channel used to resolve clawhub, or causes an unsafe package version to be published.
  2. A user follows the declared installation instruction.
  3. npx resolves and downloads the unpinned package from the configured registry.
  4. The retrieved package or its lifecycle scripts execute with the privileges of the user running the command.
  5. Malicious code can access resources available to that user and may install additional payloads.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include the user's files, environment variables, credentials available to the process, network access, and writable project or configuration directories. If the command is run from an elevated shell, the impact could extend to system-level modification.

Remediation
View remediation

Remediation Suggestions

  • Pin clawhub to an exact, reviewed version rather than allowing npx to resolve the current registry version.
  • Verify the downloaded artifact with a lockfile, registry integrity metadata, checksum, or cryptographic signature.
  • Document the expected package registry and verified publisher identity.
  • Prefer invoking a locally installed and administratively verified CLI.
  • Disable or carefully review dependency lifecycle scripts where the package manager supports doing so.
  • Run installation with an unprivileged account in a restricted environment and review package changes before deployment.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:10
Finding

Filesystem Capability Requested Without a Documented Operational Need

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-13
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Low

Vulnerable Code Snippet:

yaml
openclaw:
  requires:
    tools: [filesystem]
  install: "npx clawhub install woodworking-maker-basics"

Technical Analysis

The skill requests access to a filesystem tool, but its documented functionality consists of providing woodworking instructions, project plans, safety guidance, state fields, and conversational triggers. No file read or write operation is identified as necessary for those functions.

Granting an unnecessary capability violates the principle of least privilege. Although the reviewed skill contains no explicit instruction to misuse the filesystem, making the tool available increases the consequences of later prompt injection, malicious user content, or unintended agent behavior.

Attack Path

  1. The skill is loaded with the declared filesystem capability.
  2. The agent subsequently processes attacker-controlled or otherwise hostile instructions during the same execution context.
  3. Those instructions influence the agent to invoke the unnecessarily available filesystem tool.
  4. Depending on the host's tool policy, the agent may read, overwrite, create, or delete files within the tool's permitted scope.
  5. Retrieved information could be disclosed through later responses, while modified files could affect projects or user configuration.

Impact Assessment

The maximum impact depends on the filesystem tool's sandbox and authorization boundaries. If broadly scoped, exploitation could expose local project data or user-readable files and permit modification or deletion of user-writable content. This declaration does not itself demonstrate a sandbox escape or elevated operating-system privileges, but it unnecessarily enlarges the skill's attack surface.

Remediation
View remediation

Remediation Suggestions

  • Remove filesystem from the required tools because the documented skill behavior does not require file access.
  • If file operations are introduced later, declare only the minimum operations required, such as read-only access.
  • Restrict access to an explicit project directory instead of the user's general filesystem.
  • Require confirmation for writes, deletions, access outside the project root, and reads of potentially sensitive files.
  • Apply host-level sandboxing and deny access to credential stores, home-directory secrets, system paths, and unrelated projects.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The install command invokes npx clawhub install woodworking-maker-basics without pinning a specific package version, so consumers may execute whatever version is current at install time. If the upstream package, dependency chain, or registry entry is compromised, this can result in unreviewed code execution on the user's system during installation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.