T08 · Insecure Dependencies
- Location
scripts/install_weixin_connection.sh:57- Finding
Unpinned Third-Party Plugin Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is broadly coherent for an admin Weixin setup workflow, but it performs high-impact local actions with confirmed implementation risks.
Install only on a controlled admin host, review the Weixin plugin version before use, and expect the workflow to write QR/login artifacts, change OpenClaw plugin state, and restart the gateway after successful pairing. Avoid using it on shared systems until file permissions, PID validation, and the restart scheduler are hardened.
scripts/install_weixin_connection.sh:57Unpinned Third-Party Plugin Installation
scripts/schedule_gateway_restart.sh:16Shell Command Injection Through OPENCLAW_STATE_DIR
scripts/refresh_weixin_qr.sh:15Sensitive QR and Login Artifacts Created Without Enforced Permissions
scripts/refresh_weixin_qr.sh:54Unverified PID Files Can Terminate Unrelated Processes
The skill claims to avoid hard restarts in-chat, but the implementation reportedly schedules and performs gateway restarts, manages PID/log files, and runs delayed background tasks. Hidden service-control behavior is security-relevant because it can disrupt availability, create persistence-like background activity, and exceed the principle of least surprise for a chat-triggered admin skill.
The skill claims to avoid hard restarts in-chat, but the implementation reportedly schedules and performs gateway restarts, manages PID/log files, and runs delayed background tasks. Hidden service-control behavior is security-relevant because it can disrupt availability, create persistence-like background activity, and exceed the principle of least surprise for a chat-triggered admin skill.
The skill schedules a gateway restart as a side effect of successful login, but that service-management capability is not disclosed in the skill description. Hidden restart behavior can disrupt unrelated sessions or services and broadens the skill's authority beyond QR/login handling.
After detecting login success, the script automatically triggers a gateway restart, creating an undocumented operational side effect. In an agent skill, undisclosed service restarts are dangerous because they can cause denial of service, interrupt other automations, and bypass user expectations about the skill's scope.
The documentation states that after WeChat connection succeeds, the skill will asynchronously execute a Gateway restart, but it does not clearly warn the administrator in the user-facing flow that a background restart will occur. This can cause unexpected service interruption, break active sessions, or disrupt the current messaging path if operators do not anticipate the restart timing.
The skill instructs the agent to execute local scripts and handle QR/image/text artifacts, but it does not declare an explicit tool scope such as allowed-tools or permissions. That ambiguity increases the risk that an agent/runtime grants broader file read/write access than intended, especially since the workflow references reading generated files and emitting local media paths.
The skill description, allowed intents, required user-facing replies, and reply style are all specified in Chinese, and the trigger examples are also Chinese-only. This imposes a language constraint on usage and responses without any opt-in, fallback, or documented justification that the skill is intentionally region- or language-specific.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
This shell script kills a running process, including with SIGKILL, and then deletes state files, but it provides no confirmation prompt, warning message, or explanatory comments before doing so. Under the code-file criteria, destructive or irreversible operations should have some form of user disclosure unless the warning is present in accompanying markdown, which is not visible here.
This shell script emits multiple user-facing status messages in Chinese only, including explicit instructions such as asking the user to send the Chinese phrase “刷新微信二维码”. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not evident in this file.
The script emits only Chinese user-facing instructions, including telling the user to send the Chinese phrase “刷新微信二维码”. This imposes a specific language for interaction without any opt-in or documented locale constraint, which matches the language/locale policy violation criteria.
The script emits multiple hard-coded Chinese status messages to users, such as the responses at L045, L152, L157, L162, and L180. This imposes a specific language on all users without opt-in or an explained region-specific constraint, which matches the language/locale policy violation criteria.
The script reads a PID from a state file and forcefully terminates that process, including with SIGKILL, without verifying that the PID still belongs to the expected prior login command. If the PID file is stale, corrupted, or attacker-controlled within the same user context, the skill could kill an unrelated process, exceeding its stated QR-refresh purpose.
The script launches openclaw channels login --channel openclaw-weixin in a background shell, which is a subprocess operation that can affect authentication state. In this file there is no comment, prompt, or visible disclosure before starting that command; the user only sees status after the operation has already begun.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
fi
fi
nohup bash -lc "
sleep '$DELAY_SECONDS'
{
printf '[%s] openclaw gateway restart\n' \"\$(date -u +\"%Y-%m-%dT%H:%M:%SZ\")\"
This code schedules a background subprocess with nohup bash -lc, executes openclaw gateway restart, appends to a log file, and writes/removes a PID file. While there is internal logging to a file, there is no visible user-facing disclosure, prompt, or explanatory comment/docstring warning that the script will restart the gateway asynchronously and modify files under the state directory.
The script returns natural-language status messages only in Chinese, which imposes a specific language on users without offering a choice or documenting a locale-specific constraint. This matches the policy category for language or locale restrictions without user opt-in.
This code writes a generated PNG to a user-supplied path, and similar file writes also occur for the text and JSON outputs. Although file output is part of the script's purpose, the code provides no confirmation prompt, comment, docstring, or user-facing message disclosing that it will create or overwrite files at the specified paths.
No suspicious patterns detected.