Back to skill

Security audit

DG-LAB

Security checks for vulnerabilities and agentic risk

Overview

This plugin is openly for DG-Lab electrical stimulation control, but it gives agents and a public WebSocket service too much unsafe physical-device authority without enough confirmation, bounds, or transport protection.

Review before installing. Do not use the one-click curl-to-bash installer; prefer the OpenClaw/npm package path. Only run this in a tightly controlled environment, avoid exposing the WebSocket port directly to the Internet, set conservative hardware limits in the DG-Lab app, keep emotion mode off unless deliberately supervised, and require a human confirmation process outside the plugin before any agent-triggered stimulation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:52
Finding

Mutable Remote Installer Is Downloaded and Executed Directly by Bash

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
dist/index.js:352
Finding

Agent Tool Can Trigger Prolonged Electrical Stimulation Without Per-Call Authorization or Duration Limits

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
dist/server.js:43
Finding

Public Plaintext WebSocket Service Accepts Unauthenticated Device Feedback

Content
View full analysis
{ clients.forEach((ws, id) => { if (ws.readyState === ws_1.WebSocket.OPEN) { const hb = { type: protocol_1.DGLabWSType.HEARTBEAT, clientId: id, targetId: '', message: 'heartbeat' }; ws.send(JSON.stringify(hb)); } }); }, HEARTBEAT_INTERVAL_MS); wss.on('connection', (ws, req) => { const urlPath = (req.url || '').replace(/^\//, ''); let assignedControlId = null; if (urlPath && validControlIds.has(urlPath)) { assignedControlId = urlPath; } const clientId = (0, uuid_1.v4)(); clients.set(clientId, ws); ``` Messages matching the feedback format are accepted without verifying that the sending connection is the bound App identified by the message: ```javascript else if (msg.type === protocol_1.DGLabWSType.MSG && msg.message) { const strengthFeedback = msg.message.match(/^strength-(\d+)\+(\d+)\+(\d+)\+(\d+)$/); if (strengthFeedback) { exports.serverEvents.emit('strength-feedback', { strengthA: parseInt(strengthFeedback[1]), strengthB: parseInt(strengthFeedback[2]), limitA: parseInt(strengthFeedback[3]), limitB: parseInt(strengthFeedback[4]), }); } const feedbackMatch = msg.message.match(/^feedback-(\d)$/); if (feedbackMatch) { const index = parseInt(feed ...[truncated 2959 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
dist/index.js:419
Finding

Waveform Import Command Can Read Arbitrary Files Accessible to the Gateway Process

Content
View full analysis
' }; let resolvedPath = filePath; if (!path.isAbsolute(filePath)) { resolvedPath = path.join(os.homedir(), '.openclaw', 'workspace', 'plugins', 'openclaw-plugin-dg-lab', 'data', filePath); } if (!fs.existsSync(resolvedPath)) { return { text: `文件不存在: ${resolvedPath}` }; } try { const presets = (0, pulselib_1.loadPulsesFile)(resolvedPath); return { text: `成功导入 ${presets.length} 个波形:\n${presets.map(p => ` - [${p.id}] ${p.name}`).join('\n')}` }; } catch (e) { return { text: `导入失败: ${e.message}` }; } } ``` From `dist/pulselib.js`: ```javascript function loadPulsesFile(filePath) { const content = fs.readFileSync(filePath, 'utf-8'); const presets = parsePulsesContent(content, path.basename(filePath)); for (const p of presets) { addPreset(p); } return presets; } ``` ### Technical Analysis The documented purpose of `/dg_pulse load` is to import waveform files from the plugin’s `data` directory. Relative paths are joined to that directory, but absolute paths are accepted unchanged. Relative traversal components such as `../` are also not rejected or checked after canonicalization. The resulting path is passed directly to `fs.readFileSync` using the permissions of the OpenClaw gateway process. There is no canonical-path containment check, extension enforcement at this command boundary, file-type check, symlink defense, or file-size limit. The file content is parsed as JSON-like waveform data rather than returned verbatim, so arbitrary text files are not dire ...[truncated 1826 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (33)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The dg_shock tool can immediately send electrostimulation commands based solely on tool invocation parameters, without requiring user confirmation, runtime warning, or proof of informed consent. Because this is a safety-critical physical capability, lack of an execution-time consent barrier makes accidental, coerced, or malicious triggering materially dangerous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The message:sent hook automatically analyzes outgoing AI text and converts it into electrical stimulation with no per-event user confirmation, no session-level authorization check, and no visible disclosure at trigger time. In this skill context, the code directly controls a connected electrostimulation device, so coupling model-generated text to physical actuation creates a real safety risk from ordinary conversation, prompt injection, or unintended model behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The emotion hook triggers physical stimulation automatically from message content with no user-facing disclosure at the moment of activation and no confirmation that the user still wants stimulation. This is especially dangerous because normal model outputs, manipulated prompts, or contextual mistakes can indirectly cause real-world electrical stimulation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile includes ws 8.19.0, which is flagged for uninitialized memory disclosure and memory-exhaustion denial of service. Because ws is a network-facing WebSocket library, any skill exposing or consuming WebSocket connections can make these issues materially dangerous: a remote peer may be able to trigger service instability or unintended data exposure.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

