Back to skill

Security audit

Meeting Note

Security checks for vulnerabilities and agentic risk

Overview

The skill itself is a coherent meeting-notes helper, but its README recommends unpinned npx install commands that can run changing third-party code.

Review the install path before installing. Prefer a pinned, verified ClawHub or skills.sh version, confirm the publisher or repository owner, and avoid running the npx commands with elevated privileges. Once installed, expect the skill to structure potentially sensitive meeting content and, when appropriate, link the output into a local knowledge index.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:28
Finding

Unpinned Packages Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 28–34
Vulnerability Type: Unpinned third-party executable dependencies
Risk Level: Medium

Vulnerable Code

bash
npx clawhub@latest install meeting-note
bash
npx skills add <owner>/meeting-note

Technical Analysis

The documented installation commands use npx, which can retrieve and execute third-party package code on the local system. The first command explicitly selects the mutable latest release of clawhub, rather than a reviewed and immutable version. The second command does not pin the skills package version and uses an unspecified repository owner.

Consequently, the code executed by these commands can change after this project has been audited. Compromise of a package, publisher account, package registry, or referenced repository could cause users following the installation instructions to execute attacker-controlled code. No integrity hash, lockfile, immutable commit, or other verification mechanism is specified.

Attack Path

  1. An attacker compromises the publishing account, package, registry entry, or referenced skill repository.
  2. The attacker publishes a malicious version under the mutable package reference or controls the repository substituted for the placeholder owner.
  3. A user follows the documented installation command.
  4. npx downloads the currently resolved package and runs its CLI or lifecycle code.
  5. The malicious code executes with the privileges of the user running the installation command.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, this could expose accessible files, credentials, environment variables, development repositories, and network resources, or allow modification of user-owned configuration and project files. Administrative or root-level ...[truncated 143 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each CLI package to an exact, reviewed version instead of using @latest or an implicit current version.
  • Replace the repository owner placeholder with the exact verified publisher and repository.
  • Where supported, pin the installed skill to an immutable commit digest or signed release.
  • Publish expected integrity hashes or signature-verification instructions.
  • Review package lifecycle scripts and the dependency tree before recommending installation.
  • Advise users to run installation without administrative privileges and in an isolated environment when practical.
  • Establish a controlled update process in which new dependency versions are reviewed before documentation pins are changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The README presents the skill name and full usage description in Chinese and does not indicate that users may choose another language or locale. This can be a language-policy concern if the skill implicitly constrains output language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation guidance lists very broad keywords such as “会议纪要、会议、谈话、讨论” alongside “meeting notes”. Terms like “meeting”, “conversation”, and “discussion” are common everyday phrases and the README does not provide constraints or negative examples to clarify when this skill should or should not activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The README instructs users to execute npx clawhub@latest install meeting-note, which fetches and runs remote code at install time while tracking the latest release rather than a pinned, reviewed version. This creates a supply-chain risk: a compromised upstream package, malicious new release, or typo-squatted dependency could execute arbitrary code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx skills add <owner>/meeting-note invokes an unpinned package via npx, causing arbitrary package code to be downloaded and executed without version locking. Even though this is only documentation, users following it are exposed to supply-chain compromise if the skills package or one of its transient dependencies is hijacked or changed unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title explicitly defines the file as a meeting-notes output template in Chinese, and the entire template is written as fixed Chinese output text. Because there is no indication that language is configurable or user-selected, this creates a natural-language locale policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file’s natural-language instructions are overwhelmingly in Chinese, but line L003 includes English text ('Use when' and 'meeting notes') as part of the activation description. Because the skill does not explicitly offer a user language preference or opt-in, this may violate the language-choice policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.