Back to skill

Security audit

Setup Agent

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for OpenAnt agent setup, but it relies on mutable remote npm execution for authentication and includes optional persistent polling that users should review carefully.

Review before installing. Prefer a version-pinned OpenAnt CLI, avoid running `@latest` for authentication or key management, confirm all registration metadata before submission, and only create scheduled polling if you understand the schedule, target session, persistence duration, and how to remove it.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:5
Finding

Execution of an Unpinned Remote npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 5-27
Vulnerability Type: Supply-chain risk caused by mutable dependency execution
Risk Level: High

Vulnerable Code

yaml
allowed-tools: ["Bash(npx @openant-ai/cli@latest status*)", "Bash(npx @openant-ai/cli@latest login*)", "Bash(npx @openant-ai/cli@latest verify*)", "Bash(npx @openant-ai/cli@latest agents *)", "Bash(npx @openant-ai/cli@latest setup-agent*)", "Bash(npx @openant-ai/cli@latest bind-email*)", "Bash(npx @openant-ai/cli@latest config *)"]
bash
npx @openant-ai/cli@latest status --json
bash
npx @openant-ai/cli@latest login --key --name "MyAgent" --role AGENT --json

Technical Analysis

The Skill consistently invokes @openant-ai/cli through the mutable npm tag latest. The package version and package integrity are not pinned in the Skill, so the code executed at invocation time may differ from the code that existed when the Skill was reviewed.

npx can retrieve and execute a package from the npm registry when the required package version is not already available locally. Consequently, compromise of the publisher account, npm package, distribution pipeline, or a future malicious release could turn otherwise legitimate status, login, registration, or configuration commands into arbitrary local code execution.

The risk is amplified because the CLI is intentionally used to create or reuse cryptographic keys under ~/.openant/keys/, authenticate the Agent, and modify its OpenAnt configuration.

Attack Path

  1. An attacker compromises the npm publisher account, release pipeline, or package associated with @openant-ai/cli.
  2. The attacker publishes a malicious version and assigns it to the latest tag.
  3. A user invokes this Skill for status checking, authentication, or Agent registration.
  4. npx @openant-ai/cli@latest resolves and downloads the attacker-controlled release.
  5. npm executes the packa ...[truncated 1063 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace every use of @latest with a specific, audited package version, for example:
    bash
    npx --yes @openant-ai/cli@X.Y.Z status --json
    
  2. Verify the package tarball against an expected integrity hash before execution.
  3. Manage the CLI through a lockfile and a controlled installation process rather than downloading executable code during each Skill invocation.
  4. Review and approve version upgrades explicitly instead of following a mutable distribution tag.
  5. Run the CLI in a least-privileged environment with narrowly scoped filesystem and network access.
  6. Protect ~/.openant/keys/ with restrictive file permissions and prevent unrelated package lifecycle scripts from accessing it where sandboxing is available.
  7. Consider disabling npm lifecycle scripts during controlled installation when they are not required.

T06 · System Persistence

Warning
Location
SKILL.md:154
Finding

Persistent Cross-Session Agent Activation Through a Scheduled Cron Job

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 154-166
Vulnerability Type: Persistent scheduled task affecting future Agent sessions
Risk Level: Medium

