Back to skill

Security audit

OpenTangl Plugin

Security checks for vulnerabilities and agentic risk

Overview

The plugin is mostly clear about being a high-impact OpenTangl automation bridge, but it needs review because it can automate repository changes and may execute an unpinned npx fallback with the user's environment.

Install only if you intend to let OpenClaw operate OpenTangl with access to the configured workspace, git/GitHub tooling, and AI-provider credentials. Prefer setting an explicit trusted `bin` path to a preinstalled OpenTangl executable, avoid the `npx tsx` fallback, run under a least-privilege account with narrowly scoped repo/GitHub permissions, and enable mutating tools only when you are comfortable with automated commits, PRs, and merges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
index.ts:52
Finding

Unpinned Runtime Package Retrieval and Execution via npx

Content
View full analysis

Vulnerability Details

File Location: index.ts, lines 52–54
Vulnerability Type: Runtime supply-chain exposure through implicit package retrieval
Risk Level: Medium

Vulnerable Code

ts
if (existsSync(srcCli)) {
  return { file: "npx", baseArgs: ["tsx", srcCli] };
}

The returned command is subsequently executed here:

ts
const result = spawnSync(bin.file, [...bin.baseArgs, ...args], {
  cwd: workdir,
  encoding: "utf-8",
  timeout,
  env: { ...process.env },
});

Technical Analysis

When the globally installed opentangl command is unavailable and src/cli.ts exists in the configured workspace, the plugin falls back to npx tsx src/cli.ts.

The tsx package is neither pinned as an exact runtime dependency nor invoked with npx --no-install. If it is unavailable locally, npx may resolve, download, and execute package code from the configured npm registry at runtime. Consequently, the code that executes can differ from the code reviewed with this plugin.

This behavior is not required by the plugin's minimum declared functionality because its documentation already identifies an installed and configured OpenTangl environment as a prerequisite. It also broadens the trust boundary from the installed plugin and OpenTangl executable to the current registry configuration and whichever tsx version is selected at invocation time.

Although command arguments are safely passed without a shell, preventing ordinary shell-metacharacter injection, that protection does not mitigate package-resolution attacks. The spawned process also inherits the complete OpenClaw environment, including documented AI-provider API keys and potentially unrelated secrets.

Attack Path

  1. The configured opentangl executable is absent or fails the startup --version probe.
  2. The configured workspace contains src/cli.ts, selecting the npx tsx fallback.
  3. No trusted local tsx executable ...[truncated 1096 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic npx fallback and require a preinstalled, administrator-configured OpenTangl executable.
  2. If TypeScript-source execution must remain supported, add tsx as an exact, integrity-locked dependency and invoke its local binary directly.
  3. If retaining npx, use npx --no-install tsx ... so a missing local dependency causes a safe failure rather than a network installation.
  4. Avoid floating version selection. Pin and review the exact tsx version and regenerate the lockfile from the minimal required dependency set.
  5. Validate that the selected executable resolves to an expected trusted path before launching it.
  6. Replace { ...process.env } with an explicit environment allowlist containing only variables required by OpenTangl. Pass provider credentials only to commands that need them.
  7. Run the plugin and OpenTangl CLI under a restricted service account with narrowly scoped repository and GitHub permissions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Known Vulnerable Dependency: @mariozechner/pi-coding-agent==0.61.1 — 3 advisory(ies): CVE-2026-54326 (Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization by); CVE-2026-54328 (Pi Agent: Predictable temporary extension install paths allow local privilege es); CVE-2026-54327 (Pi Agent: Race condition in Pi auth.json writes could expose stored credentials)

High
Category
Supply Chain
Confidence
95% confidence
Finding

@mariozechner/pi-coding-agent 0.61.1 is a high-risk agent-oriented package with advisories covering XSS, predictable temp paths, and credential exposure races. In this skill context, agent/coding tooling increases the danger because such packages often process untrusted content, write files, and handle secrets, making the listed issues materially relevant.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

axios 1.13.6 is listed with multiple advisories including SSRF-related NO_PROXY bypasses and prototype-pollution-adjacent impacts. This is especially relevant in an agent ecosystem where outbound HTTP requests are common, because proxy bypass, credential leakage, or request tampering can meaningfully expand attacker reach.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: basic-ftp==5.2.0 — 4 advisory(ies): GHSA-6v7q-wjvx-w8wg (basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Exe); CVE-2026-39983 (basic-ftp has FTP Command Injection via CRLF); CVE-2026-41324 (basic-ftp vulnerable to denial of service via unbounded memory consumption in Cl) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

basic-ftp 5.2.0 has advisories for FTP command injection via CRLF and denial-of-service conditions. If any agent workflow consumes attacker-influenced FTP paths, commands, or servers, this can lead to arbitrary FTP command execution or service disruption, so the dependency is a meaningful risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==5.0.5 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-45149 (brace-expansion: Large numeric range defeats documented `max` DoS protection); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
94% confidence
Finding

brace-expansion 5.0.5 is associated with multiple denial-of-service issues caused by pathological expansion inputs. In tooling and agent environments that may process attacker-controlled glob patterns, archive contents, or ignore/include rules, this can become a practical CPU or memory exhaustion vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README recommends a fallback entry point of npx tsx src/cli.ts, which invokes tooling without a pinned version. If tsx is resolved from an untrusted or changed package source, users may execute unexpected code, and this plugin operates in a high-trust automation context that can run workflows, write code, and manage merges. Because this is documentation that influences operator configuration, the risk is real even though it is not an immediate exploit by itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises tools that can commit changes, open pull requests, wait for CI, and merge code, but the example workflow does not clearly foreground the repository impact or recommend explicit operator confirmation before destructive or high-trust actions. In an agent/tooling context, normalizing these operations through chat increases the chance of accidental or over-broad execution, especially because the plugin is designed to register native tools directly into an agent runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

If no installed binary is found and src/cli.ts exists, the plugin executes npx tsx src/cli.ts. npx may fetch or resolve packages dynamically from the registry or environment, so an unpinned tsx can lead to unexpected code execution or supply-chain compromise, especially because this plugin exposes high-impact automation tools that can write code, create commits, and merge changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The fallback invocation uses npx tsx src/cli.ts without pinning an exact package version. If tsx is not already available locally, npx may resolve or download a package version from the registry at execution time, creating a supply-chain risk and making builds non-reproducible. In this plugin, the risk is more significant because the tool can trigger high-impact actions such as writing code, creating commits, and merging changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This code path returns { file: "npx", baseArgs: ["tsx", srcCli] }, which means runtime execution depends on an unpinned package toolchain. An attacker who can influence package resolution, registry contents, or the local environment could cause unexpected code to run under the plugin's privileges. Because this skill exposes automation that can modify repositories and run workflows, the context increases the blast radius of a compromised dependency.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description promises broad autonomous capabilities such as proposing tasks, running autopilot cycles, executing workflows, reviewing cross-repo wiring, and managing merges 'all from chat' without clear trigger boundaries or safety constraints. That ambiguity can cause overbroad invocation and excessive authority use, especially in a multi-repo development context where unintended activation could modify code, workflows, or merge state across repositories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The config description indicates automatic fallback to npx tsx src/cli.ts, which is an unpinned execution path that can pull or invoke tooling without a fixed version guarantee. In a skill that advertises autonomous workflow execution and merge-pipeline control, this increases supply-chain and execution-risk because a compromised or unexpected tool version could run with the user's workspace permissions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @anthropic-ai/sdk==0.80.0 — 2 advisory(ies): CVE-2026-34451 (Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to ); CVE-2026-41686 (Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesys)

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins @anthropic-ai/sdk 0.80.0, and the listed advisories indicate real issues in path validation and local file permissions. Even though this package is marked as a peer/transitive dependency and the lockfile alone does not prove the vulnerable features are exercised, keeping a known-vulnerable SDK version in the dependency graph is a genuine supply-chain risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @hono/node-server==1.19.11 — 2 advisory(ies): CVE-2026-39406 (@hono/node-server: Middleware bypass via repeated slashes in serveStatic); GHSA-frvp-7c67-39w9 (Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encode)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

@hono/node-server 1.19.11 is flagged for middleware bypass and Windows path traversal issues related to static file serving. This is a real vulnerable dependency entry, though the actual exploitability depends on whether the skill or its host exposes serveStatic or similar file-serving behavior.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @protobufjs/utf8==1.1.0 — 1 advisory(ies): CVE-2026-44288 (protobufjs has overlong UTF-8 decoding)

Low
Category
Supply Chain
Confidence
78% confidence
Finding

The lockfile includes @protobufjs/utf8 1.1.0 with an overlong UTF-8 decoding advisory. This is a real vulnerable component, but by itself it is usually a low-severity parser weakness unless the application relies on strict UTF-8 validation for security decisions.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: body-parser==2.2.2 — 1 advisory(ies): CVE-2026-12590 (body-parser vulnerable to denial of service when invalid limit value silently di)

Low
Category
Supply Chain
Confidence
80% confidence
Finding

body-parser 2.2.2 is flagged for a denial-of-service issue tied to invalid limit handling. This is a real dependency vulnerability, but its practical impact depends on whether the application exposes HTTP parsing paths using attacker-supplied bodies and misconfigured limits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 29)May include surrounding context.

json
"openclaw": ">=1.0.0"
  },
  "dependencies": {
    "@sinclair/typebox": "^0.34.0"
  },
  "devDependencies": {
    "@types/node": "^22.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 32)May include surrounding context.

json
"@sinclair/typebox": "^0.34.0"
  },
  "devDependencies": {
    "@types/node": "^22.0.0",
    "typescript": "^5.5.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
},
  "devDependencies": {
    "@types/node": "^22.0.0",
    "typescript": "^5.5.0"
  }
}

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
dist/index.js:24

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.ts:47