Back to skill

Security audit

Skill Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it manages installed skills through unpinned remote CLI commands that can execute changing code and alter the user's agent environment.

Install only if you are comfortable with this skill suggesting lifecycle actions and maintaining a local inventory. Before using install, update, info, or uninstall flows, prefer a reviewed and pinned ClawHub CLI version or a vetted local CLI, and avoid storing sensitive details in declined-skill reasons.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:40
Finding

Unpinned ClawHub CLI Enables Supply-Chain Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:40-49
Vulnerability Type: Unpinned third-party package execution through npx
Risk Level: High

Complete Code Snippet:

markdown
## Lifecycle Actions

| Action | Command |
|--------|---------|
| Install | `npx clawhub install <slug>` |
| Update | `npx clawhub update <slug>` |
| Info | `npx clawhub info <slug>` |
| Remove | `npx clawhub uninstall <slug>` |

Technical Analysis

The documented lifecycle commands invoke npx clawhub without pinning the ClawHub CLI to an audited version or verifying package integrity. If the package is not already available locally, npx can retrieve it from the configured package registry and execute its package lifecycle or CLI code using the current user's privileges.

Because the package reference is mutable, the code executed at runtime may differ from the code that was previously reviewed. The documentation warns that ClawHub downloads and executes code, but it does not require a fixed package version, integrity hash, trusted publisher verification, lockfile, or prevention of implicit package installation. Explicit user consent for a lifecycle operation does not verify the authenticity or integrity of the package being executed.

The same unsafe invocation pattern is also documented in lifecycle.md for installation (lifecycle.md:6-10), update checks (lifecycle.md:17-21), updates (lifecycle.md:29-33), and removal (lifecycle.md:38-42).

Attack Path

  1. An attacker compromises the clawhub registry package, its publisher account, or the package distribution infrastructure.
  2. Alternatively, an unsafe registry configuration resolves clawhub to an attacker-controlled package.
  3. The user approves a legitimate-looking skill installation, update, information lookup, or removal operation.
  4. The Agent executes npx clawhub ... without a pinned CLI version or integrity con ...[truncated 1058 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the ClawHub CLI to a specifically reviewed version, for example npx --no-install clawhub after a controlled installation or an exact-version invocation such as npx clawhub@<reviewed-version>, subject to the CLI's supported deployment model.
  2. Install dependencies through a lockfile-backed workflow and enforce integrity hashes with a trusted package manager.
  3. Prevent implicit network installation during routine operations. Provision the verified CLI separately, then require commands to fail if that local version is unavailable.
  4. Verify package publisher identity, registry provenance, signatures or attestations, and checksums before approving a new CLI release.
  5. Review both the management CLI and the target skill package before installation or update. Treat each as a separate supply-chain trust boundary.
  6. Execute package-management operations in a sandbox or least-privileged environment with restricted filesystem, credential, and network access.
  7. Document an approved-version upgrade process that includes source review, integrity verification, testing, and explicit authorization before changing the pinned version.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill explicitly instructs use of npx clawhub, which downloads and executes code from a registry at runtime without pinning a version or package digest. That creates a supply-chain risk: a compromised or unexpectedly changed package release could execute arbitrary code in the user's environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill says to act 'when working on a task' and 'notice the current context,' then gives broad examples like any mention of a tool or an unfamiliar domain. This leaves unclear when the skill should not activate and does not provide exclusion conditions or a narrow trigger list, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

npx clawhub install <slug> performs remote package retrieval and execution without a pinned clawhub version, exposing users to registry tampering or malicious upstream updates. Because this command installs additional content, it also increases the blast radius if the invoked toolchain is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

npx clawhub update <slug> runs unpinned remote code each time updates are checked or applied, so a malicious or compromised release of the CLI could be executed automatically. Update workflows are especially sensitive because they may be trusted and repeated over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Even npx clawhub info <slug> invokes remote code from an unpinned package, so a seemingly read-only operation still carries code-execution risk. Users may underestimate this because the command name implies passive inspection.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

npx clawhub uninstall <slug> also depends on fetching and executing an unpinned remote CLI package, which can lead to arbitrary code execution despite being framed as cleanup. Because uninstall actions may touch local files, a compromised CLI could abuse elevated trust in filesystem operations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill instructs use of npx clawhub install <slug> without pinning an exact package version, so execution may fetch and run whatever version of the package is current at invocation time. That creates a supply-chain risk: a compromised, malicious, or simply breaking newer release could be executed during install flows with the user's consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The update-check command npx clawhub info <slug> also relies on an unpinned package resolution, meaning the skill may execute a different CLI version each time it checks metadata. Even though this looks read-only, it still runs code from the package and could expose the user to supply-chain compromise or unexpected behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill uses npx clawhub update <slug> without pinning the version of the clawhub package that will execute. Because update actions directly modify installed components, using an unpinned CLI increases the chance that a malicious or compromised upstream release could perform unauthorized changes or install unexpected code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The uninstall flow invokes npx clawhub uninstall <slug> with no pinned package version, so removal operations depend on whatever package version is published at runtime. An attacker who compromises the package or publishing pipeline could abuse that trust to execute arbitrary code under the guise of a maintenance operation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to match ordinary conversation topics like AWS, legal, or medical terms, which can cause unsolicited or excessive skill suggestions. In a skill manager that proactively notices context, this increases the risk of nudging user behavior unexpectedly and invoking installation flows without a sufficiently clear relevance threshold.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to persist declined-skill reasons to a user file without telling the user that their rationale will be stored. Those reasons may contain sensitive preferences, work context, or personal information, creating a privacy issue through undisclosed retention and future reuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.