T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Direct Retrieval and Execution of Cloud-Supplied Workflows
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent cloud workflow cache, but it automatically sends browser/session workflow data to a cloud service and runs cloud-returned workflows with insufficient consent and verification controls.
Review this carefully before installing. Use it only for workflows where sending intent, URL, session identifiers, and sanitized automation traces to the configured cloud service is acceptable. Disable auto_contribute for private accounts, internal tools, regulated data, or confidential business workflows unless you have verified the endpoint, retention policy, and workflow validation controls.
SKILL.md:43Direct Retrieval and Execution of Cloud-Supplied Workflows
skill.json:10Automatic Contribution of Session-Derived Workflows Is Enabled by Default
SKILL.md:86Installation Documentation Executes an Unpinned External CLI Package
The declared description focuses on workflow/result caching and token cost reduction across agents. The supplied code instead defines an intent parsing interface and function for converting raw language plus URL context into structured intent fields. There is no indication of cloud caching, shared agent benefits, token savings, or inference cost reduction. This is a materially different primary purpose, so it should be flagged as a mismatch.
The description centers on cloud caching, shared agent workflows, and token-cost reduction. The supplied code instead provides lightweight heuristic parsing of user intent and browser URL context. It lowercases and cleans text, identifies an action verb from a fixed set, builds an object noun from following words, and extracts the URL hostname. There is no caching layer, no cloud interaction, no workflow persistence/reuse, and no mechanism by which one agent's exploration benefits others. This is a clear description-behavior mismatch with a materially different primary purpose.
The declared description emphasizes cloud caching and token-cost savings for multi-agent workflow reuse. The supplied code instead defines a sanitizer focused on privacy protection: removing identifiable information from traces and action arguments before external transmission. This is a materially different primary purpose and introduces undeclared privacy/sanitization capabilities unrelated to the stated caching/cost-optimization behavior.
The declared description focuses on cloud caching and token cost reduction across agents. The actual code does not implement caching, workflow reuse, inference optimization, or any cloud-related behavior. Instead, it performs privacy-focused sanitization of emails, phone numbers, card numbers, SSNs, passwords, API keys, IP addresses, and sensitive argument fields. This is a materially different primary purpose, so the description does not accurately represent the code chunk.
Based on the supplied code chunk, there is no functional behavior matching the declared purpose. The file is effectively just a compiled module stub for SDK types and contains no operational logic at all. That is a material mismatch because the description advertises a concrete cost-saving caching/workflow capability, while the actual code shown does not implement or evidence any such functionality.
The skill automatically uploads compiled session traces as reusable workflows after successful sessions, without any explicit user approval or warning. In this skill context, traces represent real browser automation steps and may encode sensitive navigation paths, selectors, entered values, or business logic, so automatic cloud contribution materially increases the risk of data leakage and unintended sharing.
The lockfile pins undici to version 7.24.4, and the supplied finding indicates this version is affected by multiple known high-severity advisories, including response queue poisoning, information disclosure, and response desynchronization issues. Because undici is an HTTP client library and this skill advertises cloud-cached workflows, any vulnerable networking component increases the risk of cross-request data leakage, request/response confusion, or service instability when communicating with remote systems.
The dependency resolution indicates a known vulnerable version of undici with multiple published advisories, including response queue poisoning, information disclosure, and response desynchronization issues. Because this skill appears to rely on cloud/networked workflow caching, a vulnerable HTTP client is especially relevant and could affect confidentiality, integrity, or availability of agent traffic.
The manifest requests session history and network permissions and describes a cloud-cached, crowdsourced workflow feature, yet it provides no prominent warning that workflow data may be sent off-device. This is especially risky because auto_contribute is enabled by default, making silent exfiltration of potentially sensitive session content plausible even if the primary intent is cost optimization rather than overtly malicious behavior.
The README explicitly states that the skill will query a cloud service before exploration and contribute successful session traces afterward, but it does not warn users that session-derived data may be transmitted off-device. Even with a claimed 'PII Sanitizer,' the absence of clear disclosure, scope of data collection, retention details, and opt-in/opt-out behavior creates a real privacy and data-governance risk, especially because traces may contain sensitive prompts, outputs, or workflow context.
Enabling auto_contribute by default means successful workflows may be shared to a cloud service without an explicit, prominent opt-in warning. In a skill that handles browser automation and traces, this creates a realistic risk of unintended disclosure of sensitive operational details, metadata, or insufficiently sanitized user data.
