Back to skill

Security audit

Xiao Expense Tracker

Security checks for vulnerabilities and agentic risk

Overview

This looks like a basic expense-tracking skill, but it needs review because it handles financial data while declaring an unexplained network-capable dependency and using an unpinned installer command.

Review this skill before installing. Prefer a pinned, trusted installer version, ask why `curl` is required, and avoid entering or exporting sensitive financial details unless you understand where the data is stored and sent.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:5
Finding

Unpinned npm Package Execution Through a Mutable Release Tag

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 5–7
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

bash
npx clawhub@latest install expense-tracker

Technical Analysis

The documented installation command uses npx to download and execute the npm package identified by the mutable latest tag. The project does not pin an exact package version or provide an integrity hash, lockfile, vendored installer, or package-verification procedure.

As a result, the effective installer code can change after this project has been audited. Anyone who compromises the upstream package, its maintainer account, or its publishing workflow could cause subsequent installations to execute attacker-controlled code. The reviewed project contains only documentation and metadata, so the behavior of the externally obtained installer cannot be verified from the local artifact.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or the upstream release pipeline for clawhub.
  2. The attacker publishes a malicious version and assigns or causes it to receive the latest distribution tag.
  3. A user follows the installation command in README.md.
  4. npx resolves clawhub@latest, downloads the attacker-controlled release, and executes its CLI or applicable lifecycle code.
  5. The malicious process operates with the privileges and environment of the invoking user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the invoking user's privileges. Depending on that user's access and the malicious package behavior, the compromise could affect local files, environment variables, developer credentials, application configuration, and other resources accessible to the user. The issue does not independently demonstrate privilege escalation; its scope is limited to the permissions already held by the process running npx.

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable latest tag with an exact, reviewed package version.
  • Verify the downloaded package against a trusted integrity digest or signed provenance before execution.
  • Document the authoritative package registry and publisher identity.
  • Use a lockfile or similarly reproducible dependency mechanism where applicable.
  • Prefer a locally included and auditable installer rather than downloading executable installer logic at runtime.
  • Establish an update process in which new installer versions are reviewed and their integrity values are updated explicitly.
  • Avoid running the installation command with elevated privileges.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to run npx clawhub@latest install expense-tracker, which relies on a floating latest version rather than a pinned, reviewed release. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious version is published, users may execute untrusted code during installation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill metadata requests the external curl binary even though the stated purpose is local expense tracking, budgeting, and categorization. Unnecessary network-capable dependencies expand the attack surface by enabling outbound requests, data exfiltration, remote payload retrieval, or command chaining that is not justified by the declared functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is entirely in Chinese, with no indication that this language choice is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This can constitute a language/locale policy violation when a specific language is imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file lists '数据导出' as a feature, which implies user financial data may be exported, but it does not provide any warning about privacy, destination, or handling of exported data. For markdown files, omissions of warnings about behaviors that could affect user data or privacy should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the main explanatory text are written only in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. Under the policy for natural-language violations, a skill should not force a language choice unless it is explicitly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.