T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Untrusted Skill Metadata Can Trigger Unsafe Global Package Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a legitimate dependency-repair purpose, but it can lead agents to install global packages or an unverified binary without enough safeguards.
Review this skill before installing. Use dry-run first, inspect every proposed package, avoid running fixes with elevated privileges, and prefer pinned or verified installation methods over the direct latest-release binary. Install only dependencies declared by skills you trust.
SKILL.md:58Untrusted Skill Metadata Can Trigger Unsafe Global Package Installation
SKILL.md:118Mutable Release Binary Is Downloaded Without Integrity Verification
The trigger phrases include broad, natural-language prompts like "skills are broken" and "openclaw doctor," which can match ordinary troubleshooting requests and cause this skill to activate unexpectedly. Because the skill's purpose is to generate or recommend package installation and repair actions, accidental invocation can lead to unreviewed system-modifying guidance or follow-on actions.
The skill describes scanning and auto-fixing dependencies but does not prominently warn that fixes may install global npm packages, pip packages, Homebrew formulae, or otherwise alter the local environment. Users may treat the skill as diagnostic-only and be surprised by system modifications, especially since the document includes direct installation commands and update guidance.
The invocation list repeats ambiguous triggers without requiring clear user intent or confirmation, increasing the chance that routine support language activates the skill. In this context, unintended activation is more dangerous because the skill is designed around detecting missing packages and optionally fixing them, which normalizes potentially invasive system changes.
No suspicious patterns detected.