Vulnerable Code

markdown
### Scheduled Polling

Use [OpenClaw cron jobs](https://docs.openclaw.ai/automation/cron-jobs) to periodically check OpenAnt status. **Confirm with the user** the schedule (e.g. `*/30 * * * *`) and the checks to run before creating the task.

```bash
openclaw cron add \
  --name "openant-poll" \
  --cron "*/30 * * * *" \
  --session main \
  --system-event "Check OpenAnt: unread notifications, submitted tasks, approaching deadlines." \
  --wake now
text

### Technical Analysis

The Skill provides instructions to create a recurring OpenClaw cron job that survives the initial Skill run. Every 30 minutes, the job targets the main session, wakes it, and injects a system event directing the Agent to perform OpenAnt-related checks.

The requirement to obtain user confirmation reduces the chance of accidental installation, but it does not eliminate the persistence characteristic. Once installed, the scheduled task continues influencing future sessions without requiring a new invocation of the Skill or a fresh user request for every execution.

Targeting `--session main` increases the scope because the persistent event is delivered to the primary Agent session rather than an isolated polling context. The provided workflow also does not specify an expiration time, execution limit, or removal procedure.

### Attack Path

1. The Skill proposes periodic OpenAnt polling and obtains approval for the schedule and event content.
2. The Agent executes `openclaw cron add` with the main session as its target.
3. OpenClaw stores the recurring job beyond the current Skill invocation.
4. At every scheduled interval, the job wakes the main Agent session.
5. The injected system event prompts the Agent to check notifications, t
...[truncated 945 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer user-initiated or one-time polling instead of creating a persistent schedule.
  2. If scheduled polling is necessary, require explicit informed consent that clearly states:
    • The exact schedule.
    • The event content.
    • The target session.
    • Expected network and resource usage.
    • The persistence duration.
  3. Run polling in a dedicated, least-privileged session rather than --session main.
  4. Configure an expiration time or maximum execution count.
  5. Restrict the event to read-only status collection and require separate confirmation before performing consequential actions.
  6. Provide and verify an explicit command for listing and removing the cron job.
  7. Display the installed job configuration after creation so the user can confirm that it matches the approved parameters.
  8. Avoid incorporating untrusted remote notification content directly into privileged system events or subsequent tool commands.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The manifest whitelists Bash(npx @openant-ai/cli@latest ...), and the skill repeatedly instructs use of npx ...@latest, which fetches whatever version is current at execution time rather than a reviewed immutable build. This creates a supply-chain risk: a compromised upstream package, malicious new release, or breaking change could execute with the skill's granted shell privileges and alter registration, credential, or system behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
99% confidence
Finding

The allowed-tools list includes multiple npx @openant-ai/cli@latest invocations, meaning every approved tool execution may download and run a mutable remote package. Because tool permissions authorize shell execution, a hostile or compromised package release could run arbitrary code under the agent context.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The skill directs the model to use npx @openant-ai/cli@latest status --json, again depending on an unpinned package resolved at runtime. Even a seemingly read-only status command becomes dangerous when the executable itself is mutable and can perform unintended actions before returning output.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The login flow uses npx @openant-ai/cli@latest, which is especially sensitive because it handles authentication and key material. If the fetched package were malicious, it could exfiltrate generated private keys, session tokens, or account metadata during onboarding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The OTP verification path also depends on @latest, so a mutable package is involved in handling a sensitive authentication step. Compromise here could capture email addresses, OTP identifiers, and verification codes or falsely report success/failure.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The one-command setup-agent --key path uses an unpinned runtime package for login, registration, and heartbeat in one step. That amplifies risk because a compromised package can both create credentials and register a potentially attacker-controlled or misrepresented agent identity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This repeated @latest usage is part of the same registration command and inherits the same supply-chain exposure. Because it includes profile fields like capabilities and platform, a malicious version could silently alter agent metadata or submit extra data from the local environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The separate agents register flow is also executed via an unpinned package. Registration commands transmit identity and capability information, so a malicious upstream release could tamper with metadata or harvest local details during the process.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The bind-email command uses a mutable package in a sensitive account-recovery flow. A compromised package could capture the email address, intercept or misuse OTP workflow details, or bind an attacker-controlled address if it alters behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The commands table normalizes use of npx @openant-ai/cli@latest across all supported operations, reinforcing unsafe operational guidance. Because users and downstream skills may copy these examples broadly, the attack surface extends beyond a single command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This register-options section continues the pattern of unpinned invocation for profile management commands. While less sensitive than login, the mutable executable still enables arbitrary behavior and unauthorized data collection during profile updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The agents update-profile guidance relies on the same unpinned package, allowing a changing upstream executable to modify published agent metadata unpredictably. This can degrade integrity even if no credentials are directly handled in that specific step.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The OpenClaw integration section instructs additional registration flows via @latest, tying external platform metadata into an unpinned onboarding executable. This expands supply-chain impact because the fetched package may process and transmit more extensive environment details.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This is another occurrence within the same metadata-collection registration example, and it remains dangerous because a mutable package is entrusted with aggregated environment and identity data. Such combined context increases the value of compromise and the likelihood of stealthy overcollection.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The repeated registration example still invokes an unpinned remote package and therefore presents the same supply-chain risk. Since this section encourages automation, exploitation could be replicated at scale across many agent setups.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This occurrence remains a true issue because it is part of a shell command sequence that users may run verbatim. In automation contexts, unpinned execution allows behavior drift without any skill update, undermining change control and reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The example continues to trust @latest while injecting auto-collected values, making the command especially sensitive to package compromise and parameter manipulation. The contextual combination of local inventory and networked registration makes this more dangerous than a generic example.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This final line of the example is still part of the same vulnerable unpinned execution chain. The presence of --json does not reduce risk because compromise occurs before structured output is produced.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The skill suggests npx skills list, another unpinned runtime fetch from the package ecosystem. Even though this is framed as enumeration, it still executes mutable code that could inspect the environment or install persistence before listing skills.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This duplicate npx skills occurrence carries the same supply-chain hazard. Because the section is about local platform introspection, it is a convenient place for a malicious package to overcollect information under the guise of discovery.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section documents local environment and platform inventory commands (openclaw --version, openclaw models, openclaw skills) that are not reflected in the declared allowed-tools set. The mismatch is dangerous because it encourages broader local enumeration than the manifest suggests, undermining user expectations and making it easier to exfiltrate system and platform metadata during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The auto-collecting metadata example culminates in another npx @openant-ai/cli@latest agents register invocation. This makes the package responsible for handling enumerated model, version, and skill data, increasing confidentiality and integrity risks if the package is compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as one-time setup/onboarding, but it includes creation of recurring OpenClaw cron jobs for ongoing polling. That expands the capability from registration into persistence/automation, creating a broader operational footprint and the possibility of unintended continuous actions or surveillance beyond initial user expectations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The update-profile example again uses @latest, which allows silent changes to profile-update semantics over time. Although lower sensitivity than credential flows, it still grants code execution and can alter externally visible agent identity data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The autonomy guidance says setup-agent --key should execute immediately without confirmation. Because this flow performs authentication, key generation/reuse, registration, and heartbeat, removing confirmation can cause unintended account creation, external service registration, and transmission of local identity/profile data without an explicit user checkpoint.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
## Autonomy

- **setup-agent --key** — Execute immediately without confirmation (fully non-interactive).
- **setup-agent with --email / interactive** — Confirm with user before executing (requires human OTP).
- **Scheduled polling (cron)** — Confirm schedule and content with user before creating.
- Listing agents — Execute immediately.

Static analysis

No suspicious patterns detected.