Back to skill

Security audit

Oosmetrics

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed oosmetrics MCP integration that needs an API key and runs a pinned npm package, with no artifact evidence of hidden persistence, exfiltration, or destructive behavior.

Install this only if you are comfortable trusting the published @oosmetrics/mcp npm package with your oosmetrics API key. Use a dedicated, revocable key and normal sandboxing or environment isolation if your agent environment contains unrelated sensitive files or variables.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Automatic Execution of an Unverified Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–12; automatic startup is additionally documented at line 27
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: Medium

Complete Code Snippet

yaml
metadata:
  openclaw:
    requires:
      bins: ["npx"]
      env: ["OOSMETRICS_API_KEY"]
    primaryEnv: "OOSMETRICS_API_KEY"
    install:
      npm: "@oosmetrics/mcp@1.0.1"

The automatic execution behavior is documented separately:

text
The MCP server is installed via `npx @oosmetrics/mcp@1.0.1` and starts automatically when this skill is loaded.

Technical Analysis

Loading this Skill causes npx to retrieve and execute the external package @oosmetrics/mcp@1.0.1. The executable source is not included in the audited project, and the project contains no package lockfile, package integrity hash, vendored source, or other mechanism through which the executed npm artifact can be verified against reviewed code.

Pinning the dependency to version 1.0.1 and identifying a public source repository reduce accidental version drift, but they do not independently prove that the npm artifact is identical to that repository's source. The child process also receives access to OOSMETRICS_API_KEY as a required environment variable.

This finding does not establish that the named package is malicious. It establishes that the Skill automatically executes an external, unreviewed supply-chain component with access to a credential and the permissions available to the agent process.

Attack Path

  1. An attacker compromises the package publication account, npm artifact, distribution path, or another relevant supply-chain component.
  2. The user loads the Skill.
  3. The Skill invokes npx to retrieve and execute @oosmetrics/mcp@1.0.1.
  4. The compromised package executes with the local permissions and environment inherited by the MCP process.
  5. The packag ...[truncated 910 chars]
Remediation
View remediation

Remediation Suggestions

  1. Vendor the exact MCP server source or package artifact into a controlled internal repository and perform a source review before deployment.
  2. Verify that the npm artifact corresponds to the referenced source repository and release tag.
  3. Use a lockfile and a verified cryptographic integrity hash rather than relying only on a version string.
  4. Avoid automatic npx download-and-execute behavior when the Skill is loaded. Install the reviewed artifact through a controlled deployment process.
  5. Run the MCP server in a restricted sandbox with read-only filesystem access where possible, no access to unrelated environment variables, and minimal operating-system permissions.
  6. Restrict outbound traffic to the documented API endpoint and deny arbitrary network destinations.
  7. Provide OOSMETRICS_API_KEY only to the isolated MCP process, ensure that it has the minimum available scope, and support prompt rotation and revocation.
  8. Continuously scan and monitor the package, its transitive dependencies, publisher ownership, and release provenance for supply-chain changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.