T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:52- Finding
Mutable Remote Installer Is Downloaded and Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This plugin is openly for DG-Lab electrical stimulation control, but it gives agents and a public WebSocket service too much unsafe physical-device authority without enough confirmation, bounds, or transport protection.
Review before installing. Do not use the one-click curl-to-bash installer; prefer the OpenClaw/npm package path. Only run this in a tightly controlled environment, avoid exposing the WebSocket port directly to the Internet, set conservative hardware limits in the DG-Lab app, keep emotion mode off unless deliberately supervised, and require a human confirmation process outside the plugin before any agent-triggered stimulation.
SKILL.md:52Mutable Remote Installer Is Downloaded and Executed Directly by Bash
dist/index.js:352Agent Tool Can Trigger Prolonged Electrical Stimulation Without Per-Call Authorization or Duration Limits
dist/server.js:43Public Plaintext WebSocket Service Accepts Unauthenticated Device Feedback
dist/index.js:419Waveform Import Command Can Read Arbitrary Files Accessible to the Gateway Process
The dg_shock tool can immediately send electrostimulation commands based solely on tool invocation parameters, without requiring user confirmation, runtime warning, or proof of informed consent. Because this is a safety-critical physical capability, lack of an execution-time consent barrier makes accidental, coerced, or malicious triggering materially dangerous.
The message:sent hook automatically analyzes outgoing AI text and converts it into electrical stimulation with no per-event user confirmation, no session-level authorization check, and no visible disclosure at trigger time. In this skill context, the code directly controls a connected electrostimulation device, so coupling model-generated text to physical actuation creates a real safety risk from ordinary conversation, prompt injection, or unintended model behavior.
The emotion hook triggers physical stimulation automatically from message content with no user-facing disclosure at the moment of activation and no confirmation that the user still wants stimulation. This is especially dangerous because normal model outputs, manipulated prompts, or contextual mistakes can indirectly cause real-world electrical stimulation.
The lockfile includes ws 8.19.0, which is flagged for uninitialized memory disclosure and memory-exhaustion denial of service. Because ws is a network-facing WebSocket library, any skill exposing or consuming WebSocket connections can make these issues materially dangerous: a remote peer may be able to trigger service instability or unintended data exposure.
The package depends on ws 8.19.0, which is reported vulnerable to memory disclosure and memory-exhaustion denial of service. Because this plugin explicitly advertises WebSocket-based control of physical stimulation devices, a flaw in the network-facing transport layer is more dangerous here than in a non-networked package: a remote peer may be able to crash the process, leak memory contents, or disrupt device-control workflows.
The file's natural-language comments explicitly describe support for Chinese and English keywords, while the rule set is heavily centered on Chinese-language interaction patterns and domain-specific Chinese phrasing. There is no accompanying opt-in, language choice, or justification for this locale constraint, which can constitute a language policy issue under the natural-language policy rules.
This code maps emotionally charged text classifications such as 'punishing' and 'angry' directly to punitive waveform generation, including high-duration outputs, without any visible gating, consent check, safety interlock, or user-facing warning in this component. In a system that can drive a physical stimulation device, allowing assistant text to trigger stronger device behavior based only on keyword matching creates a real risk of unexpected or coercive output and makes misuse or prompt-induced escalation easier.
Multiple command descriptions and user-facing return texts are presented only in Chinese, while the file also includes English-facing tool descriptions, indicating mixed-language behavior without user opt-in. This can violate language or locale policy when a skill implicitly forces one language for some interactions instead of offering a choice.
The dg_shock tool description frames the action as shocking the user, but the implementation simply sends stimulation commands to any connected DG-Lab device/channel. This misleading framing can cause operators or downstream agents to misunderstand who or what will be affected, increasing the chance of unsafe activation of the wrong device or channel.
This code file contains natural-language content that assumes a Chinese-speaking user or maintainer, including the main descriptive comments and later user-visible warning/error text. Under the policy, forcing a specific language without opt-in or justification is a locale/language policy violation.
The declarations explicitly expose waveform generators for punitive and stimulation-oriented output, and the surrounding comments describe frequency/intensity ranges and continuous segmented sending without any visible safety gating, contraindication warning, or consent checks. In the context of software that appears to drive physical stimulation hardware, omission of user-facing safety controls increases the risk of misuse, overuse, or unsafe operation causing physical harm.
This file generates stimulation waveforms, including a punishment mode with sustained high-frequency, maximum-intensity output, yet contains no built-in warnings, gating, or safety disclosures. In the context of controlling a physical stimulation device, omission of safeguards can lead to unsafe use, prolonged exposure, or accidental triggering of harmful patterns.
The documentation labels teaseWave as a gentle soothing waveform, but the implementation still produces active stimulation output with intensity varying roughly between 20 and 80. In a device-control context, misleading safety descriptions can cause operators or downstream code to select a waveform under false assumptions, increasing the risk of unexpected stimulation or user harm.
This is a manifest file, so vague-trigger review applies. The description says the plugin provides "agent tools, chat commands, and an emotion-driven stimulation engine," but does not specify what exact commands, phrases, or context activate those capabilities, making the activation scope ambiguous.
Line L008 presents the Chinese README as the default and links to English as an alternative, while the rest of this file is entirely Chinese. For users who arrive at this file directly, the skill documentation effectively imposes a language choice without an explicit opt-in, which is a natural-language locale policy concern.
The README content is written in Chinese and line L008 presents Chinese first, with English as an alternate link, but this file does not state that users may choose their preferred language for interaction or documentation. Under the stated policy, forcing or defaulting to a specific language without clear opt-in can be a natural-language locale policy concern.
This file contains natural-language comments in Chinese such as the maximum message length and pulse-array descriptions, but there is no indication that the skill is intentionally region-specific or that users may choose their preferred language. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation.
The natural-language comments and parameter descriptions are written entirely in Chinese, which can indicate a language-specific constraint without offering any user choice or documenting a justified locale requirement. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.
With no manifest available, the skill's intended scope is unknown. This file implements local file creation by generating and saving QR code images to an arbitrary output directory, which is a capability beyond pure string/QR generation and is not justified by any stated purpose in the provided context.
The comment at L15 is written only in Chinese ("获取当前连接状态") while the surrounding declarations and comments are in English. This creates an implicit language inconsistency that may violate a language/locale policy when no opt-in or justification is provided.
Natural-language comments describing the skill behavior are written only in Chinese, which can impose a language constraint on users or maintainers without any documented choice or justification. The policy specifically flags forced language or locale usage when no opt-in or clear rationale is provided.
The lockfile pins uuid to 13.0.0, and the reported advisory indicates missing buffer bounds checks in certain UUID generation paths when a caller supplies a buf argument. This is a real supply-chain risk if the plugin or a downstream caller uses the affected v3/v5/v6 APIs with attacker-influenced inputs, though the stated impact is limited and no exploitability context is visible from the lockfile alone.
The only policy category in scope here is natural-language language/locale violations, and no explicit language forcing is present. However, because no locale-related policy text appears in this file, there is no confident SQP-3 violation to report.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
},
"homepage": "https://github.com/FengYing1314/openclaw-plugin-dg-lab#readme",
"dependencies": {
"qrcode": "^1.5.4",
"uuid": "^13.0.0",
"ws": "^8.19.0"
},
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"homepage": "https://github.com/FengYing1314/openclaw-plugin-dg-lab#readme",
"dependencies": {
"qrcode": "^1.5.4",
"uuid": "^13.0.0",
"ws": "^8.19.0"
},
"devDependencies": {
No suspicious patterns detected.