Back to skill

Security audit

Windows Local Embedding

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for setting up local Windows embeddings, but it asks users to install unpinned native npm code into OpenClaw and download an unverified model file.

Install only if you are comfortable manually changing OpenClaw's installed files and using third-party native code. Prefer a pinned `node-llama-cpp` version, review npm warnings instead of ignoring them, download the model from a trusted pinned revision, and verify a full SHA-256 hash before configuring OpenClaw to load it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:61
Finding

Unpinned npm Dependency Installed into the OpenClaw Application Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:61-68; duplicated in references/windows-setup.md:42-53
Vulnerability Type: Unpinned executable dependency and unsafe supply-chain installation
Risk Level: Medium

Vulnerable Code

SKILL.md:61-68:

powershell
cd "D:\Program Files\OpenClaw\resources\openclaw"
npm install node-llama-cpp

The surrounding instructions state that the installation downloads precompiled binaries and that warnings and vulnerability notices may be ignored.

The same installation procedure appears in references/windows-setup.md:42-53:

powershell
cd "D:\Program Files\OpenClaw\resources\openclaw"
npm install node-llama-cpp

Technical Analysis

The installation command does not specify an exact package version, lockfile, integrity digest, or verified package provenance. Consequently, npm resolves the dependency version available from the configured registry at installation time. The installed code may therefore differ from the code that existed when this Skill was reviewed.

npm packages can contain lifecycle scripts and native binaries that execute or load code on the user's system. Installing the package directly inside the OpenClaw application directory also permits dependency files to modify or influence the application's runtime environment. Advising users to ignore vulnerability warnings further reduces the likelihood that compromised or vulnerable transitive dependencies will be investigated.

Attack Path

  1. An attacker compromises the node-llama-cpp package, one of its transitive dependencies, its distribution account, or the registry used by the victim.
  2. The attacker publishes a malicious version or replaces a downloaded native artifact.
  3. A user follows the Skill and runs the unpinned npm install node-llama-cpp command.
  4. npm resolves the attacker-controlled release and downloads its package content and dependencies.
  5. Malicious li ...[truncated 935 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin node-llama-cpp to an exact, reviewed version rather than relying on the latest registry-selected release.
  2. Distribute a reviewed lockfile and use npm ci so direct and transitive dependency versions are reproducible.
  3. Verify package provenance, registry identity, signatures where supported, and expected integrity hashes before installation.
  4. Review package lifecycle scripts and native-binary download behavior before recommending the dependency.
  5. Do not instruct users to ignore vulnerability warnings. Document how warnings should be reviewed and define which findings, if any, are accepted with justification.
  6. Prefer an officially supported plugin or extension directory rather than modifying the packaged application directory.
  7. Perform installation with the least-privileged account capable of completing the task, and avoid an elevated shell unless strictly required.
  8. Consider disabling lifecycle scripts during initial acquisition with --ignore-scripts, inspecting the package, and only enabling required build steps after verification.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:43
Finding

Embedding Model Download Uses a Mutable Revision Without Cryptographic Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:43-55; duplicated in references/windows-setup.md:8-24
Vulnerability Type: Unverified third-party model artifact
Risk Level: Medium

Vulnerable Code

SKILL.md:43-55 directs users to download an artifact through a mutable main revision and verifies only its file signature:

text
https://huggingface.co/nomic-ai/nomic-embed-text-v1.5-GGUF/resolve/main/nomic-embed-text-v1.5.Q8_0.gguf
powershell
$fs = [System.IO.File]::OpenRead("你的文件路径\nomic-embed-text-v1.5.Q8_0.gguf")
$buf = New-Object byte[] 4
$fs.Read($buf, 0, 4) | Out-Null
$fs.Close()
[System.Text.Encoding]::ASCII.GetString($buf)  # 应该输出 GGUF

The same URL and four-byte validation procedure appear in references/windows-setup.md:8-24.

Technical Analysis

The URL resolves the artifact from the repository's mutable main reference. The content served by this URL can change after the Skill has been audited without requiring any modification to the Skill itself.

The documented validation reads only the first four bytes and confirms that they contain the GGUF magic value. This determines whether the file superficially resembles a GGUF file, but it does not authenticate the publisher or verify the integrity of the remaining content. An attacker can trivially preserve or reproduce the four-byte header in a modified artifact.

Because GGUF content is subsequently processed by model-loading and native inference components, an attacker-controlled artifact could at minimum alter embedding behavior or cause denial of service. If the relevant parser contains a memory-safety vulnerability, a crafted model could potentially trigger code execution in the context of OpenClaw. Such parser exploitation is conditional; no specific parser vulnerability was identified in the audited files.

Attack Path

  1. An attacker compromises the upstream model repository, publisher account, distribution ...[truncated 1167 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable main URL with a URL pinned to a reviewed, immutable Hugging Face commit revision.

  2. Publish the expected SHA-256 digest alongside the instructions.

  3. Require users to verify the complete artifact before configuring OpenClaw, for example:

    powershell
    $expected = "REVIEWED_SHA256_VALUE"
    $actual = (Get-FileHash -Algorithm SHA256 "D:\path\nomic-embed-text-v1.5.Q8_0.gguf").Hash
    if ($actual -ne $expected) {
        throw "Model integrity verification failed."
    }
    
  4. Treat file size and the GGUF magic value only as supplementary format checks, not as security controls.

  5. Document the trusted publisher and source, and instruct users to reject downloads obtained through redirects or mirrors that do not match the approved source and digest.

  6. Update the pinned revision and digest only after reviewing the replacement artifact and recording the reason for the update.

  7. Keep the GGUF parser and native inference dependency patched to reduce exposure to malicious model-file parsing vulnerabilities.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill file presents its operational description in Chinese only, which effectively forces a specific language for users reading activation and usage guidance. The policy allows fixed language only when users are given a choice or the locale restriction is clearly documented and justified; that is not stated here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.