Back to skill

Security audit

Manual AI

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill helps users manually use external AI websites, with privacy and installer hygiene caveats but no hidden execution or malicious behavior found.

Install only through a trusted ClawHub path or a pinned verified installer when possible. Do not paste or upload secrets, credentials, personal data, confidential business documents, or regulated material to the listed AI websites unless your organization permits it and you accept that the provider may process or retain it under its own terms.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:31
Finding

Unpinned npm Package Execution During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 31-35
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npx clawhub install manual-ai
text

### Technical Analysis

The documented installation command invokes `clawhub` through `npx` without specifying an audited package version or validating package integrity. If the package is not already available locally, `npx` may resolve, download, and execute the version currently published in the configured npm registry.

Consequently, the code executed during installation is not immutably tied to the Skill version reviewed in this audit. A compromised npm publisher account, malicious package update, registry compromise, or dependency substitution could cause the command to execute code that was not present during the audit.

### Attack Path

1. An attacker compromises the npm package, its publisher account, its dependency chain, or the registry used by the victim.
2. The attacker publishes or serves a malicious version under the package name `clawhub`.
3. A user follows the installation instructions and runs `npx clawhub install manual-ai`.
4. `npx` dynamically resolves and downloads the attacker-controlled package version.
5. The downloaded package executes with the privileges and environment access of the invoking user.

### Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, attacker-controlled code could read or modify user-accessible files, access environment variables and credentials, alter installed Skills or development tools, establish network connections, or compromise projects accessible to the user.

The command does not itself request elevated privileges, so the direct privilege boundary is normally limited to the invoking user's perm
...[truncated 134 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to a specific, reviewed version rather than relying on the registry's current version:
    bash
    npx clawhub@<verified-version> install manual-ai
    
  2. Document the package's official registry, source repository, expected publisher, and verified version so users can confirm provenance.
  3. Where supported, verify the downloaded package against a published integrity hash or signed release artifact before execution.
  4. Review the pinned package and its transitive dependencies before recommending it as an installation mechanism.
  5. Update the pinned version only after reviewing the new release, rather than allowing installation behavior to change automatically.
  6. Advise users to run the installer as an unprivileged account and in an environment without unnecessary secrets or credentials.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

All user-facing documentation in this file is presented in Chinese, and the recommendation logic explicitly steers '中文任务' to specific Chinese platforms without indicating any user language preference or opt-in. Under the policy, forcing a specific language or locale without choice can be a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README encourages users to submit tasks to multiple third-party AI web platforms but does not warn that prompts, files, or sensitive business data may be transmitted to external providers. In a fallback/manual workflow, users may paste internal content during outages, increasing the chance of accidental data leakage to services with different retention, training, or jurisdictional policies.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx clawhub install manual-ai without pinning a specific version of the package. This creates a supply-chain risk because future or compromised package versions could be fetched and executed unexpectedly, and npx may run code during install time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description and operating instructions are entirely in Chinese and include recommendations such as using Chinese prompts for certain platforms, but do not offer an alternative language or state that Chinese is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly tells users to upload files and documents to third-party AI services, but provides no warning about confidentiality, retention, model training, jurisdiction, or compliance risks. This can lead users to disclose sensitive personal, corporate, or regulated data to external providers under unsafe assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The NotebookLM workflow requires uploading source documents and downloading generated artifacts, yet it omits any caution about exposing sensitive source material to an external service. Because this section is procedural and specific, it increases the likelihood that users will follow it verbatim with confidential documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The NotebookLM instructions tell users to upload PDFs, webpages, and documents to a third-party AI service without any warning about privacy, confidentiality, data retention, or consent. In a manual AI workflow skill, users may be handling sensitive business or personal material, so omission of a disclosure materially increases the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The text says '英文效果更好' for Gemini image prompting, and later says '中文效果好' for 豆包, which steers users toward specific languages. Because the guide presents language preference guidance without offering user opt-in or explaining a justified locale constraint, it can be read as a language/locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.