Back to skill

Security audit

Overkill Token Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with token optimization, but its install instructions and dependency model ask users to run mutable third-party code with broad local privileges.

Install only after replacing the setup steps with a pinned, verified oktk release or a trusted local installation. Expect the skill to read OpenClaw session memory, create a local index, and run commands through oktk when you use compression; avoid using it on sensitive sessions until the install and disclosure issues are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
FRAMEWORK.md:97
Finding

Unverified Remote Script Downloaded and Executed by a Shell

Content
View full analysis

Vulnerability Details

File Location: FRAMEWORK.md, line 97
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: High

Complete Code Snippet:

bash
# Install oktk CLI
curl -sSL https://get.oktk.io | sh

Technical Analysis

The installation instructions pipe an HTTPS response directly into sh. This makes the effective executable payload dependent on mutable content returned by https://get.oktk.io at installation time. The project does not pin a release, verify a cryptographic checksum or signature, retain the script for inspection, or constrain the commands that the downloaded script may execute.

HTTPS protects the connection when its trust assumptions hold, but it does not establish that the current server-side payload matches the version reviewed with this Skill. Compromise of the domain, hosting environment, DNS or certificate infrastructure, deployment account, or installation script could therefore turn this documented command into arbitrary code execution.

Installing the declared CLI does not require immediately granting an unreviewed network response full shell access. This behavior exceeds the minimum privilege necessary for the Skill's token optimization functionality.

Attack Path

  1. An attacker compromises the installation endpoint or otherwise gains control over the script returned by https://get.oktk.io.
  2. The attacker modifies the response to include malicious shell commands.
  3. A user follows the installation instructions in FRAMEWORK.md.
  4. curl retrieves the modified response and passes it directly to sh.
  5. The shell executes the payload without an opportunity for inspection or integrity validation.
  6. The payload can access resources available to the invoking account and may download additional components, alter user files, or establish persistence.

Impact Assessment

Successful exploitation provides arbitrary command ex ...[truncated 444 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation pipeline.
  2. Direct users to a specific, immutable release from the documented upstream repository.
  3. Pin the expected version and artifact filename.
  4. Publish and verify a cryptographic SHA-256 or stronger checksum before execution.
  5. Prefer signature verification using a documented, independently distributed signing key.
  6. Download the artifact to a local file so users can inspect it before running it.
  7. Avoid requiring administrator privileges and install only within a user-scoped or isolated environment.
  8. Document the files, network access, subprocesses, and permissions required by the installer.
  9. If a script remains necessary, fail closed when integrity verification cannot be completed.

A safer documented flow should resemble:

bash
curl -fL -o oktk-release.tgz \
  https://github.com/satnamra/oktk/releases/download/VERSION/oktk-release.tgz

echo "EXPECTED_SHA256  oktk-release.tgz" | sha256sum --check -

The version and checksum must be replaced with values for a reviewed, immutable release.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Global Installation of a Third-Party CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 10
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Complete Code Snippet:

bash
npm install -g oktk

Technical Analysis

The prerequisite instructions install the current registry-selected version of oktk globally without pinning a reviewed version or verifying package integrity. Consequently, two users following the same audited Skill instructions at different times may install different code.

npm installation can execute package lifecycle scripts, and a global installation places executable content into a shared command location. The resulting oktk binary is subsequently trusted by cli.py to inspect session-related data and execute user-supplied commands through compression. A compromised publisher account, malicious package release, registry compromise, or unexpected future package change could therefore introduce code that was not part of this audit.

No evidence establishes that the current oktk package is malicious. The finding concerns the unsafe, unpinned supply-chain trust model in the documented installation procedure.

Attack Path

  1. An attacker publishes a malicious oktk release after compromising the relevant package publication channel, or a future release is otherwise unsafe.
  2. A user runs npm install -g oktk as instructed.
  3. npm resolves and installs the latest eligible package rather than a specifically reviewed version.
  4. Malicious lifecycle code may execute during installation, or the installed executable may run later when invoked by this Skill.
  5. The dependency inherits the privileges and data access of the invoking user, including access to command arguments, command output, and user-readable workspace files.

Impact Assessment

Exploitation could result in arbitrary user-level code execution during installation or later CLI invocation. The dependency m ...[truncated 406 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin oktk to an explicitly reviewed version, such as oktk@X.Y.Z.
  2. Record and verify package integrity through an npm lockfile or another reproducible dependency mechanism.
  3. Prefer a project-local installation instead of -g, reducing the dependency's scope and avoiding modification of shared executable locations.
  4. Review the selected package version, including its lifecycle scripts and transitive dependencies.
  5. Use an isolated environment or container with only the filesystem and network access required for compression.
  6. Disable lifecycle scripts during installation where compatible with the package, then explicitly run only reviewed setup steps.
  7. Establish a controlled upgrade process so dependency updates undergo review before the pinned version changes.
  8. Keep the repository URL, npm package identity, expected publisher, and verified version consistent in all documentation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
99% confidence
Finding

The command fetches an external script from https://get.oktk.io and passes it directly to sh, creating a direct remote code execution path. In a skill/framework document, this is more dangerous because it is presented as a normal setup step that users may copy-paste without inspection, increasing the likelihood of compromise.

Content

Scanner excerpt · FRAMEWORK.md (reported line 97)May include surrounding context.

bash
# Install oktk CLI
curl -sSL https://get.oktk.io | sh

2. Configure Compression

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The shell pipe operator is used to chain downloaded content directly into sh, which removes the user's opportunity to inspect or validate the script before execution. This pattern materially increases exploitability because any malicious or unexpected response body becomes shell commands executed immediately.

Content

Scanner excerpt · FRAMEWORK.md (reported line 97)May include surrounding context.

bash
# Install oktk CLI
curl -sSL https://get.oktk.io | sh

2. Configure Compression

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The framework instructs users to install a CLI by piping a network response directly into a shell, which executes unverified remote code immediately. This is dangerous because any compromise of the hosting domain, transport path, or installer script can lead to arbitrary code execution on the user's system with the user's privileges.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring and CLI help describe this command as performing a reset, especially under --confirm. However, in the branch where the external oktk binary is unavailable, the code merely reads session files and prints summary statistics, leaving the sessions unchanged. This is an active contradiction between documented intent and implemented behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The search and indexing flow loads session metadata and reads full session file contents, and the index command writes session information to a persistent JSON file. While the code prints status messages, it does not clearly warn users that potentially sensitive session data may be scanned and stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This command is clearly intended to run another command, and it prints the command being run, but it does not warn that arbitrary subprocess execution will occur. Users may not realize that invoking this CLI path will execute the supplied command directly under the current user's privileges.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.