Back to skill

Security audit

Scenario Forecaster

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only forecasting skill whose risky parts are mostly ordinary decision-support and installation hygiene concerns, not hidden or destructive behavior.

Before installing, prefer a pinned and verified ClawHub installer version instead of the unpinned npx command. Treat forecasts, especially financial or policy recommendations, as structured analysis to verify against current sources and qualified judgment, not as automatic advice to execute.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:37
Finding

Unpinned npm Package Is Downloaded and Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 37-40
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Complete Code Snippet:

markdown
### Option 3: One-Click Install
```bash
npx clawhub install scenario-forecaster
text

### Technical Analysis

The documented installation command invokes `clawhub` through `npx` without specifying an exact package version, integrity hash, lockfile, or verified registry source. If the package is not already available locally, `npx` can retrieve the currently published version from the configured npm registry and immediately execute its CLI code.

This creates a time-of-use supply-chain boundary: the code executed by users can change after this Skill has been reviewed. Compromise of the package publisher account, publication of a malicious release, registry substitution, or manipulation of the user's npm registry configuration could therefore turn the documented installation step into arbitrary local code execution.

The audited project itself does not contain malicious scripts, and exploitation depends on compromise or substitution of the external package. Nevertheless, presenting the command as a one-click installation method exposes users to mutable, unreviewed executable content.

### Attack Path

1. An attacker compromises the npm publisher account or distribution path for the `clawhub` package, or causes a victim to use an attacker-controlled npm registry.
2. The attacker publishes or serves a malicious package version containing harmful CLI or lifecycle code.
3. A user follows the installation instructions and runs `npx clawhub install scenario-forecaster`.
4. Because no version or integrity value is pinned, `npx` resolves and downloads the attacker-controlled release.
5. The malicious package executes with the operating-system privileges of the user who invoked the command.
6. The payload can access resources available 
...[truncated 737 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawhub to an exact, reviewed package version rather than allowing npx to resolve the latest release:
    bash
    npx --yes clawhub@EXACT_VERIFIED_VERSION install scenario-forecaster
    
  2. Document the expected npm registry and the verified publisher or package provenance.
  3. Publish an integrity digest or signed release information that users can validate before execution.
  4. Prefer installing dependencies through a committed lockfile and reviewing the resolved dependency tree before running the CLI.
  5. Recommend running the installer with a non-privileged account in an isolated environment without sensitive credentials.
  6. Establish a release-review process so the pinned version is updated only after its package contents, lifecycle scripts, and transitive dependencies have been inspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README recommends running npx clawhub install scenario-forecaster without pinning a specific package version. This causes users to fetch and execute whatever package version is current at install time, increasing supply-chain risk if the package is later compromised, typosquatted, or updated with unsafe behavior. Because this is an installation command in user-facing documentation, it can directly lead to code execution on the user's machine.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is broad enough to be invoked for a wide range of generic forecasting or advisory prompts, increasing the chance of over-triggering in contexts involving finance, policy, or other sensitive decision-making. This can cause the agent to apply powerful analysis and recommendation behavior without clear scoping, guardrails, or domain limits, which is risky even though the content is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

该 API 参考文档整体以中文编写,并在标题中直接以中文面向“编程调用”提供说明,但未说明是否支持其他语言版本或允许用户选择语言/区域设置。根据规则,强制特定语言而没有用户 opt-in 或明确的区域性正当说明,属于自然语言层面的语言/locale 策略风险。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · docs/api_reference.md (reported line 54)May include surrounding context.

"time_horizon": "6 months", "focus_dimensions": ["economic", "technological"] } response = requests.post(url, json=payload) report = response.json() print(report["paths"][0]["name"])

text

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s instructional content is entirely in Chinese, and there is no indication that this language choice is optional or that the skill is intended only for Chinese-speaking users. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and analysis solely in Chinese, with no indication that the user opted into that language and no documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.