Back to skill

Security audit

Hefestoai Auditor

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local static-analysis skill, but its behavior ultimately depends on an unpinned external pip package.

Install only if you trust the hefesto-ai package publisher and your Python package index. Prefer running it in a sandbox or virtual environment, limit analysis to intended project directories, and be cautious with repositories containing secrets until the package version and provenance are pinned or independently reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Python Package Executes Unverified Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:17-20 and SKILL.md:39
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

yaml
"package": "hefesto-ai",
"bins": ["hefesto"],
"label": "Install HefestoAI (pip)"
bash
pip install hefesto-ai

Technical Analysis

The Skill installs hefesto-ai without pinning an exact version or verifying package integrity with a cryptographic hash. Consequently, installation resolves to whichever package version the configured Python package index currently supplies.

The downloaded package provides the hefesto executable and therefore controls the Skill's effective runtime behavior. This project contains only SKILL.md; it does not include the executable implementation needed to independently verify the claims that analysis is local, read-only, and free of network activity.

This is a supply-chain weakness rather than evidence that the currently published package is malicious. Exploitation would require compromise or malicious replacement of the package, one of its transitive dependencies, or the package source used by the environment.

Attack Path

  1. An attacker compromises the hefesto-ai publishing account, a transitive dependency, or a configured Python package index.
  2. The attacker publishes a malicious release under the package name expected by the Skill.
  3. OpenClaw or a user follows the installation metadata or documented command and runs pip install hefesto-ai.
  4. Because no exact version or integrity hash is required, pip retrieves the attacker-controlled release.
  5. Malicious code can execute during installation or when the supplied hefesto command is invoked.
  6. The code then operates with the installing user's privileges and can access source files supplied for analysis and other resources available to that account.

Impact Assessment

Successful exploitation could p ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin hefesto-ai to a specific, reviewed version in both the OpenClaw installation metadata and installation documentation.
  2. Distribute a lock file or requirements file containing cryptographic hashes, and install it with pip's --require-hashes option.
  3. Pin and hash all transitive dependencies, not only the direct package.
  4. Document and enforce a trusted package index rather than relying on arbitrary environment-level pip configuration.
  5. Link or vendor the auditable source corresponding exactly to the pinned release so that the privacy and read-only claims can be verified.
  6. Run the analyzer in a sandbox with read-only project mounts, restricted filesystem permissions, no unnecessary credentials, and network access disabled.
  7. Add release provenance or package-signature verification where supported, and update pinned versions only after security review.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
**Privacy:** All analysis runs locally. No code is transmitted to external services. No network calls are made during analysis.

**Permissions:** This tool reads source files in the specified directory (read-only). It does not modify your code.

---

Static analysis

No suspicious patterns detected.