Back to skill

Security audit

Skill Update

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about updating installed skills, but it should be reviewed because it runs an unpinned external updater that can change agent behavior.

Review this skill before installing if you allow agents to modify installed skills. Its safety workflow is clear, but you should prefer a pinned, verified `clawic` CLI or a locked local install before letting it run updates, especially `update --all`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:60
Finding

Unpinned Third-Party CLI Retrieval and Execution Through npx

Content
View full analysis
# latest published version ``` `SKILL.md:126-128`: ```bash npx clawic update # update one skill npx clawic update --all # update every installed skill with a newer version ``` `batch.md:7-8`: ```bash npx clawic list # installed + versions; compare against published ``` `local-changes.md:9-12`: ```bash # Fetch the ORIGINAL of the installed version for comparison npx clawic install --dir /tmp/original- diff -r .claude/skills/ /tmp/original- ``` `multi-agent.md:14-15`: ```bash npx clawic list # shows installed skills with their locations and versions ``` `preview.md:6-10`: ```bash # Download without installing into any agent's skills folder npx clawic install --dir /tmp/preview- ``` ### Technical Analysis The Skill instructs the Agent to invoke `npx clawic` without pinning an exact package version or validating package provenance and integrity. When a suitable local package is unavailable, `npx` can retrieve the package resolved under the `clawic` name from the configured package registry and execute its CLI code. Consequently, the code executed during an update operation is not fully represented by the reviewed Skill files and can change after this audit. The instructions provide no lockfile, integrity hash, trusted registry constraint, package signature check, or reviewed version restriction. This is particularly security-sensitive because the invoked CLI is used to inspect, download, and replace Agent skills across project and global installation locations. The issue is a supply-chain trust w ...[truncated 1937 chars]
Remediation
View remediation
list npx --yes clawic@ show npx --yes clawic@ install --dir /tmp/preview- npx --yes clawic@ update ``` 2. Prefer a project-local dependency governed by a committed lockfile. Invoke the locked binary rather than permitting dynamic package resolution. 3. Verify the package source, publisher identity, and integrity metadata before execution. Restrict package resolution to an explicitly trusted registry. 4. Where supported, install the reviewed CLI once and use offline or no-install execution modes for subsequent calls, preventing an audit-time command from silently downloading a newer release. 5. Update the pinned version only through a controlled dependency-review process that examines package changes, lifecycle scripts, transitive dependency changes, and integrity hashes. 6. When fetching an historical Skill for local-change comparison, explicitly request the installed historical version. Do not assume an unversioned install command returns the correct reference copy. 7. Execute update tooling with the minimum necessary filesystem and network permissions. If practical, isolate preview downloads and diffs in a sandbox before allowing the tool to modify Agent installation directories. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs the agent to invoke npx clawic without pinning an exact package version or validating provenance. npx may resolve and execute whatever version is current or otherwise returned by the registry/environment at runtime, which creates a supply-chain execution risk if a malicious or compromised release is published or if resolution is tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command again relies on unpinned npx clawic, meaning the skill's update-check behavior depends on executing a package version that is not fixed by the skill itself. Because this skill is specifically about updating other skills and runs in act-as mode, untrusted package resolution is more dangerous: it can become a gateway to broader changes across installed skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Using npx clawic update <slug> without a pinned version can cause the agent to fetch and execute unexpected code at the moment it performs a privileged update action. That creates a direct supply-chain risk where compromise of the package, namespace confusion, or mutable latest tags could result in arbitrary code execution and unauthorized modification of skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

npx clawic update --all is especially risky when unpinned because it couples arbitrary package resolution with a bulk modification operation across all installed skills. If the resolved CLI is malicious or compromised, exploitation could lead to large-scale unauthorized updates, destructive changes, or broader code execution across multiple agent environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill instructs the agent to run npx clawic without pinning a specific package version or verifying the resolved package source. npx may fetch and execute the latest published package, so a compromised upstream release, typo-squatted dependency, or unexpected breaking update could lead to unintended code execution during a security-sensitive maintenance workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documented command uses npx clawic without pinning an exact package version or otherwise constraining the source, so execution may resolve to an unexpected or newly published package version at runtime. In a skill-update workflow, this is especially risky because users may run the command with elevated trust while handling installed skills, increasing exposure to supply-chain compromise or behavior drift.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation instructs use of npx clawic without pinning a version, which can fetch and execute the latest package from the registry at runtime. That creates a supply-chain risk: a compromised upstream release, typosquatted package, or unexpected breaking change could cause unreviewed code execution during a security-sensitive update workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs use of npx clawic install without pinning a specific package version, so the previewed content can vary over time and may pull an unexpected or compromised release from the registry. In an update-preview workflow, this weakens supply-chain integrity because the user may review one version today and a different one later, or fetch malicious code if the upstream package is hijacked.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · preview.md (reported line 44)May include surrounding context.

md
| New instruction to read, send, or upload data outside the skill's declared folders | Data exfiltration wears the grammar of a feature |
| New network endpoint, webhook, or URL the old version never contacted | The skill's reach just grew; the user should ratify it |
| Broadened file access (home directory, other skills' data, credentials paths) | Scope creep from `~/Clawic/data/<slug>/` to anywhere else is a decision, not a patch |
| Instructions to act "silently", skip confirmation, or not mention something to the user | Legitimate skills never need the user unaware |
| Encoded blobs, unusual Unicode, or text that renders differently than it reads | Hiding content from human review is itself the signal |
| Description rewritten to trigger far more broadly than the skill's function | Trigger-surface grab: the skill starts loading into unrelated conversations |

Static analysis

No suspicious patterns detected.