other
- Location
install.sh:20- Finding
Undisclosed Installation Telemetry
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill advertises prompt-cache cost estimates, but its installer makes under-disclosed persistent shell changes and sends silent install telemetry while the declared executable is missing.
Review this before installing. The core prompt-cache idea is plausible, but the package is incomplete and the installer changes your shell profile and contacts Signal Loom during setup without clear consent. Prefer a version that includes the declared executable, documents all network activity, and asks before editing shell startup files.
install.sh:20Undisclosed Installation Telemetry
install.sh:17Unnecessary Persistent Shell-Profile Modification
package.json:5Package Declares a Missing Executable
The skill's stated purpose is prompt cache cost estimation, but the detected behavior includes local installation, filesystem and shell profile modification, and outbound telemetry to an external endpoint. This mismatch is dangerous because users invoking an apparently simple analytical skill would not reasonably expect persistence changes or data egress, increasing the risk of stealthy system modification and leakage of prompts, keys, or usage data.
The skill declares no explicit tool scope or allowed-tools despite requiring a binary and exhibiting shell-capable behavior. In a skill that appears to perform only cost estimation, undisclosed shell access expands the attack surface and can enable unintended command execution or environment changes without clear user consent.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
LOCAL_BIN="${HOME}/.local/bin"
echo "Installing ${SKILL_NAME}..."
mkdir -p "$OPENCLAW_SKILLS" "$LOCAL_BIN"
# Symlink into OpenClaw skills dir
ln -sf "$SCRIPT_DIR" "$OPENCLAW_SKILLS/${SKILL_NAME}"
The installer appends to the user's ~/.zshrc without prompting, which is a persistent environment change that affects future shell sessions. Unannounced startup-file modification can break user environments, create hard-to-trace behavior, and violates the principle of least surprise.
The installer makes an outbound analytics POST during installation that is not necessary for the advertised prompt-cost estimation functionality. Silent network transmission during install creates an avoidable privacy and trust risk, especially because users are not given an explicit opt-in before data is sent.
The installer sends telemetry without explicit disclosure or consent beyond a comment in the script, which most users will never inspect. In an installer context, undisclosed external communication is especially sensitive because users expect setup steps, not silent reporting.
The hardcoded external endpoint indicates the installer depends on or communicates with a remote analytics service unrelated to core installation. In the context of a local skill installer, hidden remote contact increases privacy risk and expands the attack surface if the endpoint behavior changes later.
grep -q '~/.local/bin' "${HOME}/.zshrc" 2>/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> "${HOME}/.zshrc"
# Fire install ping (no auth needed — tracks community installs)
curl -s -m 5 -X POST "https://api.signalloomai.com/v1/analytics/install" \
-H "Content-Type: application/json" \
-d "{\"skill\":\"${SKILL_SLUG}\",\"version\":\"${VERSION}\",\"source\":\"clawhub\"}" &
The hardcoded external endpoint indicates the installer depends on or communicates with a remote analytics service unrelated to core installation. In the context of a local skill installer, hidden remote contact increases privacy risk and expands the attack surface if the endpoint behavior changes later.
grep -q '~/.local/bin' "${HOME}/.zshrc" 2>/dev/null || echo 'export PATH="$HOME/.local/bin:$PATH"' >> "${HOME}/.zshrc"
# Fire install ping (no auth needed — tracks community installs)
curl -s -m 5 -X POST "https://api.signalloomai.com/v1/analytics/install" \
-H "Content-Type: application/json" \
-d "{\"skill\":\"${SKILL_SLUG}\",\"version\":\"${VERSION}\",\"source\":\"clawhub\"}" &
The comment downplays the behavior as a harmless install ping, but the script silently performs a background network request. This mismatch between explanation and actual behavior is risky because it reduces user awareness and impairs informed consent about external communications.
The manifest description says only "Estimate prompt caching savings. Signal Loom AI.", which describes a broad capability but does not specify trigger phrases, scope boundaries, or when the skill should or should not activate. In a manifest file, this lack of specificity can contribute to ambiguous invocation behavior if the description is used for discovery or routing.
No suspicious patterns detected.