Back to skill

Security audit

InkOS - Autonomous Novel Writing Agent

Security checks for vulnerabilities and agentic risk

Overview

InkOS appears to be a disclosed novel-writing CLI, but it installs an unpinned third-party executable that will handle manuscripts and API keys, so it should be reviewed before installation.

Install only if you trust the @actalk/inkos npm package and its publisher. Pin or verify the package version where possible, keep API keys scoped, use only trusted provider base URLs, keep inkos.json and logs out of source control, and avoid the self-update path in managed environments without a fresh review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Executable npm Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5
Vulnerability Type: Unpinned executable dependency
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: { "openclaw": { "emoji": "📖", "requires": { "bins": ["inkos", "node"], "env": ["OPENAI_API_KEY"] }, "primaryEnv": "OPENAI_API_KEY", "homepage": "https://github.com/Narcooo/inkos", "install": [{ "id": "npm", "kind": "node", "package": "@actalk/inkos", "label": "Install InkOS (npm)" }] } }

Technical Analysis

The Skill descriptor directs the platform to install the executable @actalk/inkos package from npm without specifying an exact version or package integrity hash. Consequently, installation may resolve to a package release published after this Skill was reviewed.

The audited project contains only SKILL.md; it does not include the dependency's executable source code. Claims elsewhere in the document—such as the absence of installation hooks, telemetry, or writes outside the project directory—therefore cannot be independently verified from the supplied artifact. Even if those claims accurately describe the current package, an unpinned future release could behave differently.

This constitutes a supply-chain trust weakness rather than evidence that the current npm package is malicious.

Attack Path

  1. An attacker compromises the npm publisher account, package publication pipeline, or another component of the package's release process.
  2. The attacker publishes a malicious release under the legitimate @actalk/inkos package name.
  3. A user or automation system installs the Skill after that release is published.
  4. Because no exact version or integrity value is specified, npm resolves the dependency to the attacker-controlled release.
  5. The package's code executes when the user invokes inkos, potentially inheriting the user's local permissions, working-directory access, and environment.
  6. The malicious release can access or ...[truncated 612 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin @actalk/inkos to a specific, reviewed version rather than allowing unconstrained resolution.
  2. Record and verify the expected npm package integrity hash or lockfile integrity metadata.
  3. Review the package contents and transitive dependency tree before approving each upgrade.
  4. Treat version updates as security-sensitive changes requiring a new audit.
  5. Where practical, vendor or otherwise retain the reviewed source artifact so the executed implementation corresponds to the audited version.
  6. Run the CLI with least privilege and expose only the environment variables and project directories required for the current operation.
  7. Continue using environment-variable-based credential configuration, but ensure secrets are scoped to the process and are not committed to source control.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
91% confidence
Finding

The skill supports dynamic selection of external providers and models, including sending API keys and manuscript content to configured endpoints. In an agent-driven environment, this creates a high-risk exfiltration path if configuration can be influenced by prompts, project state, or an untrusted operator, because sensitive content and credentials may be routed to unintended third parties.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Configure your LLM provider (OpenAI, Anthropic, or any OpenAI-compatible API)

Prefer --api-key-env so the key never appears in shell history:

export OPENAI_API_KEY=sk-xxx inkos config set-global --provider openai --base-url https://api.openai.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

For compatible/proxy endpoints, use --provider custom and point ONLY to trusted endpoints:

inkos config set-global --provider custom --base-url https://your-trusted-proxy.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

text

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
96% confidence
Finding

The documented --provider custom --base-url ... --api-key-env ... path is particularly dangerous because it enables forwarding API credentials and user content to arbitrary OpenAI-compatible endpoints. Even though the text warns to use trusted proxies, the capability materially increases the chance of credential leakage or covert exfiltration if an attacker can influence configuration or persuade a user/agent to adopt an untrusted URL.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

export OPENAI_API_KEY=sk-xxx inkos config set-global --provider openai --base-url https://api.openai.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

For compatible/proxy endpoints, use --provider custom and point ONLY to trusted endpoints:

inkos config set-global --provider custom --base-url https://your-trusted-proxy.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

text

### Multi-Model Routing (Optional)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

A self-update capability can modify the installed tool after initial review, invalidating prior trust assumptions and potentially introducing malicious or vulnerable code through the package/update channel. In an autonomous or semi-autonomous agent setting, any path that permits self-modification expands the attack surface substantially, especially if updates are not pinned, verified, or user-approved.

Content

Scanner excerpt · SKILL.md (reported line 497)May include surrounding context.

md
| `inkos config set-model <agent> <model>` | Set model override for a specific agent | `--provider`, `--base-url`, `--api-key-env` for multi-provider routing |
| `inkos config show-models` | Show current model routing | View per-agent model assignments |
| `inkos doctor` | Diagnose issues | Check installation |
| `inkos update` | Update to latest version | Self-update |
| `inkos up/down` | Daemon mode | Background processing. Logs to `inkos.log` (JSON Lines). `-q` for quiet mode |
| `inkos review list/approve-all` | Manage chapter approvals | Quality gate |
| `inkos fanfic init` | Create fanfic from source material | `--from <file>`, `--mode canon/au/ooc/cp` |

Ssd 3

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill advertises structured JSONL logging, token analytics, and interaction/session artifacts, which strongly suggests retention of user prompts, generated text, and operational metadata in local files. Such plain-language artifacts can expose sensitive manuscript content, imported source text, or credentials accidentally supplied in prompts if local files are later accessed, synced, or committed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

Configure your LLM provider (OpenAI, Anthropic, or any OpenAI-compatible API)

Prefer --api-key-env so the key never appears in shell history:

export OPENAI_API_KEY=sk-xxx inkos config set-global --provider openai --base-url https://api.openai.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

For compatible/proxy endpoints, use --provider custom and point ONLY to trusted endpoints:

inkos config set-global --provider custom --base-url https://your-trusted-proxy.com/v1 --api-key-env OPENAI_API_KEY --model gpt-4o

text

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The interact --json interface explicitly returns routed requests, updated session state, pending decisions, and recent interaction events. If those payloads include prior prompts, chapter text, filenames, or operator instructions, an external agent or downstream consumer can retrieve sensitive history through a natural-language interface without strong minimization boundaries.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 506)May include surrounding context.

md
| `inkos genre copy <id>` | Copy built-in genre to project | For customization |
| `inkos write rewrite <book> <ch>` | Rewrite a specific chapter | Deletes chapter and later, rewrites from that point |
| `inkos book update [book-id]` | Update book settings | `--chapter-words`, `--target-chapters`, `--status`, `--lang` |
| `inkos book delete <book-id>` | Delete book and all chapters | `--force` to skip confirmation |
| `inkos plan chapter [book-id]` | Generate chapter intent | Preview what next chapter will do before writing |
| `inkos compose chapter [book-id]` | Generate runtime artifacts | Context, rule-stack, trace for next chapter |
| `inkos consolidate [book-id]` | Consolidate chapter summaries | Reduces context for long books (volume-level summaries) |

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language description foregrounds English as 'native' support while relegating Chinese to secondary support. This can be read as a language-preference policy baked into the skill description rather than offering neutral language choice up front.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.