Security checks for vulnerabilities and agentic risk
Overview
The skill’s memory-search purpose is coherent, but setup installs mutable global third-party code and indexes local OpenClaw workspace data with limited upfront control.
Review this before installing if you are sensitive to local workspace indexing, background services, or supply-chain risk. Run setup only as a normal user, avoid sudo, confirm you are comfortable with QMD being installed globally and downloading about 2GB of models, and inspect or disable any QMD daemon or scheduled refresh behavior you do not want.
Insecure DependenciesIntroduces malicious components through unsafe dependency sources
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T08 · Insecure Dependencies
Warning
Location
scripts/setup.sh:16
Finding
Unpinned Global npm Dependency Installation
Content
View full analysis
Vulnerability Details
File Location: scripts/setup.sh, lines 16-20 Vulnerability Type: Unpinned third-party package installation with npm lifecycle-script execution Risk Level: Medium
Vulnerable Code
bash
# Check if QMD is installed
if ! command -v qmd &> /dev/null; then
echo "📦 Installing QMD..."
npm install -g @tobilu/qmd
echo "✅ QMD installed"
Technical Analysis
The setup process globally installs @tobilu/qmd without specifying an exact version or verifying package integrity. As a result, npm resolves a mutable package release at installation time rather than a version reviewed alongside this skill.
npm packages may execute lifecycle scripts during installation. If the package, a transitive dependency, or its publishing account is compromised, running this setup script could execute attacker-controlled code with the privileges of the user invoking the skill. The global installation scope also modifies user- or system-level tooling outside the project directory.
This is a supply-chain weakness; the audited repository does not itself contain evidence that the current QMD package is malicious.
Attack Path
An attacker compromises the @tobilu/qmd publication process, its registry account, or a dependency resolved by the package.
The attacker publishes a malicious version that is selected by npm's unpinned resolution.
A user without an existing qmd executable runs the skill's setup command.
npm install -g @tobilu/qmd downloads the mutable release and its dependency tree.
Malicious package code or lifecycle scripts execute with the invoking user's privileges.
The installed program may subsequently access files indexed by the skill, including workspace memory and agent configuration documents.
Impact Assessment
Successful exploitation can provide arbitrary code execution under the account running the setup command. This may
...[truncated 312 chars]
Remediation
View remediation
Remediation Suggestions
Pin QMD to a reviewed exact version, for example:
bash
The README markets the skill as low-cost and easy to use, but it does not clearly warn users that first use auto-downloads roughly 2GB of models and that nightly automatic index updates can modify local state. This can lead users to install and run the skill without informed consent about network activity, disk usage, background processing, and changes to local indexed data, which is a meaningful safety and transparency issue for an agent skill.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The skill explicitly advertises that setup installs QMD, configures collections, and sets up cron jobs, but it does not present these system-modifying actions as clear upfront warnings requiring explicit user awareness or consent. This is dangerous because users may run setup expecting a simple local enhancement while unintentionally altering indexed data sources and persistence behavior on their machine, including scheduled background tasks.
Content
No source excerpt is available for this finding.
Missing User Warnings
Low
Category
Not specified by scanner
Confidence
88% confidence
Finding
The skill notes auto-downloaded models and lists their sizes, but it does not frame this as a clear operational warning before setup, despite a multi-gigabyte download and storage impact. This can surprise users on constrained systems, cause failed installs, or consume significant disk/bandwidth without informed consent.