Back to skill

Security audit

教育课题申报智能套件

Security checks for vulnerabilities and agentic risk

Overview

This education proposal skill is mostly purpose-aligned, but its core functionality depends on unpinned external packages that were not included for review.

Install only in a least-privileged environment, preferably after pinning and reviewing the two dependency packages. Treat generated proposals, biographies, achievements, and school-support materials as drafts, and verify every factual or institutional claim before using them in an official application.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:27
Finding

Unreviewable Third-Party Runtime Dependencies

Content
View full analysis

Vulnerability Details

File Location: package.json, lines 27–30
Vulnerability Type: Third-party supply-chain exposure through unpinned dependencies
Risk Level: Medium

Vulnerable Code:

json
"dependencies": {
  "provincial-education-project": "^1.0.0",
  "municipal-education-project": "^1.0.0"
}

Technical Analysis

The package delegates its substantive functionality to two external npm dependencies whose source code is not included in the audited project. Consequently, their runtime behavior, transitive dependencies, and installation lifecycle scripts cannot be verified from the supplied artifact.

Both dependencies use caret version ranges. For a 1.x package, a range such as ^1.0.0 permits npm to resolve later compatible minor and patch releases. This means that the code installed in the future may differ from the code originally reviewed. If a dependency publisher account, package release process, or transitive dependency is compromised, an attacker could distribute malicious code under a version accepted by these ranges.

No lockfile or integrity metadata was supplied to constrain dependency resolution to specific reviewed artifacts. No malicious behavior in either dependency is confirmed by the available files; the finding concerns the unresolved supply-chain trust boundary.

Attack Path

  1. An attacker compromises the publishing account, release process, or dependency chain of one of the declared packages.
  2. The attacker publishes a malicious version that remains compatible with the declared caret range.
  3. A user installs or updates this project without a lockfile fixing the previously reviewed dependency versions.
  4. npm resolves and downloads the malicious compatible release.
  5. Malicious dependency code may execute through an npm lifecycle script during installation or when the dependency is loaded by the skill.
  6. The payload operates with the permissions of the user or ...[truncated 745 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin both dependencies to exact, reviewed versions instead of caret ranges.
  2. Commit an npm lockfile and require reproducible installation with npm ci.
  3. Verify lockfile integrity hashes and review all transitive dependencies before release.
  4. Confirm the package names, registry ownership, maintainers, source repositories, and provenance to reduce dependency-confusion and package-takeover risk.
  5. Audit dependency source code and npm lifecycle scripts. Where operationally possible, install with lifecycle scripts disabled.
  6. Use automated dependency and provenance scanning in CI, and block unexpected dependency or integrity changes.
  7. Prefer including and auditing the required implementation in the project itself when the external packages are not independently verifiable.
  8. Run installation and skill execution in a least-privileged, isolated environment without unnecessary credentials, sensitive filesystem mounts, or unrestricted network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly offers end-to-end generation of complete project applications and supporting materials, including personal profiles, participant bios, prior achievements, and school support proof, but does not instruct users to verify facts or prohibit fabricated content. This creates a realistic risk that users will submit false or AI-invented institutional or personal information in official grant applications, leading to fraud, misrepresentation, or compliance violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This skill's title, overview, examples, and operational descriptions are all written in Chinese, and the document does not indicate that users may choose another language or that the locale restriction is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This manifest contains user-facing natural language that assumes Chinese as the only language for the skill description. Under the language/locale policy, forcing a specific language without user opt-in or documented regional justification can be a policy concern.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Using a caret version range allows newer minor/patch releases of the dependency to be installed automatically, which increases supply-chain risk if an upstream package is compromised or introduces malicious code. In a skill package, dependency resolution can change over time, reducing build reproducibility and making it harder to audit exactly what code will run.

Content

Scanner excerpt · package.json (reported line 28)May include surrounding context.

json
"openclaw": ">=2026.4.0"
  },
  "dependencies": {
    "provincial-education-project": "^1.0.0",
    "municipal-education-project": "^1.0.0"
  },
  "scripts": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Using a caret version range allows newer minor/patch releases of the dependency to be installed automatically, which increases supply-chain risk if an upstream package is compromised or introduces malicious code. In a skill package, dependency resolution can change over time, reducing build reproducibility and making it harder to audit exactly what code will run.

Content

Scanner excerpt · package.json (reported line 29)May include surrounding context.

json
},
  "dependencies": {
    "provincial-education-project": "^1.0.0",
    "municipal-education-project": "^1.0.0"
  },
  "scripts": {
    "test": "echo '测试通过'",

Static analysis

No suspicious patterns detected.