Back to skill

Security audit

Find Skills Skill 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is a simple skill-discovery guide, but it repeatedly tells agents or users to run an unpinned remote CLI through npx.

Review before installing. Prefer using a pinned, reviewed `clawhub` version or a trusted local install, and avoid allowing an agent to run unpinned `npx` commands in sensitive environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned ClawHub Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35, 38, 62, 65, 70, 75, 80, and 85
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

bash
# Search skills
npx clawhub search "keyword"

# Browse categories
npx clawhub browse
bash
# Web search skills
npx clawhub search "web search"

# Weather skills
npx clawhub search "weather"

# Document skills
npx clawhub search "document"
bash
# Tavily skills
npx clawhub search "tavily"

# GitHub skills
npx clawhub search "github"

# Calendar skills
npx clawhub search "calendar"
bash
# Most installed skills
npx clawhub search --sort installs

# Most starred skills
npx clawhub search --sort stars

Technical Analysis

The skill repeatedly instructs users or agents to invoke the clawhub package through npx without specifying an exact package version, lockfile, integrity hash, or trusted local installation. When the package is not already installed locally, npx can resolve and download a mutable package release from the configured package registry before executing it.

This creates a third-party supply-chain trust boundary that is not represented in the reviewed artifact. The effective executable code can change after this skill has been audited. A compromised registry account, package takeover, malicious future release, or registry-resolution attack could therefore cause attacker-controlled package or lifecycle code to execute.

The project itself contains no executable scripts, and there is no evidence that the current clawhub package is malicious. The risk arises from the unsafe, unpinned dependency-execution pattern.

Attack Path

  1. An attacker compromises the package publisher, registry account, distribution infrastructure, or a future package release.
  2. The attacker publishes a malicious version that can be selected by the unversi ...[truncated 1077 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace unversioned commands with an exact, reviewed package version, for example:
    bash
    npx --yes clawhub@<reviewed-exact-version> search "keyword"
    
  2. Prefer installing the reviewed CLI through a controlled dependency manifest and lockfile rather than allowing an implicit download each time the skill is used.
  3. Verify the package source and record registry integrity metadata or checksums in the deployment process.
  4. Configure package installation to use a trusted registry and enforce organizational allowlists where available.
  5. Disable or suppress unnecessary dependency lifecycle scripts during installation when compatible with the CLI.
  6. Execute the CLI in a restricted environment with minimal filesystem, credential, and network access.
  7. Document an approved package version and require security review before updating it.
  8. Avoid presenting unpinned npx execution as the default workflow; if a trusted local binary is required, invoke that binary directly and fail safely when it is unavailable.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx clawhub search "keyword" without pinning an exact package version. npx may fetch the latest published package at execution time, so a compromised upstream package, malicious update, or dependency hijack could result in arbitrary code execution on the user's machine. Because this is a discovery skill that encourages repeated CLI use, the exposure is real even though the content appears instructional rather than malicious.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command npx clawhub browse invokes an unpinned package from the registry, which can change over time and may execute attacker-controlled code if the package or its dependencies are compromised. This is especially risky in documentation because users may copy-paste it directly, trusting the skill's guidance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This example directs users to run npx clawhub search "web search" without specifying a fixed version. Unpinned npx execution creates a supply-chain risk because the resolved code can differ between runs and could be malicious if the upstream package is replaced or tampered with.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The skill includes npx clawhub search "weather" as a copy-paste command, again relying on an unpinned registry package. If the package version resolved at runtime is malicious, the user may execute arbitrary code while expecting only a search operation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command npx clawhub search "document" is another instance of executing a remote package without version pinning. Even in a benign skill, this increases the attack surface for supply-chain compromise and makes builds or user actions non-reproducible.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

Using npx clawhub search "tavily" without an exact version exposes users to package substitution or malicious updates from the npm ecosystem. The risk is not from the search term but from the execution model: documentation is prompting direct execution of mutable third-party code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The npx clawhub search "github" example is a true supply-chain risk because it executes whatever package version the registry currently serves. In a skill meant to help users discover more software, this weakens trust boundaries and may normalize unsafe execution habits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command npx clawhub search "calendar" remains vulnerable for the same reason: unpinned remote code execution via npx. The skill context makes this moderately dangerous because it is a discovery guide likely to be widely reused, increasing the chance of copy-paste execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

npx clawhub search --sort installs executes an unpinned npm package, leaving users exposed to arbitrary code if the package or dependency chain is compromised. Because the skill repeatedly recommends this tool as the primary discovery source, the unsafe pattern is amplified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The example npx clawhub search --sort stars is a true positive because it runs a mutable third-party package without version pinning. If an attacker publishes a malicious update or compromises dependencies, users following the skill may unknowingly run attacker code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.