Back to skill

Security audit

huawei-cloud-openviking-agent-integration

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its memory-integration purpose, but it can fetch and cache plugin code before the promised confirmation step, so users should review it before installing.

Install only if you are comfortable with this skill modifying multiple agent templates and runtime sandboxes, enabling long-term memory tools, and indexing or storing project context in OpenViking. Review or fix the confirmation order first so no package download, npm install, plugin cache write, or runtime provisioning happens before you explicitly confirm.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/agents/openclaw.sh:20
Finding

OpenClaw dependency installation occurs before mandatory authorization

Content
View full analysis

Vulnerability Details

File Location: scripts/agents/openclaw.sh:20-80, 120
Vulnerability Type: Authorization-order flaw allowing premature remote package execution
Risk Level: Medium

Technical Analysis

The OpenClaw integration downloads and installs the unpinned latest release of @openviking/openclaw-plugin before invoking the mandatory confirmation gate:

bash
# Install plugin source — npm first, fall back to GitHub download
local _ov_npm_ok=0
if [[ "${DRY_RUN:-false}" != "true" ]]; then
  local _npm_reg; _npm_reg=$(ov_first_npm_registry)
  log_info "Trying npm install @openviking/openclaw-plugin (online, $_npm_reg)..."
  mkdir -p /tmp/openviking
  local _npm_stage; _npm_stage=$(mktemp -d /tmp/openviking/ov-npm.XXXXXX) || { log_warn "mktemp failed, falling back to GitHub"; _npm_stage=""; }
  cat > "$_npm_stage/package.json" << 'OVPKGEOF'
{
  "dependencies": {
    "@openviking/openclaw-plugin": "latest"
  }
}
OVPKGEOF
  if [[ -n "$_npm_stage" ]] && \
     (cd "$_npm_stage" && "$OV_NPM" install \
         --registry="$_npm_reg" --no-audit --no-fund 2>&1 | tail -5) && \
     [[ -d "$_npm_stage/node_modules/@openviking/openclaw-plugin" ]]; then
    rm -rf "$ov_runtime_src"
    cp -a "$_npm_stage/node_modules/@openviking/openclaw-plugin" "$ov_runtime_src"
    log_ok "openclaw-plugin installed from npm (online) -> $ov_runtime_src"
    touch "$ov_runtime_src"
    _ov_npm_ok=1
  else
    log_warn "npm install failed — falling back to GitHub source download"
  fi
  [[ -n "$_npm_stage" ]] && rm -rf "$_npm_stage"
fi

...

if [[ "${DRY_RUN:-false}" != "true" && -d "$ov_runtime_src" ]]; then
  log_info "Pre-building openclaw-plugin (npm install for runtime deps) for fast runtime recovery..."
  local _pb_stage; _pb_stage=$(mktemp -d /tmp/openviking/ov-prebuild.XXXXXX) || _pb_stage=""
  if [[ -n "$_pb_stage" ]]; then
    cp -a "$ov_runtime_src/." "$_pb_stage/"
    l
...[truncated 3343 chars]
Remediation
View remediation

Remediation Suggestions

  1. Move require_confirmation to the beginning of agent_openclaw_integrate, before all package provisioning, network requests, cache deletion, npm execution, and persistent writes.
  2. Permit only read-only prerequisite and status checks before confirmation.
  3. Ensure refusal leaves the filesystem and dependency state unchanged.
  4. Pin @openviking/openclaw-plugin to an explicit reviewed version instead of latest.
  5. Use a lockfile and verified integrity value for the npm installation path, or provision all plugin files through the existing Git-tree blob verification mechanism.
  6. Consider installing with --ignore-scripts where lifecycle scripts are unnecessary, then perform any required build step through a separately reviewed command.
  7. Add a regression test that invokes the integration, refuses confirmation, and verifies that no network installation occurred and that both persistent runtime directories remain unchanged.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (95)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims tightly controlled, user-authorized integration across eight agents, but the analyzed behavior includes undeclared remote plugin provisioning and incomplete support relative to the stated functionality. This mismatch is dangerous because operators may trust the documentation and approve execution without realizing it can download code, modify templates, or omit promised safety checks such as authorization, status validation, and clean unbinding.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 47)May include surrounding context.

sh
fi
    if [[ "$plugin_source" == "none" ]]; then
      local NPM_REGISTRY; NPM_REGISTRY=$(ov_first_npm_registry 2>/dev/null || echo "$OV_NPM_REGISTRY_DEFAULT")
      echo "registry=${NPM_REGISTRY}" > "${ov_npm_dir}/.npmrc"
      cat > "${ov_npm_dir}/package.json" <<PKGEOF
{"dependencies":{"@opencode-ai/plugin":"$OV_PLUGIN_SDK_VER","@openviking/opencode-plugin":"$OV_OPENCODE_PLUGIN_VER"}}
PKGEOF