The installation instructions invoke npx clawhub without pinning an exact package version, which can cause users to execute whatever version is currently resolved from the registry. This increases supply-chain risk because a compromised or newly published package version could run arbitrary code during install or execution.
The match() method sends the full request payload to a remote cloud endpoint, and this file contains no evidence of user notice, consent gating, or payload minimization before transmission. In an agent skill whose purpose is cloud-cached workflow sharing, this increases the risk that prompts, tool inputs, secrets, or other sensitive workflow data are exfiltrated to a third party without users fully realizing it.
The contribute() method posts data to a remote service to populate shared cloud cache state, which can expose user or workflow content outside the local environment. Because this skill advertises that one agent's exploration benefits all agents, the context makes external sharing more sensitive: submitted data may be retained, reused, or surfaced in ways users do not expect.
The reportFailure() method transmits failure details to a cloud endpoint without visible disclosure controls in this code. Failure reports often contain error context, request fragments, stack traces, or identifiers, so even telemetry-style reporting can leak sensitive operational data if sent automatically.
The interceptor description states that every intent is queried against a cloud service and that successful session traces are contributed back to the cloud, but it provides no indication of consent, minimization, or redaction. In an agent context, intents and traces can contain credentials, secrets, internal URLs, business data, or personal information, so silent transmission creates a meaningful data-exfiltration and privacy risk.
The match request transmits user intent, URL, DOM-derived fingerprinting data, and node identity to a remote service with no user-facing warning at the point of collection. This is dangerous because the skill operates on live browsing sessions, so even metadata alone can expose private accounts, internal sites, and user behavior patterns to an external party.
The code automatically compiles successful session actions into a workflow and uploads it to a cloud service along with the user's intent, current URL, DOM hash, and session ID. In an agent/browser-automation context, session traces can contain sensitive behavioral data, internal app structure, and potentially secrets or PII derived from actions, so omitting this from the skill's description is materially misleading and creates a real privacy and data-exfiltration risk.
The code constructs reusable openclaw.invoke commands from session trace data, which can encode browser navigation, clicks, typing, and evaluation actions. Although the file has a high-level docstring, it does not warn users that recorded interactive actions will be turned into replayable workflow steps, which is a safety-relevant transformation affecting user/system behavior.
The manifest registers global hooks for both intent reception and session completion while also requesting browser, network, and session history access, but it does not define any trigger limits, exclusions, or user-consent boundaries. In this context, broad interception is dangerous because the skill appears designed to observe and reuse workflows across sessions, which can capture and transmit sensitive prompts, browsing activity, or task results to a cloud service by default.
The manifest describes a cloud cache that lets agents reuse prior work to reduce inference cost. While match and contribute align with that purpose, reportFailure introduces an additional telemetry/reporting behavior that is not mentioned in the description. This is a mild description-behavior mismatch because operational failure reporting is adjacent to, but broader than, simple cache reuse.
The failure-reporting behavior indicates data may be sent to the cloud for circuit-breaker tracking, but it does not specify what session details are included or whether sensitive failure context is scrubbed. Failure paths often contain especially sensitive material such as error payloads, tokens, stack traces, or attempted credentials, so undisclosed reporting increases privacy and leakage risk.
Every intercepted intent is sent to the cloud with normalized intent text, current URL, DOM skeleton hash, and node ID to look up a cached workflow, but this behavior is not clearly disclosed by the skill description. In a browser agent, intents and URLs can reveal credentials targets, internal systems, or sensitive business activity, making undisclosed transmission a meaningful security and privacy concern.
On workflow execution failure, the skill reports macro identifiers, node ID, and error details back to the cloud without any visible disclosure. Error strings often contain page state, selectors, internal URLs, or other sensitive context, so undisclosed failure telemetry can leak operational or private information beyond what users would reasonably expect from a cost-saving cache feature.
The runtime dependency uses a caret range, which allows automatic installation of newer minor and patch versions that have not been explicitly reviewed. In a security-sensitive agent skill, this weakens supply-chain control and can unexpectedly pull in vulnerable or behavior-changing releases.
"start": "node dist/index.js"
},
"dependencies": {
"undici": "^7.2.0"
},
"devDependencies": {
"typescript": "^5.7.0",
No suspicious patterns detected.