Back to skill

Security audit

Workplace Injury Rights

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent workplace-injury guidance document with one install-time supply-chain caution but no evidence of hidden, destructive, or data-stealing behavior.

Before installing, consider using a pinned or trusted ClawHub installer version and avoid running install commands with elevated privileges. Once installed, treat the skill as general rights guidance, verify state-specific deadlines with official agencies or an attorney, and keep sensitive injury records only where you intend to store them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Package Execution in Installation Command

Content
View full analysis
Remediation
View remediation
install workplace-injury-rights" ``` 2. Verify the selected package version through a trusted registry source and review its provenance before publishing the instruction. 3. Provide and verify package integrity metadata or cryptographic signatures where the installation platform supports them. 4. Document the expected package publisher, registry, version, and checksum so users can detect substitution. 5. Prefer a trusted installation mechanism that does not download and immediately execute mutable remote code. 6. Run installation with least privilege in an isolated environment; users should not execute the command as `root` or with unnecessary administrative permissions. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill metadata includes an install command using npx clawhub install workplace-injury-rights without pinning a specific package version. Unpinned npx execution can fetch and run whatever code is current at install time, so a compromised, typosquatted, or later-malicious package release could execute arbitrary code in the installer or agent environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.