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 345)May include surrounding context.

sh
fi
    if [[ "$plugin_source" == "none" ]]; then
      local NPM_REGISTRY; NPM_REGISTRY=$(ov_first_npm_registry 2>/dev/null || echo "$OV_NPM_REGISTRY_DEFAULT")
      echo "registry=${NPM_REGISTRY}" > "${ov_npm_dir}/.npmrc"
      cat > "${ov_npm_dir}/package.json" <<PKGEOF
{"dependencies":{"@opencode-ai/plugin":"$OV_PLUGIN_SDK_VER","@openviking/opencode-plugin":"$OV_OPENCODE_PLUGIN_VER"}}
PKGEOF

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/opencode.sh (reported line 96)May include surrounding context.

sh
fi
    if [[ "$plugin_source" == "none" ]]; then
      local NPM_REGISTRY; NPM_REGISTRY=$(ov_first_npm_registry 2>/dev/null || echo "$OV_NPM_REGISTRY_DEFAULT")
      echo "registry=${NPM_REGISTRY}" > "${ov_npm_dir}/.npmrc"
      cat > "${ov_npm_dir}/package.json" <<PKGEOF
{"dependencies":{"@opencode-ai/plugin":"$OV_PLUGIN_SDK_VER","@openviking/opencode-plugin":"$OV_OPENCODE_PLUGIN_VER"}}
PKGEOF

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/opencode.sh (reported line 222)May include surrounding context.

sh
fi
    if [[ "$plugin_source" == "none" ]]; then
      local NPM_REGISTRY; NPM_REGISTRY=$(ov_first_npm_registry 2>/dev/null || echo "$OV_NPM_REGISTRY_DEFAULT")
      echo "registry=${NPM_REGISTRY}" > "${ov_npm_dir}/.npmrc"
      cat > "${ov_npm_dir}/package.json" <<PKGEOF
{"dependencies":{"@opencode-ai/plugin":"$OV_PLUGIN_SDK_VER","@openviking/opencode-plugin":"$OV_OPENCODE_PLUGIN_VER"}}
PKGEOF

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/opencode.sh (reported line 487)May include surrounding context.

sh
fi
    if [[ "$plugin_source" == "none" ]]; then
      local NPM_REGISTRY; NPM_REGISTRY=$(ov_first_npm_registry 2>/dev/null || echo "$OV_NPM_REGISTRY_DEFAULT")
      echo "registry=${NPM_REGISTRY}" > "${ov_npm_dir}/.npmrc"
      cat > "${ov_npm_dir}/package.json" <<PKGEOF
{"dependencies":{"@opencode-ai/plugin":"$OV_PLUGIN_SDK_VER","@openviking/opencode-plugin":"$OV_OPENCODE_PLUGIN_VER"}}
PKGEOF

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 171)May include surrounding context.

sh
cp -a "$OV_PLUGIN_DST" "$OV_PLUGIN_SHARED"
      touch "$OV_PLUGIN_SHARED"
      if [[ -d "$OV_NPM_DIR/node_modules/@opencode-ai" ]]; then
        rm -rf "$OV_PLUGIN_SHARED/../@opencode-ai"
        cp -a "$OV_NPM_DIR/node_modules/@opencode-ai" "$OV_PLUGIN_SHARED/../@opencode-ai"
      fi
    else

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 312)May include surrounding context.

sh
print("No OpenViking integration block found in template")
PYUNBIND
    log_ok "OpenViking integration block removed from template"
    rm -f "$OV_SHARED_DIR/ov-codearts-init.sh" && log_ok "Removed ov-codearts-init.sh"
  fi
  if [[ -n "$sandbox" ]]; then
    if [[ -n "$cf" && -f "$cf" ]]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 342)May include surrounding context.

sh
log_ok "OpenViking plugin removed from live sandbox"
    fi
    local ov_npm_dir="${sandbox}/.codeartsdoer"
    rm -rf "${ov_npm_dir}/node_modules" 2>/dev/null && log_ok "node_modules removed"
    rm -f "${ov_npm_dir}/package.json" 2>/dev/null
    rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 343)May include surrounding context.

sh
fi
    local ov_npm_dir="${sandbox}/.codeartsdoer"
    rm -rf "${ov_npm_dir}/node_modules" 2>/dev/null && log_ok "node_modules removed"
    rm -f "${ov_npm_dir}/package.json" 2>/dev/null
    rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null
    rm -f "${ov_npm_dir}/openviking-config.json" 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 344)May include surrounding context.

