Back to skill

Security audit

Health Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a small health-tracking skill with visible documentation-only behavior; the main caution is a mutable installer command and handling potentially sensitive health data.

Before installing, consider pinning or verifying the clawhub installer version instead of using latest. Treat entered weight, calorie, exercise, and sync data as personal health information, and confirm where it is stored or uploaded if using any cloud-sync feature.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Execution of an Unpinned Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: README.md, line 7
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippet:

bash
npx clawhub@latest install health-tracker

Technical Analysis

The installation command directs npx to resolve and execute the mutable latest release of the third-party clawhub package. The project does not pin an audited package version or provide an integrity hash, lockfile, or provenance verification mechanism for this command.

Because the latest tag can be reassigned to a different release after this project has been reviewed, the code ultimately executed by users may differ from the version expected by the project author. This creates a supply-chain trust boundary outside the audited repository.

The reviewed package itself contains only documentation and metadata; no embedded malicious script or confirmed malicious remote payload was found. Exploitation therefore depends on compromise or malicious control of the referenced package, its publisher account, or the relevant package-distribution infrastructure.

Attack Path

  1. An attacker compromises the clawhub package, its publisher account, or an associated release process.
  2. The attacker publishes a malicious release and assigns it to the latest distribution tag.
  3. A user follows the installation command in README.md.
  4. npx resolves, downloads, and executes the attacker-controlled release.
  5. The malicious package runs with the permissions of the user who invoked the command.

Impact Assessment

Successful exploitation could allow arbitrary code execution within the invoking user's security context. Depending on that user's privileges and environment, the malicious package could access user-readable files, environment variables, developer credentials, project data, and network resources, or modify files writable by that user.

The ...[truncated 245 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable latest tag with an explicitly pinned, reviewed package version, for example:

    bash
    npx clawhub@<audited-exact-version> install health-tracker
    
  • Verify the selected package version's publisher, provenance, release signatures, and registry integrity metadata before recommending execution.

  • Use lockfiles and integrity hashes where the installation workflow supports them.

  • Prefer installing the dependency through a controlled dependency-management process and invoking the locally locked binary instead of dynamically downloading and executing it.

  • In CI/CD environments, restrict package lifecycle scripts, network access, filesystem permissions, and available credentials during installation.

  • Establish a controlled update process in which new versions are reviewed and tested before the documented version pin is changed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The installation command uses npx clawhub@latest, which pulls whatever version is current at execution time rather than a reviewed, fixed version. If the upstream package is compromised or a breaking/malicious release is published later, users installing this skill could execute untrusted code during setup.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and the user-facing instructional content are written in Chinese throughout the file, with no indication that other languages are supported or that Chinese is optional. This can violate a language/locale policy when the skill effectively requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is written in Chinese for its purpose, features, and goals, with no indication that users can choose another language or locale. This can violate a language/locale policy when a skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.