Back to skill

Security audit

Xiao Habit Tracker

Security checks for vulnerabilities and agentic risk

Overview

This is a small Chinese-language habit-tracking skill with no bundled executable code; its main caution is an unpinned documented install command.

Before installing, note that the documentation is Chinese-only and the install command tracks the latest ClawHub CLI release. Prefer a pinned, reviewed installer version if reproducibility matters.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:5
Finding

Execution of an Unpinned, Mutable npm Package Release

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 5–7
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

bash
npx clawhub@latest install habit-tracker

Technical Analysis

The documented installation command instructs users to execute the package identified by the mutable npm tag latest. Unlike an exact, audited version, this tag can be reassigned to a different package release after the Skill has been reviewed.

npx may download and execute package code from the npm registry. Consequently, the effective code executed by this command is neither present in the reviewed project nor cryptographically fixed by the documentation. A compromised package maintainer account, malicious release, registry compromise, or unexpected future release could therefore introduce attacker-controlled CLI or lifecycle code.

Attack Path

  1. An attacker compromises the clawhub npm package, its publisher account, or its release process.
  2. The attacker publishes a malicious release and assigns the latest distribution tag to it.
  3. A user follows the installation instructions and runs npx clawhub@latest install habit-tracker.
  4. npx retrieves the release currently referenced by latest.
  5. Attacker-controlled package code executes with the operating-system privileges and environment access of the invoking user.

Impact Assessment

Successful exploitation could allow arbitrary code execution under the invoking user's account. Depending on that account's permissions and environment, the malicious package could read or modify accessible files, obtain environment variables or local credentials, make network requests, alter installed content, or execute additional processes. The command does not itself demonstrate privilege escalation; the maximum directly established privilege is that of the user who runs it.

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable latest tag with an exact, reviewed package version, such as npx clawhub@1.2.3 install habit-tracker.
  • Verify the selected release's publisher, provenance, and integrity before recommending it.
  • Where the installation workflow permits, use a lockfile and integrity hashes to make dependency resolution reproducible.
  • Prefer trusted package releases with npm provenance attestations and protected, multi-factor-authenticated maintainer accounts.
  • Review package lifecycle scripts and disable them during installation when they are unnecessary.
  • Update the pinned version only after reviewing and testing the new release, rather than automatically tracking latest.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx clawhub@latest install habit-tracker, which pulls and executes the latest published package version at install time rather than a pinned, reviewed version. That creates a supply-chain risk: if the package is compromised, typosquatted, or updated maliciously, users may execute attacker-controlled code simply by following the documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content of the skill, including the description, feature list, and usage guidance, is presented only in Chinese. This can violate language/locale policy when a specific language is effectively forced without user opt-in or documentation that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description and all user-facing documentation are presented in Chinese, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy when users are not given a choice or informed of the constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.