T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party Packages Can Introduce Mutable Supply-Chain Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for configuring a WeCom/OpenClaw bot, but it handles bot credentials and broad access defaults in ways users should review carefully before installing.
Install only if you are comfortable reviewing the package source and plugin version yourself. Prefer pinned package and plugin versions, avoid passing the Secret on the command line, enter credentials only in a private terminal, restrict the OpenClaw config file to owner-only permissions, and change dmPolicy to pairing or allowlist for any shared or production bot.
SKILL.md:24Unpinned Third-Party Packages Can Introduce Mutable Supply-Chain Code
scripts/setup_wecom.py:76Bot Secret Can Be Exposed Through Command-Line Arguments
scripts/setup_wecom.py:37Interactive Secret Entry Is Displayed in the Terminal
scripts/setup_wecom.py:24Plaintext Bot Secret Is Written Without Enforcing Restrictive File Permissions
scripts/setup_wecom.py:28Direct Messaging Is Insecurely Configured as Open by Default
This markdown file presents all user-facing instructions exclusively in Chinese, including setup, troubleshooting, and safety guidance. Under the policy for natural-language violations, forcing a specific language without giving the user a choice or documenting a justified locale constraint can be a policy issue.
The skill instructs users to run npx clawhub@latest install wecom-ai-bot-setup, which fetches and executes the latest package version at runtime without pinning it. This creates a supply-chain risk: if the package or one of its delivery paths is compromised, users may execute unexpected code during installation.
The script stores the provided WeCom secret directly in a user configuration file on disk with no warning, no permission hardening, and no use of a safer secret store. If that file is readable by other local users, backed up insecurely, or later exposed through logs/support bundles, the bot credential could be stolen and abused.
The example values and instructions are written in Chinese ('你的 Bot ID', '你的 Secret', '保持现有模型配置'), which imposes a specific language in user-facing configuration guidance. There is no indication that Chinese is optional, selectable, or required for a region-specific use case.
User-facing strings, prompts, help text, and docstrings are all presented in Chinese, which can impose a fixed language on users without indicating that language is configurable. The policy calls for flagging language/locale constraints when the skill forces a specific language without user opt-in.
No suspicious patterns detected.