Back to skill

Security audit

Isolated Workspace

Security checks for vulnerabilities and agentic risk

Overview

The skill is a normal development-workflow helper, but it overstates isolation and automatically runs dependency/build commands that can execute project-controlled code.

Review this skill carefully before installing. It can create branches, alter and commit .gitignore, and run package-manager or build commands in the current checkout. Use it only in repositories you trust, and prefer changing it to ask before dependency setup and to either create a real separate workspace or stop claiming directory isolation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:82
Finding

Automatic Execution of Unreviewed Dependency and Build Scripts

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 82–90
Vulnerability Type: Automatic installation and execution of repository-controlled dependencies
Risk Level: Medium

Vulnerable Code

bash
# Node.js
if [ -f package.json ]; then npm install; fi

# Python
if [ -f requirements.txt ]; then pip install -r requirements.txt; fi
if [ -f pyproject.toml ]; then pip install -e .; fi

# Rust
if [ -f Cargo.toml ]; then cargo build; fi

# Go
if [ -f go.mod ]; then go mod download; fi

Technical Analysis

The skill instructs the agent to detect dependency manifests and automatically invoke package managers or build systems without first reviewing the dependencies or obtaining explicit user approval.

Several of these operations can execute code controlled by the repository or its dependencies:

  • npm install can run package lifecycle scripts, including preinstall, install, and postinstall.
  • pip install -e . can invoke repository-selected Python build backends and execute package build or installation logic.
  • pip install -r requirements.txt installs packages from sources specified by the repository and does not require hashes or a lockfile.
  • cargo build executes Rust build scripts declared through build.rs.
  • Dependency resolution without an enforced lockfile or integrity policy can retrieve versions that were not reviewed when the skill was audited.

The skill does not require version pinning, integrity verification, script suppression, source allowlisting, sandboxing, or confirmation before these commands execute. Consequently, workspace initialization can become an arbitrary code-execution channel if the skill is invoked in a malicious or compromised repository.

Attack Path

  1. An attacker creates or compromises a repository in which one of the detected manifest files is present.
  2. The attacker adds a malicious package lifecycle script, Python build backend, Rust build script, or dependency reference.
  3. A user ...[truncated 1334 chars]
Remediation
View remediation

Remediation Suggestions

  1. Separate isolated branch creation from dependency installation and make dependency setup an explicit optional phase.
  2. Present the exact command to the user and require confirmation before invoking a package manager or build system.
  3. Prefer deterministic, lockfile-enforced installation:
    • Use npm ci with a reviewed package-lock.json.
    • Require hash-pinned Python requirements, such as pip install --require-hashes -r requirements.txt.
    • Use Cargo and Go lockfiles where applicable and enforce locked resolution.
  4. Disable lifecycle scripts where compatible with the project, such as using npm ci --ignore-scripts, and enable scripts only after review.
  5. Review Python build-system declarations and Rust build.rs files before executing editable installations or builds.
  6. Restrict package sources to approved registries and avoid untrusted direct URLs, Git dependencies, or custom indexes.
  7. Run installation and build commands inside a sandbox or disposable container with minimal filesystem access, no unnecessary credentials, and restricted outbound networking.
  8. Report detected manifests and planned operations without executing them when dependency integrity cannot be established.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises creation of an isolated workspace/directory, but the documented steps only create a new git branch in the current checkout with git checkout -b. That mismatch can cause users or agents to perform feature work in the active working tree, leading to accidental modification of unrelated files, contamination of the current session state, and reduced safety guarantees the skill explicitly promises.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is written entirely in Chinese and prescribes user-facing announcement and status messages in Chinese, but does not state that language choice is optional or configurable. This creates a language/locale policy concern because the skill appears to enforce a specific language for interaction without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The OpenClaw notes claim the workflow uses git branch plus an independent working directory, but no such directory is ever created or entered anywhere in the procedure. This is dangerous because operators may rely on a false safety model and assume edits are isolated when they are actually occurring in the existing checkout, increasing risk of accidental overwrite, dirty state carryover, or leaking in-progress changes into the wrong branch/context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.