Back to skill

Security audit

Pipeworx dictionary

Security checks for vulnerabilities and agentic risk

Overview

This dictionary skill is purpose-aligned, but its MCP setup automatically runs an unpinned npm package that can change after review.

Review before installing. Ordinary word lookups fit the skill's purpose, but do not submit secrets, internal project names, or sensitive text. Prefer a version-pinned MCP setup for `mcp-remote` or run it in a constrained environment before trusting this configuration.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:44
Finding

Automatic Execution of an Unpinned npm Dependency

Content
View full analysis
Remediation
View remediation
`. 2. Record the dependency in a package manifest and lockfile rather than resolving it dynamically through an unpinned `npx` command. 3. Verify package integrity using the package manager's lockfile integrity metadata or an independently validated checksum. 4. Remove `-y` where practical so that unexpected downloads or package changes require explicit approval. 5. Review the selected package version, including its executable entry point and npm lifecycle scripts, before deployment. 6. Monitor advisories and publisher changes for the pinned dependency, then upgrade only after reviewing and testing each new version. 7. Run the MCP process with least privilege in an isolated environment, exposing only the files, environment variables, and network destinations necessary for dictionary operations. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill depends on external network access and its examples/configuration direct requests to a remote MCP endpoint, meaning user inputs are transmitted off-host. In this context that behavior is expected for a dictionary lookup skill, but it still carries data exposure risk if users submit confidential terms or if operators assume the skill is purely local.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
openclaw:
    requires:
      bins:
        - curl
    emoji: "📝"
    homepage: https://pipeworx.io/packs/dictionary
---

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill clearly sends user-supplied words to a third-party dictionary service, but the description does not warn users that their queries leave the local environment. This creates a privacy/transparency issue because seemingly sensitive terms, project names, or internal jargon entered by users may be disclosed externally without explicit notice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.