Back to skill

Security audit

Skills Finder

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can run mutable npm tools and install agent skills without enough version pinning or confirmation.

Review this before installing if you care about reproducible or tightly controlled agent environments. Use it only in a restricted workspace, avoid exposing secrets to the process environment, and prefer pinned or preinstalled marketplace CLIs before allowing it to search, list, or install skills.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/skill-finder.sh:120
Finding

Unpinned npm CLI Packages Allow Mutable Third-Party Code Execution

Content
View full analysis
&1 || { print_warning "ClawHub search failed or rate limited" fi } # Search Skills.sh search_skills() { local query="$1" print_source "Skills.sh" echo "Searching: '$query'" npx skills find "$query" 2>&1 || { print_warning "Skills.sh search failed" fi } ``` `scripts/skill-finder.sh:268-298`: ```bash case "$source" in clawhub) npx clawhub@latest install "$name" 2>&1 ;; skills) npx skills add "$name" 2>&1 ;; all) print_status "Trying ClawHub first..." npx clawhub@latest install "$name" 2>&1 || { print_status "Trying Skills.sh..." npx skills add "$name" 2>&1 } ;; esac } # List command cmd_list() { print_status "Installed skills:" echo "" print_source "ClawHub" npx clawhub@latest list 2>&1 || echo "(none)" echo "" print_source "Skills.sh" npx skills list 2>&1 || echo "(none)" } ``` `SKILL.md:46-59` documents the same mutable dependency usage: ```bash npx clawhub@latest search "" npx clawhub@latest install ``` ```bash npx ...[truncated 3584 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger examples include very broad phrases such as "what can you do" and generic requests for tools, which can cause the skill to activate during ordinary conversation rather than explicit consent to search external marketplaces or install software. In this skill's context, over-triggering is more dangerous because activation can lead to external command execution and software installation workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs use of npx clawhub@latest, which fetches and executes remote package code at runtime without a fixed version. Even though @latest is specified, it is not pinned to an immutable version, so a compromised upstream package, malicious update, or dependency hijack could lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This installation command uses npx clawhub@latest install <name>, combining unpinned remote code execution with package installation. That increases risk because the invoked tool and the installed package source may both change over time, enabling supply-chain compromise or execution of attacker-controlled code.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command npx skills find "<query>" executes a package resolved at runtime without a pinned version. If the skills package or one of its dependencies is compromised, the act of searching alone could execute malicious code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The command npx skills add <package> invokes an unpinned remote CLI and then installs additional code, creating a layered supply-chain risk. An attacker controlling the CLI package, registry resolution, or package metadata could cause arbitrary code execution or persistence through installed skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This implementation guidance again instructs runtime execution of npx clawhub@latest, which is mutable and externally controlled. Repeating the pattern in the implementation section makes accidental operational use more likely and reinforces unsafe execution practices.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The implementation section uses npx skills find "<query>" without pinning or integrity constraints. Because this skill is specifically designed to search and install third-party skills, the surrounding context increases danger by normalizing execution of untrusted ecosystem tooling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The install flow executes package-manager commands that can modify the system and fetch external code without any confirmation prompt, dry-run, or explicit warning about side effects. In this skill's context, that is more dangerous because it advertises one-click installation from multiple external marketplaces, increasing the chance users trigger significant system changes without understanding the trust implications.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The script executes npx clawhub@latest install, which fetches and runs remote code at install time from the registry. Using @latest makes execution non-reproducible and exposes users to supply-chain compromise, malicious updates, or account takeover of the package publisher.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The script runs npx skills add without pinning a package version, so npx may resolve and execute whatever version is currently published. In a skill installer context, that magnifies supply-chain risk because this script is explicitly designed to install further components from external marketplaces.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

This executable npx clawhub@latest install invocation again runs remote code from a mutable package reference. Because it is part of the default all installation flow, many users may hit this path automatically, increasing exposure to compromised upstream packages.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This fallback path executes npx skills add if the ClawHub install fails, introducing another unpinned remote execution path. Automatic fallback means users may unknowingly run a second external package-manager command from a different source, compounding trust and supply-chain concerns.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The list command executes npx clawhub@latest list, which still requires fetching and running remote package code even though the operation appears read-only. A compromised package could abuse that trust boundary to execute arbitrary code on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This npx skills list call executes an unpinned external package for a seemingly harmless listing action. Users may underestimate the risk because the command name sounds non-destructive, but the execution model still permits arbitrary code from the resolved package version.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
### Supported Languages (Truly Universal)

This skill supports **ALL languages and scripts** including but not limited to:

| Language Family | Examples |
|-----------------|----------|

Static analysis

No suspicious patterns detected.