sh
local ov_npm_dir="${sandbox}/.codeartsdoer"
    rm -rf "${ov_npm_dir}/node_modules" 2>/dev/null && log_ok "node_modules removed"
    rm -f "${ov_npm_dir}/package.json" 2>/dev/null
    rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null
    rm -f "${ov_npm_dir}/openviking-config.json" 2>/dev/null
    rm -rf "${ov_npm_dir}/openviking" 2>/dev/null

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 345)May include surrounding context.

sh
rm -rf "${ov_npm_dir}/node_modules" 2>/dev/null && log_ok "node_modules removed"
    rm -f "${ov_npm_dir}/package.json" 2>/dev/null
    rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null
    rm -f "${ov_npm_dir}/openviking-config.json" 2>/dev/null
    rm -rf "${ov_npm_dir}/openviking" 2>/dev/null
    log_ok "npm packages and config cleaned up"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 346)May include surrounding context.

sh
rm -f "${ov_npm_dir}/package.json" 2>/dev/null
    rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null
    rm -f "${ov_npm_dir}/openviking-config.json" 2>/dev/null
    rm -rf "${ov_npm_dir}/openviking" 2>/dev/null
    log_ok "npm packages and config cleaned up"
  fi

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 347)May include surrounding context.

sh
rm -f "${ov_npm_dir}/package-lock.json" 2>/dev/null
    rm -f "${ov_npm_dir}/.npmrc" 2>/dev/null
    rm -f "${ov_npm_dir}/openviking-config.json" 2>/dev/null
    rm -rf "${ov_npm_dir}/openviking" 2>/dev/null
    log_ok "npm packages and config cleaned up"
  fi
  if [[ -n "$sandbox" && -f "${sandbox}/AGENTS.md" ]] && grep -q "OpenViking" "${sandbox}/AGENTS.md" 2>/dev/null; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/codearts.sh (reported line 351)May include surrounding context.

sh
log_ok "npm packages and config cleaned up"
  fi
  if [[ -n "$sandbox" && -f "${sandbox}/AGENTS.md" ]] && grep -q "OpenViking" "${sandbox}/AGENTS.md" 2>/dev/null; then
    rm -f "${sandbox}/AGENTS.md"
    log_ok "AGENTS.md removed (old approach cleanup)"
  fi
  ov_log_info "重启 CodeArts 以使更改完全生效" "Restart CodeArts for changes to take full effect"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/deepseek_harness.sh (reported line 83)May include surrounding context.

sh
[[ -d "\$_pd" ]] || continue
      _pn=\$(basename "\$_pd")
      [[ "\$_pn" == "dsh-llm" || "\$_pn" == "dsh-tools" ]] && continue
      rm -rf "\$_plugin_da/\$_pn"
      cp -r "\$_pd" "\$_plugin_da/\$_pn"
    done
    touch "\$_peers_marker"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/deepseek_harness.sh (reported line 319)May include surrounding context.

sh
f.write(content)
DSHUNBINJ
    log_ok "OpenViking integration block removed from template start.sh"
    rm -f "$OV_SHARED_DIR/ov-deepseek-harness-init.sh" && log_ok "Removed standalone ov-deepseek-harness-init.sh"
  fi
  # Live sandbox profiles
  if [[ "$live_has_ov" == "true" ]]; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/deepseek_harness.sh (reported line 327)May include surrounding context.

sh
local cf="${dsh_home}/profiles/$p/package.json"
      [[ -f "$cf" ]] || continue
      backup_file "$cf" 2>/dev/null || true
      rm -rf "${dsh_home}/profiles/$p/node_modules/@openviking"
      "$OV_PY" - "$cf" << 'DSHPJSON'
import json
import sys

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/agents/deepseek_harness.sh (reported line 370)May include surrounding context.

sh
local rt_cf="$_rt_profiles/$p/package.json"
      [[ -f "$rt_cf" ]] || continue
      if [[ -d "$_rt_profiles/$p/node_modules/@openviking" ]]; then
        rm -rf "$_rt_profiles/$p/node_modules/@openviking"
        rt_cleaned=true
      fi
      if grep -q '"@openviking/dsh-memory-plugin"' "$rt_cf" 2>/dev/null; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 62)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 63)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 111)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 112)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 189)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agents/hermes.sh (reported line 190)May include surrounding context.

sh
endpoint: __OV_ENDPOINT__
OVYAML
fi
if ! grep -q "OPENVIKING_ENDPOINT" "$HOME/.hermes/.env" 2>/dev/null; then
  echo "OPENVIKING_ENDPOINT='__OV_ENDPOINT__'" >> "$HOME/.hermes/.env"
fi
"""

Static analysis

No suspicious patterns detected.