Back to skill

Security audit

clawdo - Todo List for Agents

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a coherent agent todo-list skill, but it installs an unpinned global npm CLI whose reviewed code is not included in the artifact.

Review or pin the exact npm package version before installing, prefer an isolated or project-local environment over a global install, and be cautious before enabling heartbeat or cron workflows that let agents process `auto` tasks without immediate human review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned and Unverifiable Global npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:37-45, SKILL.md:63-66, and README.md:34-40
Vulnerability Type: Supply-chain exposure through an unpinned globally installed dependency
Risk Level: Medium

Vulnerable Code

SKILL.md:37-45:

yaml
"requires": { "bins": ["clawdo"] },
"install":
  [
    {
      "id": "npm",
      "kind": "npm",
      "package": "clawdo",
      "bins": ["clawdo"],
      "label": "Install clawdo (npm global)",
    },
  ],

SKILL.md:63-66:

bash
clawhub install clawdo    # installs skill + docs into your workspace
npm install -g clawdo     # install the CLI binary

README.md:34-40:

bash
# In OpenClaw
clawhub install clawdo

# Or npm directly
npm install -g clawdo

Technical Analysis

The skill package directs users and installation tooling to obtain the mutable clawdo package from npm without pinning an exact version or integrity digest. The supplied project contains only documentation; it does not include the CLI source, a lockfile, a package manifest with integrity metadata, or other material that would allow the installed implementation to be audited against this skill package.

Consequently, the code executed after installation is determined by whichever release the npm registry resolves at installation time. A global npm installation can also run package lifecycle scripts under the permissions of the installing account. The documentation's claims regarding input sanitization, parameterized SQL, SQLite persistence, immutable autonomy, and append-only audit logging cannot be verified from the supplied artifact.

This finding establishes supply-chain exposure, not evidence that the current npm package is malicious.

Attack Path

  1. An attacker compromises the npm publisher account, publishing pipeline, package registry entry, or another component able to release the clawdo package.
  2. The attacker publi ...[truncated 1155 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an exact reviewed version rather than resolving the latest release.
  2. Verify the package using a trusted integrity digest or equivalent cryptographic provenance mechanism before installation.
  3. Include the CLI source, package manifest, and lockfile in the reviewed release, or link the skill release cryptographically to the exact audited source revision and npm artifact.
  4. Publish and verify package provenance, use protected publisher credentials, require multi-factor authentication, and restrict release automation permissions.
  5. Avoid global installation where practical. Run the CLI in a project-local, isolated, or otherwise least-privileged environment.
  6. Disable npm lifecycle scripts during installation when they are not required, and separately review any scripts before enabling them.
  7. Ensure automated ClawHub installation resolves the same pinned and reviewed CLI version as the skill manifest.
  8. Add continuous dependency and release-artifact scanning so changes to the distributed npm package are detected before publication.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · README.md (reported line 47)May include surrounding context.

md
When CLI changes:
1. Update `skill/SKILL.md` in same commit as code changes
2. Commit atomically: `git commit -m "feat: add feature + update skill docs"`
3. Create release: workflow auto-publishes to npm + ClawHub

## Size

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
## Security

- **Immutable autonomy** — agents cannot escalate permissions
- **Proposal limits** — max 5 active, 60s cooldown
- **Prompt injection defense** — input sanitization, parameterized SQL
- **Audit trail** — append-only log of every state change

Static analysis

No suspicious patterns detected.