Back to skill

Security audit

YouTube OpenClaw 监控系统

Security checks for vulnerabilities and agentic risk

Overview

The skill’s YouTube-to-Telegram workflow is understandable, but it asks users to install an unpinned npm package and run a missing script on a schedule, so it needs review before use.

Review before installing. Do not set up the cron job until you have inspected or obtained the missing script, pinned and reviewed npm dependencies, and confirmed exactly what transcript, summary, video metadata, and credentials are sent to external services such as Telegram and transcriptapi.com.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned npm Dependency Installation in Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

bash
npm install https-proxy-agent

Technical Analysis

The installation command does not specify an exact package version, lockfile, or integrity value. Consequently, npm resolves the package version available under the mutable latest distribution tag at installation time. The project also provides no package.json or lockfile to constrain or reproduce the dependency graph.

Although https-proxy-agent is a legitimate package, this installation pattern creates supply-chain exposure if a future release, package publication channel, maintainer account, or transitive dependency is compromised. npm lifecycle scripts associated with an installed package may execute during installation unless explicitly disabled.

The referenced implementation, scripts/youtube-openclaw-monitor.js, is absent from the supplied project, so the necessity and expected use of this dependency cannot be independently verified.

Attack Path

  1. An attacker compromises the package publication channel, a maintainer account, a future package release, or a dependency in the resolved graph.
  2. The attacker publishes a malicious version selected by the unpinned installation command.
  3. A user follows the documented instructions and runs npm install https-proxy-agent.
  4. npm downloads the attacker-controlled release and may execute its lifecycle scripts.
  5. The malicious code executes with the privileges of the user running npm and may inspect files, network access, and environment variables available to that process.

Impact Assessment

Successful exploitation could execute arbitrary code with the invoking user's privileges. Within that scope, malicious dependency code could read or alter user-accessible files, initiate outbound network connections, modify project content, and access envi ...[truncated 283 chars]

Remediation
View remediation

Remediation Suggestions

  • Add a reviewed package.json that declares an audited, exact dependency version.
  • Generate and commit a lockfile containing resolved versions and integrity hashes.
  • Replace ad hoc installation with npm ci so installation fails if the manifest and lockfile disagree.
  • Review the selected package version and its transitive dependency graph before distribution.
  • Use npm ci --ignore-scripts when package lifecycle scripts are not required.
  • Configure npm to use a trusted registry and retain integrity verification.
  • Include the referenced implementation in the project so auditors can verify why the dependency is required and how it is used.

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned npm Dependency Installation in README Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md:18
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

bash
cd scripts
npm install https-proxy-agent

Technical Analysis

The README directs users to install a third-party npm package without an exact version, package manifest, committed lockfile, or explicit integrity constraint. The package selected by npm can therefore change over time, preventing reproducible installation and exposing users to future changes in the package or its transitive dependencies.

Running the command from a scripts directory does not isolate the installation from the user's account. If a resolved package contains malicious lifecycle behavior, that behavior may execute with the permissions and environmental access of the user invoking npm.

The documented scripts directory and youtube-openclaw-monitor.js implementation are not present in the audited artifact. As a result, the dependency's necessity and runtime security properties cannot be validated.

Attack Path

  1. An attacker gains control of a package release path, maintainer account, registry response, or resolved transitive dependency.
  2. A malicious release becomes the version selected by npm for the unpinned package name.
  3. A user runs the README's installation commands.
  4. npm retrieves the mutable dependency version and may run package lifecycle scripts.
  5. Attacker-controlled code executes in the user's context and can access resources available to that process.

Impact Assessment

Exploitation could result in arbitrary code execution under the invoking user's account. The reachable scope may include user-readable files, writable project files, outbound network access, and credentials exposed through the process environment. In particular, the documentation instructs users to configure TRANSCRIPT_API_KEY and TELEGRAM_USER_ID, which could be exposed if present wh ...[truncated 198 chars]

Remediation
View remediation

Remediation Suggestions

  • Provide a reviewed package.json and pin the dependency to an exact audited version.
  • Commit a generated lockfile with npm integrity metadata.
  • Instruct users to run npm ci rather than directly installing a mutable latest release.
  • Where lifecycle scripts are unnecessary, install with npm ci --ignore-scripts.
  • Audit direct and transitive dependencies and automate monitoring for compromised or vulnerable releases.
  • Use only a trusted npm registry and preserve registry integrity checks.
  • Add the missing script and supporting project files so the documented dependency and credential handling can be fully audited.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly describes automatically searching YouTube content, generating summaries, and pushing results to Telegram, which transmits generated content off-system. Without a clear warning or consent note, users may enable behavior that exports potentially sensitive transcripts or summaries to a third-party messaging platform without fully appreciating the privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cron example instructs users to run the script unattended every day, creating an ongoing automated workflow that performs network access and writes files. Without a warning about continuous execution, external requests, and persistent file generation, users may unknowingly deploy a background process with privacy, cost, and operational implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description states it will search YouTube, fetch transcripts, generate summaries, and push results to Telegram, but it does not clearly warn users about the outbound data transfer and local file creation as security/privacy-relevant side effects. This can cause users to invoke the skill without understanding that monitored content and generated reports will be persisted locally and sent to an external messaging platform, increasing the risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes the skill as generating Chinese summaries and highlights this as a fixed behavior, but it does not offer users a language option or explain that the skill is intentionally limited to a Chinese-language use case. That can violate language-choice policy when a specific locale is enforced without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description says the skill will generate Chinese summaries, but it does not indicate that the user can choose the summary language or opt into that locale-specific behavior. This can violate language/locale policy when a skill forces a specific language by default without documenting choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.