Back to skill

Security audit

opencli

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it gives an AI broad access to your logged-in browser sessions and account actions with weak scoping and mutable install steps.

Install only if you are comfortable letting an agent operate a browser profile that is already logged in to supported sites. Use a separate Chrome profile or low-risk accounts, review commands before running them, require explicit confirmation for posts, likes, replies, deletes, DMs, and check-ins, and prefer pinned package versions or reviewed local installs instead of mutable npx/@latest commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:64
Finding

Unpinned Third-Party Packages Are Installed or Executed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: README.md:64-98 and duplicated installation instructions at README.md:226-262
Vulnerability Type: Unpinned and mutable third-party npm dependencies
Risk Level: Medium

Vulnerable Code

bash
npm install -g @jackwener/opencli
bash
claude mcp add playwright --scope user -- npx @playwright/mcp@latest
bash
npx skills add joeseesun/opencli-skill

Technical Analysis

The documented installation process installs or executes third-party npm packages without immutable version pins or integrity verification. The use of @latest explicitly resolves to a mutable future release, while the other commands rely on the registry's current package resolution.

The npm install -g command installs a package globally. The Playwright MCP command executes a transient package through npx and registers the resulting MCP configuration at user scope. The skill installation command also invokes code resolved through npx. Consequently, installation behavior can change after this skill has been reviewed without any change to the files in this repository.

This is a supply-chain exposure rather than evidence that the currently referenced packages are malicious. Exploitation would require compromise of a package, one of its transitive dependencies, its publisher account, or the package-resolution infrastructure.

Attack Path

  1. An attacker compromises a referenced npm package, publisher account, transitive dependency, or registry resolution path.
  2. The attacker publishes a malicious version under a package name used by the documented commands.
  3. A user follows the installation or troubleshooting instructions.
  4. npm or npx resolves the mutable package reference to the compromised release.
  5. Package lifecycle scripts or the resolved executable run with the user's operating-system privileges.
  6. Malicious code can access resources available to that ...[truncated 1080 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every referenced npm package to an exact, reviewed version rather than using an implicit current version or @latest.
  2. Replace the mutable MCP invocation with an exact version, for example:
    bash
    claude mcp add playwright --scope user -- npx @playwright/mcp@<reviewed-exact-version>
    
  3. Pin @jackwener/opencli and the skill installer workflow to reviewed releases.
  4. Publish expected package versions, provenance information, and integrity hashes in the installation documentation.
  5. Where supported, require npm provenance or signature verification before installation.
  6. Prefer a project-local, lockfile-controlled installation over global installation and transient npx execution.
  7. Disable or strictly limit lifecycle scripts during installation where operationally possible, and review any scripts before enabling them.
  8. Run browser-control components under a dedicated low-privilege account or isolated browser profile containing only the sessions required for the task.
  9. Document the permissions granted to the MCP component and provide removal procedures for the user-scoped registration.
  10. Periodically audit pinned packages and transitive dependencies, updating them only after review.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill forces Chinese translation and forbids English-only output without user opt-in, overriding user presentation preferences and potentially altering meaning of sourced content. For security-sensitive or factual browsing tasks, mandatory translation can reduce fidelity, misrepresent quoted content, and manipulate output format beyond the user's request.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README prominently advertises reusing the user's existing Chrome login sessions across many platforms, but its warning section focuses mainly on write/posting risks and does not clearly explain the privacy and account-exposure implications of read access. In this skill's context, read operations can still expose private timelines, bookmarks, messages, watchlists, browsing history, or account-specific content through an AI-controlled browser bridge.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to install and run an MCP server via npx @playwright/mcp@latest, which pulls mutable code at execution time rather than a reviewed, fixed version. Because this MCP is then granted browser-control capabilities over the user's logged-in Chrome session, a compromised or malicious upstream release could immediately gain powerful access to authenticated web sessions and sensitive data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

