T08 · Insecure Dependencies
- Location
docs/OPENCLAW.md:128- Finding
Unpinned ClawHub CLI Installation and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a text-only product-risk review skill with an optional, disclosed external case lookup that requires user permission.
Before installing, understand that this skill will steer product or feature requests into a skeptical pre-build review and may advise validating or deferring work. Do not use the optional Case Memory lookup with confidential business ideas, customer data, financials, credentials, or unreleased details unless you are comfortable sending a minimal summary to beforeyoubuild.fyi. Maintainers following the publishing docs should pin and verify CLI tooling rather than running mutable npm/npx commands blindly.
docs/OPENCLAW.md:128Unpinned ClawHub CLI Installation and Execution
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
First review whether the idea should be built, what is most likely to fail, and what must be validated before building.
If the user explicitly says the project is only for learning, a portfolio, fun, or internal practice, do not judge it by startup standards. You may still point out scope and clarity risks.
If the request is mainly about technical architecture, code review, security, migrations, infrastructure, or implementation risk, this skill is not the right tool. Use a general cold-shower technical review instead.
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
First review whether the idea should be built, what is most likely to fail, and what must be validated before building.
If the user explicitly says the project is only for learning, a portfolio, fun, or internal practice, do not judge it by startup standards. You may still point out scope and clarity risks.
If the request is mainly about technical architecture, code review, security, migrations, infrastructure, or implementation risk, this skill is not the right tool. Use a general cold-shower technical review instead.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Case Memory endpoint:
POST https://api.beforeyoubuild.fyi/api/v1/case-memory/search
The endpoint is used to retrieve similar public product cases from Before You Build. It is not required for the core skill to work.
The trigger list includes broad natural-language phrases like 'Should I add this feature?' and 'Competitors have X. Should we add it?' that can match ordinary product discussions far beyond the intended narrow use case. Overbroad invocation can cause the wrong skill to activate, steering conversations away from the user's actual goal and potentially suppressing more appropriate safety, technical, or domain-specific guidance.
The default prompt uses a broad natural-language invocation phrase ('before you build') without any visible trigger constraints or namespacing. This can cause accidental or ambiguous activation when users say common phrases, leading to unintended skill routing or prompt injection opportunities through mis-invocation, though the skill’s business-analysis scope limits the severity.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
- No API key is required for normal use.
- Optional Case Memory lookup is documented separately and should only be used after user permission.
A separate OpenClaw-only fork would create duplicate maintenance work and increase the chance that the public instructions drift apart.
## Recommended OpenClaw Install
The documentation recommends executing npx --yes clawhub without pinning a specific package version. This creates a supply-chain risk because users may fetch and run whatever version is current at execution time, including a compromised or maliciously republished package. In a security-sensitive publishing workflow, that can lead to arbitrary code execution on the publisher's machine.
The documentation recommends running npx --yes clawhub without pinning a specific package version. Because npx resolves and executes the latest published package by default, a compromised upstream release or unexpected breaking change could cause users to run unreviewed code on their machine. In this context, the risk is real but limited to users who follow the operational instruction in the docs.
The trigger phrase "before you build" is generic and can plausibly appear in ordinary product or planning conversations, which increases the chance the skill is invoked outside its intended niche. Unintended invocation can cause workflow confusion, irrelevant guidance, or context switching, though this file does not suggest direct code execution, data exfiltration, or privilege abuse.
The skill instructs sending user-derived idea summaries to an external API, which creates a real data exfiltration/privacy risk if the summary contains confidential business information, personal data, or unreleased product details. The file partially mitigates this by requiring explicit user agreement and warning not to send secrets, but remote transmission remains security-relevant because users or downstream agents may still overshare sensitive content.
Endpoint:
POST https://api.beforeyoubuild.fyi/api/v1/case-memory/search
Request fields:
The example request sets "language": "en", which imposes a specific language/locale in the skill instructions. Because the document does not indicate that users may choose another language or explicitly opt into English-only behavior, this appears to violate the language/locale policy.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
### Feature additions and requirement changes
If the user wants to add a feature, change requirements, expand scope, copy a competitor, or pivot an in-progress product, do not treat it as a brand-new product idea.
Give a short Feature Reality Check.
This markdown file includes repeated natural-language notes about submitting the skill to Chinese skill lists and guides. Because the file presents locale-specific targeting without any stated user opt-in or documented justification for language/locale constraints, it may conflict with the policy against forcing a specific language or locale.
No suspicious patterns detected.