Back to skill

Security audit

Decision Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a local decision-support CLI with no hidden execution, persistence, credential access, or data exfiltration found; the main caution is standard npm/npx supply-chain hygiene.

Install it only from a source you trust, preferably with pinned package versions or a reviewed lockfile. Be aware that the current implementation is a simple local decision-analysis tool and should not be treated as professional financial, legal, medical, or career advice.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:36
Finding

Unpinned Third-Party Package Execution and Dependency Resolution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:369, README.md:48, and package.json:36-45
Vulnerability Type: Supply-chain exposure through unpinned package execution and dependency resolution
Risk Level: Medium

Complete Code Snippets

SKILL.md:369 and README.md:48:

bash
npx skills add <owner/repo>@decision-expert

package.json:36-45:

json
"dependencies": {
  "commander": "^11.0.0",
  "inquirer": "^9.2.0",
  "chalk": "^5.3.0",
  "cli-table3": "^0.6.3",
  "lodash": "^4.17.21",
  "yaml": "^2.3.0",
  "json2csv": "^6.0.0",
  "markdown-table": "^3.0.3"
},

Technical Analysis

The installation instructions invoke the unversioned skills package through npx. When the package is not already available locally, npx may resolve, download, and execute the package currently published under that registry name. The artifact does not pin the executable package to a reviewed version, and the placeholder <owner/repo> does not identify a concrete, verifiable source revision.

Runtime dependencies use caret version ranges, allowing npm to resolve newer compatible releases than those originally reviewed. The audited directory structure contains no package lockfile, so dependency versions and transitive dependency integrity are not reproducibly fixed by this artifact.

This is a supply-chain weakness rather than evidence that any currently declared dependency is malicious. Exploitation requires compromise, replacement, dependency confusion, or an unsafe future publication affecting a package that installation resolves.

Attack Path

  1. An attacker compromises or gains control of the unpinned skills registry package, one of the declared dependencies, or a relevant transitive dependency.
  2. The attacker publishes a malicious version that remains compatible with the unpinned invocation or caret version range.
  3. A user follows the documented command or run ...[truncated 1096 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the package executed by npx to an exact, reviewed version, for example npx --yes skills@X.Y.Z ..., after confirming the package identity and publisher.
  2. Replace the <owner/repo> placeholder with a verified repository owner and repository name. Where supported, bind installation to an immutable commit digest or signed release.
  3. Pin direct dependencies to exact versions rather than caret ranges.
  4. Generate, review, and commit a lockfile so direct and transitive dependency versions and integrity hashes are reproducible.
  5. Use npm ci in CI and deployment workflows to enforce the reviewed lockfile.
  6. Disable package lifecycle scripts during dependency acquisition where they are unnecessary, such as with npm ci --ignore-scripts, and explicitly run only reviewed build steps afterward.
  7. Add automated dependency scanning, provenance verification, lockfile integrity checks, and controlled update review.
  8. Run package installation with a non-privileged account in an isolated environment with minimal filesystem, credential, and network access.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (22)

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run npx skills add <owner/repo>@decision-expert without pinning the version of the package providing skills. npx can fetch and execute the latest published package at install time, which creates a supply-chain risk if the package is updated maliciously, compromised, or differs from what the author expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documented trigger phrases are exclusively in Chinese, while the file otherwise uses English for headings and instructions. This creates a natural-language/locale constraint without any opt-in, alternative language triggers, or stated region-specific justification, which can violate language-choice policy expectations.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
# Analyze a decision with automatic framework selection
decision analyze "买什么手机" --options "iPhone 15, Samsung Galaxy S24, Google Pixel 8"

# Create a pros/cons list
decision pros-cons "换工作到上海" --pros "高薪, 发展机会" --cons "高房价, 离家远"

# Use a specific decision framework

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to run npx skills add <owner/repo>@decision-expert without pinning an exact version or immutable source. This can cause execution of unexpected code if the upstream package changes, is compromised, or resolves to a malicious version at install time, which is especially risky because npx fetches and runs packages directly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The examples prominently use Chinese input phrases for core commands, but the README does not explain whether the skill is multilingual, Chinese-focused, or whether users may use their preferred language. This can amount to an implicit language constraint in the skill description without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The help and example text includes Chinese-only sample invocations and the matrix error example uses Chinese input as the sole illustration. For a general-purpose CLI, this can be read as steering users toward a specific language/locale without any opt-in or stated regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples shown to users are all in Chinese, which implicitly enforces or strongly biases a specific locale in user-facing guidance. There is no accompanying note that the skill supports multiple languages or that it is region-specific.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 39)May include surrounding context.

