Back to skill

Security audit

Heart Rate Tracker

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a heart-rate tracking skill, but it needs review because it handles health-related data while declaring an unexplained network tool and using a mutable install command.

Review this skill before installing. Treat its heart-rate analysis as wellness information only, ask where heart-rate data is stored or transmitted, and prefer a pinned installer version. The unexplained `curl` requirement should be removed or documented with exact network destinations and consent behavior.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Execution of an Unpinned npm Package During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, line 8
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
npx clawhub@latest install heart-rate-tracker

Technical Analysis

The documented installation procedure uses npx to download and execute the release currently referenced by the mutable latest tag. The project does not pin an exact reviewed version or specify an integrity hash or signature.

Consequently, the code executed by this command may differ over time from the code that was available when the skill was reviewed. The risk materializes if the npm package, its publisher account, its dependencies, or the mutable release tag is compromised. The audit did not establish that the referenced package is currently malicious.

Attack Path

  1. An attacker compromises the clawhub npm package, its publisher account, a transitive dependency, or the publication workflow.
  2. The attacker publishes a malicious release and assigns or causes the latest tag to resolve to that release.
  3. A user follows the installation command from README.md.
  4. npx retrieves and executes the attacker-controlled package.
  5. The malicious package runs with the operating-system privileges of the user who invoked the command.

Impact Assessment

Successful exploitation could permit arbitrary code execution within the invoking user's security context. Depending on that user's privileges and accessible resources, this may expose local files, environment variables, authentication tokens, project credentials, and network-accessible services. If the command is run under an administrative account or in a privileged CI environment, the impact may extend to broader system or pipeline compromise.

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed package version.
  • Verify the package using registry-supported integrity metadata or cryptographic signatures.
  • Document the expected files, commands, and permissions involved in installation.
  • Use a trusted registry and enable protections such as publisher multifactor authentication and provenance attestations.
  • Review and lock transitive dependencies where the installation model permits it.
  • Advise users not to run installation commands with administrative privileges.
  • Re-audit the package before updating the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
_meta.json:1
Finding

Undocumented Declaration of a General-Purpose Network Transfer Tool

Content
View full analysis

Vulnerability Details

File Location: _meta.json, line 1
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Low

Vulnerable Configuration:

json
{"name":"heart-rate-tracker","version":"1.0.0","author":"小鸣 🦞","tags":["heartrate","tracker","health","cardio"],"requires":{"bins":["curl"]}}

Technical Analysis

The metadata declares curl as a required binary, but neither README.md nor SKILL.md documents any network operation, remote endpoint, or workflow that needs it. A general-purpose transfer utility provides the capability to retrieve remote content or transmit data, including potentially sensitive health information.

This declaration conflicts with least-privilege principles because the demonstrated heart-rate logging, analysis, and alert workflows do not explain the need for network transfer capability. No command invoking curl, no remote payload retrieval, and no confirmed data exfiltration behavior were present in the audited files; therefore, this is a capability and configuration concern rather than evidence of active malicious behavior.

Attack Path

  1. The skill is installed in an environment that satisfies or grants its declared binary requirements.
  2. A later, external, or otherwise unaudited skill implementation invokes curl.
  3. The command connects to an attacker-controlled or unauthorized endpoint.
  4. It retrieves executable content or sends locally available information outside the documented workflow.

This path is conditional because the reviewed project contains no implementation that invokes curl.

Impact Assessment

The declaration alone does not grant additional operating-system privileges and does not prove exploitation. If used by later or external instructions, however, curl could facilitate unauthorized outbound transfer of heart-rate records, identifiers, credentials, or other files accessible to the invoking user. It ...[truncated 184 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the curl requirement unless it is necessary for an implemented and documented feature.
  • If network access is required, document the exact destinations, protocols, request methods, and data fields transmitted.
  • Restrict outbound traffic to allowlisted HTTPS endpoints.
  • Require explicit user consent before transmitting health-related or identifying information.
  • Apply authentication, certificate validation, encryption in transit, data minimization, and defined retention controls.
  • Avoid downloading and directly executing remote content.
  • Add the actual implementation to the package so its network behavior can be independently audited.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents all substantive user-facing instructions and descriptions in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking region. This is a natural-language locale policy concern because it effectively imposes a language requirement without opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install heart-rate-tracker, which pulls and executes the latest version of a remote package rather than a pinned, audited version. This creates a supply-chain risk: if the package or a dependency is compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill presents heart-rate analysis, abnormal alerts, and health monitoring features without any disclaimer that outputs are informational only and not a substitute for professional medical advice. In a health-related context, users may over-rely on the tool for medical decision-making, potentially delaying care or misinterpreting normal or dangerous readings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and body text are presented in Chinese, while no language choice, opt-in, or justification for a Chinese-only locale is provided. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.