T08 · Insecure Dependencies
Error
- Location
SKILL.md:42- Finding
Unpinned npm Package Is Automatically Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This climate skill is purpose-aligned, but its setup asks users to run a mutable npm package automatically, which deserves review before installation.
Review the MCP setup before installing. Prefer pinning mcp-remote to a reviewed exact version or using a locked dependency, and run the MCP server in an environment that exposes only the files and credentials needed for climate queries.
SKILL.md:42Unpinned npm Package Is Automatically Downloaded and Executed
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
openclaw:
requires:
bins:
- curl
emoji: "🌍"
homepage: https://pipeworx.io/packs/climate
---
No suspicious patterns detected.