Back to skill

Security audit

Devlog Skill

Security checks for vulnerabilities and agentic risk

Overview

This journaling skill is coherent, but its setup script automatically installs unpinned third-party software and may alter the user's shell PATH.

Review the setup script before installing. The journaling behavior itself is straightforward, but installation should ideally use pinned, verified versions of pipx and dev-log-cli, and PATH changes should be made only with explicit user consent. Avoid running setup.sh in privileged automation or sensitive environments unless you trust the upstream package source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
setup.sh:9
Finding

Automatic Installation of Unpinned Third-Party Packages

Content
View full analysis
/dev/null then echo "Error: Failed to install pipx automatically." echo "Please install it manually: https://github.com/pypa/pipx#install-pipx" exit 1 fi fi echo "Installing dev-log-cli via pipx..." pipx install dev-log-cli ``` ### Technical Analysis The setup script installs both `pipx` and `dev-log-cli` from external Python package repositories without specifying exact versions, validating package hashes or signatures, or using a reviewed lockfile. Consequently, the code ultimately installed and executed can change independently of the audited skill. Python package installation may execute package build hooks or other installation-time code. The installed `devlog` command also executes package-controlled code whenever users or agents invoke it. If an upstream package, maintainer account, package repository, or dependency is compromised, running this setup script could introduce attacker-controlled code. The command `python3 -m pipx ensurepath --force` may modify persistent shell configuration to add the pipx binary directory to future sessions. This is not independently classified as malicious persistence, but it can increase the continued visibility of an installed, compromised executable. ### Attack Path 1. An attacker compromises the `pipx` or `dev-log-cli` distribution, one of its transitive dependencies, a package maintainer account, or the package delivery infrastructure. 2. The attacker publishes a malicious release under the expected package name. 3. A user runs `setup.sh` while the relevant command is ab ...[truncated 1320 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
A standardized journaling skill for OpenClaw agents to track progress, tasks, and project status using `dev-log-cli`.

## Description
This skill enables agents to maintain a professional developer log. It's designed to capture context, project milestones, and task statuses in a structured SQLite database.

## Requirements
- `dev-log-cli` (installed via `pipx`)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The setup script installs software from remote package sources and modifies PATH automatically, which exceeds a narrowly scoped journaling skill and introduces supply-chain and environment-manipulation risk. If this script is run in a privileged or trusted automation context, a compromised package, typosquatted dependency, or altered user environment could affect the host beyond the skill’s intended function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.