Back to skill

Security audit

Goal Tracker Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a simple goal-tracking skill with no bundled executable code; the main caution is that its README recommends an unpinned npx installer command.

Review the installer source before running the README command, and prefer a pinned clawhub version if one is available. The skill content itself appears limited to goal-tracking instructions, with no hidden persistence or credential handling found.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:6
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
install goal-tracker-pro ``` 2. Document the expected npm registry and verified publisher to reduce dependency-confusion and registry-substitution risks. 3. Where supported, verify the downloaded package using an integrity hash, signed provenance, or another cryptographic verification mechanism. 4. Review the selected package version, including its lifecycle scripts and transitive dependencies, before recommending execution. 5. Establish a controlled update process in which newer versions are reviewed before the documented version is changed. 6. Consider an installation method that does not immediately execute remotely downloaded package code. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is written entirely in Chinese, including headings and feature descriptions, with no indication that users can choose another language or that the skill is intended only for a Chinese-speaking audience. This creates a natural-language policy concern because it effectively imposes a locale/language constraint without user opt-in or justification.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The README instructs users to run npx clawhub@latest install goal-tracker-pro, which fetches and executes the latest publisher-controlled code at install time rather than a pinned, reviewed version. This creates a supply-chain risk: if the package or a dependency is compromised later, users following the documentation may execute unexpected code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and introductory text are written in Chinese while the document title is English, and there is no indication that the skill is region-specific or that users can choose their preferred language. This creates a natural-language policy concern because the skill appears to impose a specific language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest contains natural-language metadata using a non-English author name and emoji presentation, which may signal a locale-specific presentation without any documented opt-in or justification. Under the stated policy, locale-specific constraints or forced language conventions should be explicitly justified or offer user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.