Back to skill

Security audit

Xiao Goal Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a simple goal-tracking skill with no embedded executable code, but its install instructions and metadata deserve normal caution.

Review the installer command before running it, and prefer a pinned or otherwise verified ClawHub installer version if available. The skill appears purpose-aligned, but users who do not read Chinese should confirm the goal-tracking commands and pricing terms before installing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:5
Finding

Execution of an Unpinned npm Package During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 5–7
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

bash
npx clawhub@latest install goal-tracker

Technical Analysis

The documented installation command instructs users to execute the mutable latest release of the third-party npm package clawhub. Because no exact version or integrity value is specified, the code executed by this command can change after the skill has been reviewed.

npx may download and execute the selected package when it is not already available locally. Consequently, compromise of the package publisher account, npm distribution channel, or a future malicious release could cause users following the documentation to execute attacker-controlled code. The project provides no lockfile, checksum, signature-verification step, or other mechanism that binds this installation command to a reviewed artifact.

Attack Path

  1. An attacker compromises the clawhub npm publisher account or otherwise causes a malicious version to become the package's latest release.
  2. A user follows the installation instructions in README.md.
  3. npx resolves clawhub@latest to the attacker-controlled release and downloads it.
  4. npx executes the package with the privileges of the current user.
  5. The malicious package can access resources available to that user, subject to operating-system controls.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the malicious package could read or modify user-accessible files, access environment variables and locally stored credentials, make network requests, modify development assets, or install additional user-level components.

The issue does not itself demonstrate privilege escalation or prove that the current clawhub package is malici ...[truncated 122 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace clawhub@latest with an exact, reviewed version, such as clawhub@X.Y.Z.
  • Verify the selected package version and document its official registry and publisher identity.
  • Where supported, validate the downloaded artifact using a trusted checksum or cryptographic signature.
  • Use lockfiles and integrity metadata for package-managed installation workflows.
  • Review package lifecycle scripts and transitive dependencies before recommending execution.
  • Avoid commands that automatically download and execute mutable remote packages. Prefer a separately verified installation step followed by invocation of the pinned local binary.
  • Establish a controlled update process in which new versions are reviewed before the documented pin is changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description and all user-facing documentation are presented in Chinese, with no indication that users can choose another language or that the skill is region-specific. This creates a natural-language policy concern because it implicitly enforces a locale/language without user opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The installation command uses npx clawhub@latest, which pulls the latest package version at execution time rather than a pinned, reviewed version. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published later, users running the documented command could execute untrusted code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and body text are presented in Chinese, while the skill title is in English, and there is no indication that the language is optional or that the skill is intended only for a Chinese-speaking region. This creates a natural-language locale policy concern because the skill appears to assume a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.