The package depends on ws 8.19.0, which is reported vulnerable to memory disclosure and memory-exhaustion denial of service. Because this plugin explicitly advertises WebSocket-based control of physical stimulation devices, a flaw in the network-facing transport layer is more dangerous here than in a non-networked package: a remote peer may be able to crash the process, leak memory contents, or disrupt device-control workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file's natural-language comments explicitly describe support for Chinese and English keywords, while the rule set is heavily centered on Chinese-language interaction patterns and domain-specific Chinese phrasing. There is no accompanying opt-in, language choice, or justification for this locale constraint, which can constitute a language policy issue under the natural-language policy rules.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code maps emotionally charged text classifications such as 'punishing' and 'angry' directly to punitive waveform generation, including high-duration outputs, without any visible gating, consent check, safety interlock, or user-facing warning in this component. In a system that can drive a physical stimulation device, allowing assistant text to trigger stronger device behavior based only on keyword matching creates a real risk of unexpected or coercive output and makes misuse or prompt-induced escalation easier.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Multiple command descriptions and user-facing return texts are presented only in Chinese, while the file also includes English-facing tool descriptions, indicating mixed-language behavior without user opt-in. This can violate language or locale policy when a skill implicitly forces one language for some interactions instead of offering a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The dg_shock tool description frames the action as shocking the user, but the implementation simply sends stimulation commands to any connected DG-Lab device/channel. This misleading framing can cause operators or downstream agents to misunderstand who or what will be affected, increasing the chance of unsafe activation of the wrong device or channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language content that assumes a Chinese-speaking user or maintainer, including the main descriptive comments and later user-visible warning/error text. Under the policy, forcing a specific language without opt-in or justification is a locale/language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The declarations explicitly expose waveform generators for punitive and stimulation-oriented output, and the surrounding comments describe frequency/intensity ranges and continuous segmented sending without any visible safety gating, contraindication warning, or consent checks. In the context of software that appears to drive physical stimulation hardware, omission of user-facing safety controls increases the risk of misuse, overuse, or unsafe operation causing physical harm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file generates stimulation waveforms, including a punishment mode with sustained high-frequency, maximum-intensity output, yet contains no built-in warnings, gating, or safety disclosures. In the context of controlling a physical stimulation device, omission of safeguards can lead to unsafe use, prolonged exposure, or accidental triggering of harmful patterns.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation labels teaseWave as a gentle soothing waveform, but the implementation still produces active stimulation output with intensity varying roughly between 20 and 80. In a device-control context, misleading safety descriptions can cause operators or downstream code to select a waveform under false assumptions, increasing the risk of unexpected stimulation or user harm.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description says the plugin provides "agent tools, chat commands, and an emotion-driven stimulation engine," but does not specify what exact commands, phrases, or context activate those capabilities, making the activation scope ambiguous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Line L008 presents the Chinese README as the default and links to English as an alternative, while the rest of this file is entirely Chinese. For users who arrive at this file directly, the skill documentation effectively imposes a language choice without an explicit opt-in, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README content is written in Chinese and line L008 presents Chinese first, with English as an alternate link, but this file does not state that users may choose their preferred language for interaction or documentation. Under the stated policy, forcing or defaulting to a specific language without clear opt-in can be a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains natural-language comments in Chinese such as the maximum message length and pulse-array descriptions, but there is no indication that the skill is intentionally region-specific or that users may choose their preferred language. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language comments and parameter descriptions are written entirely in Chinese, which can indicate a language-specific constraint without offering any user choice or documenting a justified locale requirement. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

With no manifest available, the skill's intended scope is unknown. This file implements local file creation by generating and saving QR code images to an arbitrary output directory, which is a capability beyond pure string/QR generation and is not justified by any stated purpose in the provided context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The comment at L15 is written only in Chinese ("获取当前连接状态") while the surrounding declarations and comments are in English. This creates an implicit language inconsistency that may violate a language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language comments describing the skill behavior are written only in Chinese, which can impose a language constraint on users or maintainers without any documented choice or justification. The policy specifically flags forced language or locale usage when no opt-in or clear rationale is provided.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==13.0.0 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The lockfile pins uuid to 13.0.0, and the reported advisory indicates missing buffer bounds checks in certain UUID generation paths when a caller supplies a buf argument. This is a real supply-chain risk if the plugin or a downstream caller uses the affected v3/v5/v6 APIs with attacker-influenced inputs, though the stated impact is limited and no exploitability context is visible from the lockfile alone.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
61% confidence
Finding

The only policy category in scope here is natural-language language/locale violations, and no explicit language forcing is present. However, because no locale-related policy text appears in this file, there is no confident SQP-3 violation to report.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 38)May include surrounding context.

json
},
  "homepage": "https://github.com/FengYing1314/openclaw-plugin-dg-lab#readme",
  "dependencies": {
    "qrcode": "^1.5.4",
    "uuid": "^13.0.0",
    "ws": "^8.19.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 39)May include surrounding context.

json
"homepage": "https://github.com/FengYing1314/openclaw-plugin-dg-lab#readme",
  "dependencies": {
    "qrcode": "^1.5.4",
    "uuid": "^13.0.0",
    "ws": "^8.19.0"
  },
  "devDependencies": {

Static analysis

No suspicious patterns detected.