json
},
  "homepage": "https://skills.sh/openclaw/decision-expert",
  "dependencies": {
    "commander": "^11.0.0",
    "inquirer": "^9.2.0",
    "chalk": "^5.3.0",
    "cli-table3": "^0.6.3",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 40)May include surrounding context.

json
"homepage": "https://skills.sh/openclaw/decision-expert",
  "dependencies": {
    "commander": "^11.0.0",
    "inquirer": "^9.2.0",
    "chalk": "^5.3.0",
    "cli-table3": "^0.6.3",
    "lodash": "^4.17.21",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 41)May include surrounding context.

json
"dependencies": {
    "commander": "^11.0.0",
    "inquirer": "^9.2.0",
    "chalk": "^5.3.0",
    "cli-table3": "^0.6.3",
    "lodash": "^4.17.21",
    "yaml": "^2.3.0",

Unverifiable Dependency: chalk has 1 known advisory(ies) (MAL-2025-46969 (Malicious code in chalk (npm))), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 42)May include surrounding context.

json
"commander": "^11.0.0",
    "inquirer": "^9.2.0",
    "chalk": "^5.3.0",
    "cli-table3": "^0.6.3",
    "lodash": "^4.17.21",
    "yaml": "^2.3.0",
    "json2csv": "^6.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 43)May include surrounding context.

json
"inquirer": "^9.2.0",
    "chalk": "^5.3.0",
    "cli-table3": "^0.6.3",
    "lodash": "^4.17.21",
    "yaml": "^2.3.0",
    "json2csv": "^6.0.0",
    "markdown-table": "^3.0.3"

Unverifiable Dependency: lodash has 10 known advisory(ies) (CVE-2020-28500 (Regular Expression Denial of Service (ReDoS) in lodash); CVE-2021-23337 (Command Injection in lodash); CVE-2018-16487 (Prototype Pollution in lodash) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
"chalk": "^5.3.0",
    "cli-table3": "^0.6.3",
    "lodash": "^4.17.21",
    "yaml": "^2.3.0",
    "json2csv": "^6.0.0",
    "markdown-table": "^3.0.3"
  },

Unverifiable Dependency: yaml has 2 known advisory(ies) (CVE-2026-33532 (yaml is vulnerable to Stack Overflow via deeply nested YAML collections); CVE-2023-2251 (Uncaught Exception in yaml)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 45)May include surrounding context.

json
"cli-table3": "^0.6.3",
    "lodash": "^4.17.21",
    "yaml": "^2.3.0",
    "json2csv": "^6.0.0",
    "markdown-table": "^3.0.3"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 46)May include surrounding context.

json
"lodash": "^4.17.21",
    "yaml": "^2.3.0",
    "json2csv": "^6.0.0",
    "markdown-table": "^3.0.3"
  },
  "devDependencies": {
    "jest": "^29.7.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 49)May include surrounding context.

json
"markdown-table": "^3.0.3"
  },
  "devDependencies": {
    "jest": "^29.7.0",
    "eslint": "^8.50.0",
    "@types/node": "^20.8.0",
    "typescript": "^5.2.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 50)May include surrounding context.

json
},
  "devDependencies": {
    "jest": "^29.7.0",
    "eslint": "^8.50.0",
    "@types/node": "^20.8.0",
    "typescript": "^5.2.2"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 51)May include surrounding context.

json
"devDependencies": {
    "jest": "^29.7.0",
    "eslint": "^8.50.0",
    "@types/node": "^20.8.0",
    "typescript": "^5.2.2"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 52)May include surrounding context.

json
"jest": "^29.7.0",
    "eslint": "^8.50.0",
    "@types/node": "^20.8.0",
    "typescript": "^5.2.2"
  },
  "engines": {
    "node": ">=16.0.0",

Static analysis

No suspicious patterns detected.