Back to skill

Security audit

Nanchang Jbl

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese retail customer-service skill for a Nanchang paint distributor, with some overbroad trigger and documentation risks but no hidden execution, persistence, credential access, or destructive behavior found.

Install only if you want a Chinese-language customer-service assistant for this specific Nanchang Carpoly distributor. Be aware it may respond to broad home-renovation terms, and prefer a pinned or trusted ClawHub installer path rather than running an unpinned `npx` command from elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Unpinned npm CLI Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 13–16
Vulnerability Type: Unpinned third-party installation dependency
Risk Level: Medium

Vulnerable Code

markdown
### Method 2: ClawHub installation

```bash
npx clawhub install nanchang-jbl
text

### Technical Analysis

The documented installation command invokes `clawhub` through `npx` without specifying an exact package version or integrity value. If the package is not already available in the local cache, `npx` can retrieve it from the configured npm registry and immediately execute its CLI code.

Consequently, the code executed during installation is not fully determined by the reviewed Skill artifact. A future package release, compromised package-maintainer account, registry compromise, or malicious dependency introduced into the CLI could alter installation behavior after this audit.

The artifact itself does not contain malicious dependency code, and this finding does not establish that the current `clawhub` package is malicious. The risk arises from executing an unpinned, externally maintained package.

### Attack Path

1. An attacker compromises the npm package, a package-maintainer account, the configured registry, or a transitive dependency used by the `clawhub` CLI.
2. The attacker publishes a malicious release under the package name resolved by `npx`.
3. A user follows the installation command in `README.md`.
4. `npx` downloads the currently resolved package release rather than a specifically reviewed version.
5. The malicious package lifecycle or CLI code executes with the privileges of the user running the command.
6. The code may access or modify any resources available to that user.

### Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope could include user-owned files, environment variables, application configuration, credentials available to that process, and writable proj
...[truncated 550 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to an exact, reviewed version:

    bash
    npx --yes clawhub@<reviewed-exact-version> install nanchang-jbl
    
  2. Document the expected npm registry and verify that users are not resolving the package through an untrusted mirror.

  3. Publish and document the expected package integrity hash or signed provenance where supported.

  4. Prefer a separately installed, organization-approved ClawHub client whose version is managed and audited before use.

  5. Avoid recommending elevated execution and explicitly state that installation must run with ordinary user privileges.

  6. Review each new installer version before updating the pinned version in the documentation.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords include very generic terms such as '油漆', '涂料', '装修', and '刷墙', which can appear in many ordinary conversations unrelated to this merchant. Overbroad activation can cause the skill to hijack unrelated interactions, inject store-specific sales behavior, and steer users toward business actions or disclosure of location/contact details outside the intended context.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The short-keyword table allows activation on highly ambiguous one-word inputs like '地址', '价格', '推荐', '预约', and '附近'. Because these words are common across many unrelated conversations, the skill may engage unexpectedly, causing context confusion, unwanted persona takeover, and inappropriate business guidance in sessions that did not request this store's service.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The README instructs users to run npx clawhub install nanchang-jbl without pinning a specific version. This can cause consumers to fetch whatever package version is current at install time, increasing supply-chain risk if a malicious or compromised update is published later. In a skill-distribution context, install commands are directly acted on by users, which makes this more practically dangerous than passive documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger keywords include very broad everyday terms such as '油漆', '涂料', '装修', and '刷墙', which are likely to match many ordinary conversations unrelated to this specific merchant. Overbroad activation can cause unintended skill invocation, context hijacking, and exposure of persuasive commercial behavior in conversations where the user did not intend to engage this skill. Because this is a retail/customer-service skill, accidental triggering is more concerning: it may steer recommendations, store navigation, or promotions into generic home-improvement queries.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill repeatedly instructs the agent to read files from the references/ directory, but it does not explicitly declare a corresponding tool scope or permission boundary. This creates a capability/manifest mismatch: a host may either grant broader-than-expected file access implicitly or fail open in inconsistent ways, increasing the risk of unintended file reads if the runtime does not strictly sandbox access to only the intended reference files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions require the AI to act as a specific Chinese storefront客服 and to use prescribed Chinese colloquialisms like “亲~” and “咱家”. This forces a language/locale style without user opt-in or an option to adapt to the user's preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains multiple named individuals' phone numbers and store contact details in a broadly consumable skill reference, which is a privacy and data-handling issue unless there is documented consent and a clear lawful basis for publication. In a customer-service skill, exposing personal mobile numbers at scale increases risk of scraping, spam, harassment, and misuse of personally identifiable information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains substantive release notes in Chinese alongside English headings, but it does not indicate that the skill is multilingual or that language selection is optional. Under the language/locale policy, forcing or assuming a language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All visible user-facing instructions, installation prompt text, and trigger phrases are presented only in Chinese, with no indication that users may choose another language. This can violate a language/locale policy when a skill implicitly forces one language without opt-in or an explicit region-specific justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This manifest describes the skill only as an 'intelligent customer service Skill' for a paint/coatings distributor, but it does not specify what user phrases, contexts, or boundaries should trigger it. In a manifest file, the absence of explicit trigger scope or exclusion conditions can lead to unintended invocation for broadly related customer-service queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file discloses the store's Wi‑Fi SSID directly in a broadly accessible skill knowledge file, which exposes an internal network identifier to any user interacting with the skill. While an SSID alone is not a credential, it facilitates reconnaissance and may encourage unauthorized connection attempts or social-engineering against store staff or customers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill content is presented only in Chinese, and there is no natural-language indication that users may choose another language or that the skill is explicitly limited to a Chinese-only regional context. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill content is presented only in Chinese, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file content is entirely written in Chinese and provides no indication that other languages are supported or that the user can opt into this locale. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file uses Chinese-only natural-language strings in the module docstring and user-facing console output, which imposes a specific language on users without any opt-in or fallback. Under the policy for natural-language violations, forcing a locale without documented user choice can be flagged unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.