Back to skill

Security audit

skill-stats

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for local skill-usage analytics, but it reads broad session histories, persists behavioral metadata, and runs through an unpinned npm executable.

Install only if you are comfortable with a local tool scanning Claude/OpenClaw session histories and saving usage summaries with project paths. Prefer a version that pins `tsx`, documents exact data retained, and offers a way to clear or disable stored statistics.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Third-Party Package Is Downloaded and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:31 and SKILL.md:36
Vulnerability Type: Supply-chain risk caused by automatic execution of an unpinned npm package
Risk Level: Medium

Vulnerable Code

bash
npx -y tsx ${SKILL_DIR}/scripts/main.ts --context claude-code
bash
npx -y tsx ${SKILL_DIR}/scripts/main.ts --context openclaw

Technical Analysis

Both documented execution commands invoke npx -y tsx without specifying a package version, lockfile, or integrity constraint. If tsx is not already installed locally, npx can resolve, download, and execute the package from the configured npm registry. The -y option automatically accepts installation without user confirmation.

As a result, the code executed at runtime is not limited to the reviewed project files and can change after this audit. The effective package can also be influenced by the user's npm registry configuration. A compromised upstream release, package-maintainer account, registry, or package-resolution environment could therefore introduce arbitrary executable code.

Attack Path

  1. A user or agent follows the commands in SKILL.md.
  2. The environment does not contain a trusted local tsx executable.
  3. npx resolves the unversioned tsx package through the configured npm registry.
  4. A compromised or otherwise untrusted package version is downloaded.
  5. Because -y is used, installation and execution proceed without an interactive approval step.
  6. The package executes with the invoking user's privileges before or while loading the local statistics script.
  7. Malicious dependency code can access resources available to that user, including the Claude Code and OpenClaw session data that this skill is intended to process.

Impact Assessment

Successful exploitation would allow arbitrary code execution with the privileges of the user invoking the skill. Within that user's permission boundary, malicious package code could read or modify files, ...[truncated 390 chars]

Remediation
View remediation

Remediation Suggestions

  1. Declare an audited, exact tsx version in package.json; do not use a floating version range.
  2. Commit the generated lockfile and require installation with a lockfile-enforcing command such as:
bash
npm ci
  1. Invoke only the locally installed executable, for example:
bash
./node_modules/.bin/tsx scripts/main.ts --context claude-code
./node_modules/.bin/tsx scripts/main.ts --context openclaw

Alternatively, use npm exec --offline -- tsx ... after a controlled installation.

  1. Remove npx -y tsx from the runtime instructions so skill invocation cannot silently download new executable code.
  2. Review the pinned package and its transitive dependencies, verify registry provenance and integrity metadata, and update dependencies through an explicit review process.
  3. Where practical, execute the collector with restricted filesystem and network permissions to reduce the impact of a compromised dependency.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill is described as a simple statistics/query interface, but its documented behavior includes broad filesystem log scanning and persistent local data storage, while some advertised features appear unsupported or overstated. This mismatch undermines informed consent and can cause users to authorize a skill with a materially broader privacy and data-handling footprint than expected.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell-capable commands (npx -y tsx ...) and relies on environment state, but the manifest does not declare any tool scope such as permissions or allowed-tools. That makes the skill's runtime capabilities implicit rather than reviewable, increasing the chance of over-privileged execution and making risk harder for users and hosts to assess.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation criteria are so broad that the skill may be selected for nearly any question related to skill usage details, causing routine requests to trigger log scanning and stats collection. Over-broad routing increases unnecessary exposure of session-history data and raises the chance that a more privileged skill is invoked when a simpler answer would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that the skill scans session files and stores derived statistics, but it does not warn that session logs may contain sensitive usage history, project metadata, or other private context. Without an explicit privacy notice and write-side disclosure, users may unknowingly permit collection and persistence of sensitive local behavioral data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Using npx -y tsx without pinning an exact version allows whatever package version resolves at execution time to be fetched and run. This creates a supply-chain risk where a compromised, malicious, or breaking upstream release could execute arbitrary code in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This second invocation repeats the same unpinned npx -y tsx pattern, carrying the same remote code execution and supply-chain exposure. Because it is documented for a second environment path, the unsafe pattern is normalized across both supported usage modes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script instructs the model to output analysis in Chinese and formats dates using the zh-CN locale, but it does not offer any language or locale choice to the user. This is a natural-language policy concern because it imposes a specific language/locale by default rather than documenting it as a justified regional constraint or making it optional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The collector reads session logs, derives per-skill usage history, project paths, and timestamps, then persists them without any visible consent, notice, or minimization controls in this code path. Because session-derived metadata can reveal user behavior and local project locations, silent long-term aggregation increases privacy risk even if the data stays on local disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The collector persists detailed skill-usage telemetry to ~/.claude/skill-stats/global-stats.json, including skill names, timestamps, session-derived project paths, and usage history, without any notice, consent, minimization, or access-control logic in this file. Because this data can reveal workflow habits, project names/paths, and tool usage over time, local disclosure or later reuse by other components could leak sensitive behavioral metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multiple natural-language comments in this file are written as imperative Chinese-only guidance (for example, the parsing comments at L019 and similar later comments), with no indication that language choice is optional or justified by a region-specific constraint. This can violate language/locale policy when a skill or codebase imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest emphasizes usage information such as call counts, success rates, and last-used times. This code also enumerates workspace and global installed skills by traversing skill directories and checking for SKILL.md files, adding an installation inventory capability in addition to usage tracking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest frames this skill as querying, analyzing, and tracking skill usage information, which is primarily analytics-oriented. This implementation goes beyond transient analysis by creating a dedicated stats directory and later writing aggregated usage data to a persistent JSON file, introducing durable state not explicitly conveyed by the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language comments and descriptions in the file are written in Chinese, such as the path and parser descriptions, with no indication that this language choice is optional or region-specific. Under the policy provided, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The code reads ~/.claude/settings.json and enumerates ~/.claude/skills and project skill directories to infer enabled plugins and available skills. These accesses are part of data collection behavior, but the file contains no user-facing disclosure, prompt, or logging to make the user aware that local configuration and workspace metadata are being scanned.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.