Back to skill

Security audit

Upwork Proposal Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is a simple Upwork proposal-writing helper, but its install instructions run a mutable external package without pinning or verification.

Use this as a localized Upwork proposal assistant, not as an account automation tool. Before installing, prefer a pinned and reviewed ClawHub installer version or verify package provenance, because the documented `@latest` npx command can run whatever package version is current at install time. Also expect broad activation on job-post text unless you explicitly constrain when it should run.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 7
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code:

bash
npx clawhub@latest install upwork-proposal-generator

Technical Analysis

The installation instructions invoke clawhub@latest through npx. The latest tag is mutable and does not identify a fixed, previously audited package version. No lockfile, integrity hash, signature requirement, or trusted-source verification is provided.

When followed, this command downloads and executes third-party package code selected by the package registry at execution time. Consequently, the effective installer may differ from the version reviewed by the skill author. This creates a supply-chain exposure if the package, maintainer account, registry response, or a future release is compromised.

Attack Path

  1. An attacker compromises the package publisher, publishing process, registry distribution path, or a future release associated with the latest tag.
  2. The attacker publishes a modified clawhub package containing malicious CLI or lifecycle code.
  3. A user follows the documented installation command.
  4. npx resolves clawhub@latest, downloads the attacker-controlled release, and executes it.
  5. The malicious package runs with the privileges of the user who launched the command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions, the malicious dependency could access user-readable files, environment variables, credentials, project data, and network resources, or modify files available to that user. System-wide impact would require elevated privileges or a separate privilege-escalation mechanism; neither is demonstrated in the reviewed project.

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed package version.
  • Document the expected package registry and verified publisher identity.
  • Verify package provenance, signatures, or published integrity metadata before execution.
  • Review the pinned package's CLI entry point and lifecycle scripts before recommending it.
  • Use a lockfile or equivalent reproducible dependency manifest where supported.
  • Update pinned versions only through a controlled review process that includes source and dependency auditing.
  • Consider downloading and verifying the package artifact before execution rather than combining retrieval and execution in a single npx command.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation command invokes an external package via npx clawhub@latest, which fetches and executes the latest published code without pinning a specific trusted version. This creates a supply-chain risk: a compromised publisher account or malicious update could cause users to run attacker-controlled code at install time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage instruction says the skill applies whenever a user sends a job post link or text, but it does not clearly constrain what kinds of links or text qualify beyond the general Upwork context. This ambiguity can cause unintended invocation because many ordinary messages containing job-related text could match.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructions and output guidance are presented in Cantonese/Chinese, and the file does not indicate that language selection is optional or user-configurable. This can violate language/locale policy when users are not given a choice or informed that the skill is language-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.