The README tells users to run npx skills add joeseesun/opencli-skill without pinning a specific version or commit. This means users may install whatever current package content resolves at runtime, creating a supply-chain risk where a later malicious update could alter the installed skill's behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This is another unpinned npx skills installation reference in the Chinese instructions, carrying the same mutable-code execution and supply-chain exposure as the English section. Users may unknowingly install changed skill contents with different capabilities than what the README describes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This duplicate Chinese-language instruction again uses npx @playwright/mcp@latest, which executes the newest available code with browser automation privileges. In this skill's context, that is especially sensitive because the tooling is explicitly designed to reuse live authenticated sessions across multiple third-party platforms.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This is another unpinned npx skills reference in the Chinese section, exposing users to mutable package resolution and unexpected code changes over time. While the README itself is not executable, it directly instructs unsafe installation practice that can lead to compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
78% confidence
Finding

Although this final finding is likely triggered by mention of npx skills in troubleshooting rather than a primary install command, it still normalizes unpinned npx execution. The risk is lower here because it is not adding a new privileged component by itself, but it reinforces unsafe supply-chain practice already present elsewhere in the README.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
76% confidence
Finding

The directive to 'ALWAYS prefer opencli' is behavior-shaping language that biases tool selection regardless of context. While not directly harmful by itself, it can suppress safer or more appropriate alternatives and contributes to overbroad automatic use of a tool that accesses authenticated browser state.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: opencli
description: |
  Use opencli CLI to interact with social/content websites (Bilibili, Zhihu, Twitter/X, YouTube, Weibo, 小红书, V2EX, Reddit, HackerNews, 雪球, BOSS直聘 etc.) via the user's Chrome login session. ALWAYS prefer opencli over playwright/browser automation for these supported sites. Triggers: user asks to browse, search, fetch hot/trending content, post, or read messages on any supported site; 查B站热门, 搜知乎, 看微博热搜, 发推, 搜YouTube, 查股票行情 etc.
---

# opencli

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language is extremely broad, covering generic browsing, searching, posting, and reading messages across many major websites. Such wide matching can cause the skill to activate in commonplace situations and route user activity into a tool that operates through the user's logged-in browser session, increasing the chance of overreach and unintended authenticated access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill manifest presents an opencli-based interface, but the documentation silently expands behavior to full Playwright browser automation for unsupported sites and actions, including reading messages and performing writes through the user's logged-in browser session. This materially broadens the trust boundary and permissions of the skill, enabling access to authenticated content and actions not clearly declared in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation adds a self-extension mechanism that can generate new CLIs, explore arbitrary sites via DOM inspection, and write local configuration under ~/.opencli/clis. That is a substantial capability increase beyond the stated purpose of using an existing CLI for supported sites, and it creates a path to persistently expand scraping/automation against new domains without clear review or user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Developer-oriented instructions to inspect DOM structure with browser_evaluate and author local YAML scraping templates are not obviously necessary for normal end-user website interaction. In this context, they increase the skill's ability to reverse-engineer site structure and build custom extraction logic against authenticated pages, which meaningfully raises abuse potential.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command reference exposes a broader capability surface than the manifest description, including many authenticated services and account-scoped operations. This can mislead downstream agents or reviewers about what the skill can access, increasing the chance of unauthorized browsing of private data or unexpected actions through the user's logged-in Chrome session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file contains many command descriptions and option explanations only in Chinese, despite being titled as a general command reference in English. This may impose a language constraint on users without opt-in or an explicit statement that the reference is intended for Chinese-speaking or China-specific contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented posting and engagement commands (twitter post, twitter reply, twitter like) perform visible account actions but are presented like ordinary retrieval commands. Without prominent warnings and consent boundaries, an agent could post, reply, or interact on behalf of the user due to prompt injection, misunderstanding, or ambiguous instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

twitter delete is a destructive account action that can permanently remove user content, yet the reference provides no warning, safeguard, or confirmation requirement. In an LLM-agent workflow, omission of such guardrails materially increases the risk of accidental or socially engineered deletion of tweets.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented v2ex daily command performs a side-effecting account action (daily check-in and coin claim), but that behavior is not clearly reflected in the high-level description as an account modification. In an agent setting, undocumented side effects are dangerous because a model may invoke them while believing it is only retrieving information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The automatic v2ex daily check-in changes account state and claims rewards, but the reference lacks a warning that it is not a read-only operation. Although lower impact than deletion or posting, it still authorizes the agent to act on the user's behalf without clearly signaling that behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.