Back to skill

Security audit

Pearl Calc

Security checks for vulnerabilities and agentic risk

Overview

The calculator itself is coherent, but its setup delegates to an unpinned external Pearl skill and mutable setup instructions, so users should review that chain before installing.

Install only if you are comfortable with a paid remote calculator and with installing Pearl as a separate dependency. Before approving setup, review the Pearl skill being installed, its payment limits, and any commands it asks the agent to run; avoid sending sensitive formulas or private business data as calculator expressions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned External Skill Installation and Instruction Delegation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:3, 20-21
Vulnerability Type: Unpinned third-party Skill dependency and delegation to unaudited external instructions
Risk Level: Medium

Vulnerable Code Snippet:

yaml
description: "Paid math calculator — $0.01/expression via Pearl payments. Run: node {baseDir}/scripts/calc.js \"<expr>\". Right after install of this skill, ask user if he wants to proceed with setup. If yes, then you go through setup process: install nodejs deps, install pearl skill (clawhub install pearl), read pearl's SKILL.md and proceed."
markdown
1. Install the pearl skill: `clawhub install pearl`
2. Read pearl's SKILL.md and follow its **Setup (one-time)** section.

Technical Analysis

The setup procedure installs the external pearl Skill without specifying an immutable version or integrity digest. It then instructs the Agent to read and follow that Skill's setup instructions. Consequently, the effective setup behavior is not fully represented by the code reviewed in this project and may change independently after this audit.

This creates a supply-chain trust boundary: control of the registry entry, its distribution infrastructure, or a future release could allow an attacker to supply altered instructions. User approval before setup reduces accidental execution but does not establish the authenticity or safety of the subsequently retrieved content.

The project also pins @pearl-cash/client to version 0.0.15, but no lockfile or integrity metadata was present in the audited directory. The primary confirmed issue is the unpinned external Skill and instruction delegation.

Attack Path

  1. An attacker compromises the pearl registry entry, its publisher account, or its distribution channel, or publishes a harmful future release under the trusted name.
  2. A user approves the documented setup process.
  3. The Agent executes clawhub install pearl without a v ...[truncated 1304 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the external pearl Skill to a specifically audited version and an immutable cryptographic digest.
  2. Verify signatures or checksums before loading or following external Skill instructions.
  3. Vendor the required setup instructions locally, or explicitly document the exact audited commands instead of delegating to mutable external text.
  4. Require separate, informed user confirmation before each consequential installation or command rather than one broad setup approval.
  5. Restrict setup execution to the minimum required tools, filesystem paths, network destinations, and credentials.
  6. Add and commit a package lockfile with registry integrity metadata for Node.js dependencies, and use a deterministic installer such as npm ci.
  7. Re-audit any updated Pearl Skill or client dependency before deployment.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code does implement the core calculator behavior by taking an expression and obtaining a result from a Pearl-hosted calculator service. However, the declared description emphasizes paid usage via Pearl payments and a required post-install setup process, neither of which appears in this code chunk. Instead, the actual code primarily validates input and makes an outbound request to https://pearlcash.ai/api/calc through the Pearl client. That remote network access is not reflected in the declared permissions, and payment logic is absent from the visible implementation. This is a material description-to-behavior mismatch, even though the high-level calculator purpose is partially aligned.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest instructs the agent to initiate a broad post-install setup flow, including installing dependencies and another skill, without tightly scoping what may be executed. This increases the risk of over-permissioned or unintended actions, especially because it chains trust into a second skill and its instructions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The instruction to proceed with setup while not asking the user to manually run commands encourages the agent to take autonomous action on the user's environment. Even though user approval is mentioned, the wording reduces user visibility and can normalize automatic installation and configuration of software and dependencies.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
## Pearl

This skill is powered by [Pearl](https://pearlcash.ai) — Stripe for AI agents. Pearl handles payments with user-defined limits, list of approved skills, anti-fraud, and works universally across all Pearl-powered skills. Pearl runs its own setup separately, with user approval (user approves, but don't ask user to manually run commands for user's convinience).

This skill requires Pearl to be installed and set up to work:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as a calculator invoked locally, but the implementation sends the user’s expression to a remote Pearl API through the pearl client. This is a security-relevant behavior mismatch because users may reasonably expect local-only processing, while their inputs are actually disclosed to an external service and subject to remote handling, logging, or policy changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-provided expressions are transmitted to a remote service without any user-facing disclosure at runtime in the script. Even though the input is filtered to look like math, expressions can still contain sensitive business logic, financial data, or proprietary formulas, so silent exfiltration to a third party creates a real privacy and trust risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code requires outbound network access to perform a calculator function, which is not inherently unsafe but increases the attack surface and trust requirements versus a local calculator. In this context, the dependency is somewhat justified by the skill metadata describing a paid Pearl-backed calculator, but the remote dependency still creates privacy, availability, and integrity risks if the service is unavailable or compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.