T09 · Insecure Skill Coding Practices
- Location
scripts/lib/happyhorse-1-video.mjs:27- Finding
Arbitrary API endpoint can receive the HiAPI bearer credential
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but its installer and update flow create avoidable code-execution and credential-redirection risks.
Review this skill before installing. Prefer a pinned commit or trusted OpenClaw installation path, avoid running the npx GitHub installer with custom target paths, keep HIAPI_BASE_URL unset unless you fully trust the endpoint, and treat any printed update command as something to verify manually before running.
scripts/lib/happyhorse-1-video.mjs:27Arbitrary API endpoint can receive the HiAPI bearer credential
scripts/install.mjs:101Shell command injection through the installer target path
scripts/lib/happyhorse-1-video.mjs:356Unsigned remote manifest controls mandatory Agent-facing instructions
scripts/lib/happyhorse-1-video.mjs:264Unrestricted output URL fetching enables SSRF and unbounded resource consumption
scripts/install.mjs:11Installer retrieves mutable unpinned code from a remote repository
Referenced artifact was not completely inspected
node scripts/check-config.mjs
The README instructs users to execute npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill directly from GitHub without pinning a commit, tag, or package version. This creates a supply-chain risk: if the upstream repository is changed or compromised, future installs execute different code than was originally reviewed.
This line recommends running code from a GitHub repository via npx without a pinned version. Because the fetched installer can change over time, users and agents may execute unreviewed or malicious code if the repository or dependency chain is tampered with.
The installation command references a live GitHub source rather than a fixed version. In an agent-skill context, this is more dangerous because automated systems may execute the command non-interactively, amplifying supply-chain compromise impact.
Using npx -y github:... against an unpinned repository allows silent code drift and possible execution of attacker-controlled updates. Since this README is an installation guide, the risk is actionable and not merely theoretical.
The command encourages users to run mutable remote code from GitHub. If the repository, account, or a transitive dependency is compromised, execution occurs at install time and may affect local agent skill directories or environment variables.
The auto-install prompt includes an unpinned npx -y github: command, which can cause an agent or user to execute whatever code is current in the repository at that moment. Embedding this in a copy-pasteable automation prompt raises exploitation likelihood.
The README's upgrade instruction again relies on an unpinned GitHub install command. Although framed as maintenance, it still exposes users to supply-chain compromise by pulling and executing the latest repo state during an upgrade.
The compatibility section recommends the same unpinned GitHub-based installer. Because this line targets Codex specifically, an AI-assisted environment may execute it automatically, increasing the operational risk of remote code execution from a compromised source.
This compatibility entry directs Claude Code users to execute an unpinned GitHub installer. The danger is the same supply-chain and remote code execution risk, with added concern that agent tooling may run it with access to user workspaces and secrets.
The OpenCode installation example also uses an unpinned npx -y github: source. Combined with an environment variable pointing to the skills directory, a compromised installer could write arbitrary skill content or modify agent behavior.
The generic 'Cursor / other' install command executes a mutable GitHub repository into a target directory. This is a true vulnerability because it normalizes running unaudited remote code in arbitrary local paths, which could be abused if the source changes maliciously.
The README instructs users to execute code directly from a GitHub repository via npx -y github:... without pinning a commit SHA, tag, or package version. This creates a supply-chain risk: if the upstream repository is compromised or its contents change, users may unknowingly execute attacker-controlled installation code.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
安装脚本会自动检测 Codex(~/.codex/skills)和 Claude Code(~/.claude/skills)。如果两个都存在,-y 会同时装到两个目录。指定 Agent 或自定义目录:
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --codex # 只装到 ~/.codex/skills
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --claude # 只装到 ~/.claude/skills
npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --target=/path # 自定义目录
AGENT_SKILLS_DIR=/path npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill -y
This command again tells users to run npx -y github:HiAPIAI/hiapi-happyhorse-1-0-video-skill --codex from an unpinned GitHub source. Because npx may fetch and execute the latest repository state, any malicious update or repo takeover could result in arbitrary code execution on the user's machine.
The install command for Claude uses the same unpinned npx -y github: pattern. In the context of an agent skill installer that writes into local skill directories, executing unreviewed latest code increases the blast radius to local files, agent behavior, and potentially secrets available in the shell environment.
This custom target installation command still executes installer code from an unpinned GitHub repository. Because the script can write to an arbitrary target path, compromise of the upstream repo could allow file placement in sensitive directories chosen by the user.
The environment-variable form still uses npx -y github:... -y without version pinning, so it has the same supply-chain code execution risk. Since the command may run in a shell containing HIAPI_API_KEY or other credentials, a malicious installer could exfiltrate secrets.
The 'copy for your Agent' block instructs an agent or user to execute an unpinned GitHub npx command. Embedding this into agent-oriented automation makes it more dangerous because users may delegate execution without manually reviewing the fetched code.
The FAQ's forced-update instruction tells users to rerun the same unpinned GitHub installer. This normalizes repeated execution of mutable remote code, increasing exposure over time and making compromise of the upstream repo especially impactful.
The Codex compatibility example again relies on direct execution from an unpinned GitHub source. In a security-sensitive developer environment, this can lead to arbitrary code execution with access to local repositories, credentials, and configuration files.
The Claude Code compatibility example repeats the same mutable remote execution pattern. Because this installs into agent skill directories, a malicious upstream change could both execute immediately and persist altered behavior in future agent sessions.
The OpenCode compatibility example uses an environment-variable-directed install with unpinned GitHub execution. This combines mutable code execution with control over destination path, which could be abused to plant malicious files in user-selected locations if the upstream repo is compromised.
The generic 'other agents' example continues to recommend npx -y github: without pinning. Since it targets arbitrary skill directories across unknown agents, the unsafe pattern is broadly reusable and could impact many environments if exploited.
The skill instructs the agent to perform network-capable actions against external HiAPI endpoints, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates a mismatch between documented behavior and enforcement boundaries, increasing the risk that an agent runtime may allow broader-than-intended outbound access or execute the skill without clear authorization constraints.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal