Back to skill

Security audit

Pc Monitor Cn

Security checks for vulnerabilities and agentic risk

Overview

This looks like a simple local system monitor, but its launcher can automatically install an unpinned Python dependency without clear user approval.

Install only if you are comfortable with a local monitor that may run pip and modify your Python environment when launched through monitor.sh. Prefer reviewing or changing the wrapper so it fails with a clear dependency error, then install a pinned psutil version in a virtual environment or through your OS package manager before running it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/monitor.sh:13
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: scripts/monitor.sh, lines 13–17
Vulnerability Type: Supply-chain risk caused by runtime installation of an unpinned dependency
Risk Level: Medium

Complete Code Snippet:

bash
# Check whether psutil is installed
if ! python3 -c "import psutil" 2>/dev/null; then
    echo "Installing psutil..."
    pip3 install psutil -q
fi

Technical Analysis

The wrapper automatically invokes pip3 when psutil is unavailable. The installation command does not pin an audited package version, verify an integrity hash, select an explicitly trusted package repository, or require an isolated virtual environment.

Package resolution therefore depends on the user's pip configuration, configured index URLs, network environment, and the package version available at execution time. If a configured package index, mirror, DNS/network path, or upstream release is compromised, executing the otherwise legitimate monitoring wrapper could install and run attacker-controlled code.

Python packages can execute build and installation logic during installation. A malicious package or compromised release may therefore execute code before the monitoring script starts. This finding concerns unsafe dependency acquisition; the reviewed project itself does not contain evidence that it intentionally retrieves a malicious package.

Attack Path

  1. An attacker compromises or controls a package source, mirror, or index configured for the victim's pip3, or causes it to serve a malicious psutil distribution.
  2. The victim runs scripts/monitor.sh in an environment where psutil cannot be imported.
  3. The dependency check fails, causing the wrapper to execute pip3 install psutil -q.
  4. Pip resolves and downloads the attacker-controlled or compromised distribution without enforcing a reviewed version or expected hash.
  5. Malicious package installation or build logic executes with the privi ...[truncated 814 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic package installation from the runtime wrapper. If psutil is unavailable, terminate with a clear error and direct the operator to an explicit installation process.
  2. Declare dependencies in a lock or requirements file using a reviewed, exact version rather than an unconstrained package name.
  3. Enforce distribution integrity with hashes, for example by using a hash-locked requirements file and pip install --require-hashes.
  4. Install dependencies into a dedicated virtual environment during a controlled deployment step instead of modifying the invoking user's global or shared Python environment.
  5. Use an explicitly configured, trusted package repository and secure transport. Restrict or audit pip configuration that can redirect dependency resolution to untrusted indexes.
  6. Incorporate dependency vulnerability and provenance checks into the release process, and update the pinned version through a reviewed procedure.
  7. Replace the installation block with a non-mutating dependency check, such as:
bash
if ! python3 -c "import psutil" 2>/dev/null; then
    echo "Error: psutil is required. Install the audited, pinned dependency in an isolated environment." >&2
    exit 1
fi
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown description and usage guidance are presented exclusively in Chinese, which imposes a language choice on users without opt-in. The policy specifically calls for flagging skills that force a specific language or locale unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The wrapper script silently expands its behavior from monitoring into software installation by invoking pip3 install psutil when the dependency is missing. This changes the host system state, may pull unpinned code from package indexes, and can violate user expectations for a read-only monitoring utility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a package installation without clearly warning the user or requesting confirmation, which is a system-changing action inappropriate for a simple monitor launcher. In an agent skill context, this is more dangerous because users may expect passive status viewing while the skill modifies the environment and retrieves external code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents the skill description in Chinese only ("监控系统资源状态的 OpenClaw skill。") and does not indicate that language selection is optional or that the skill is intentionally region-specific. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file-level natural-language description is written as a Chinese-only skill description with no indication that the language is selectable or that the tool is intentionally region-specific. The policy requires flagging language or locale constraints when a specific language is imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script's descriptive comments and error/status messages are written in Chinese, with no indication that the skill is region-specific or that users can choose another language. This can violate a language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.