Back to skill

Security audit

CLI Anything

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly coherent local CLI-harness helper, but it includes under-scoped guidance to install mutable local packages into shared Python/PATH, so users should review it before use.

Install only after reviewing the local CLI-Anything checkout and any harness setup files. Prefer a disposable workspace or virtual environment, avoid --break-system-packages and shared PATH installs, pin dependencies where possible, and treat generated or third-party harness code as untrusted until inspected.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/validated-example-gimp.md:9
Finding

Unverified Editable Package Installation Into the System Python Environment

Content
View full analysis

Vulnerability Details

File Location: references/validated-example-gimp.md, lines 9–21
Vulnerability Type: Unverified third-party package installation and unsafe system-environment modification
Risk Level: Medium

Vulnerable Code Snippet

markdown
### Python dependencies installed for the harness

Installed into the current machine Python environment:

- `Pillow`
- `numpy`
- `prompt_toolkit`

### Harness installation

Installed from:

- `/root/.openclaw/workspace/CLI-Anything/gimp/agent-harness`

Command used conceptually:

```bash
python3 -m pip install --break-system-packages -e /root/.openclaw/workspace/CLI-Anything/gimp/agent-harness
text

Related workflow guidance also appears in `SKILL.md`, lines 53–54 and 72–74:

```markdown
4. Install or verify Python requirements only as needed
5. Validate the CLI entry point and a minimal command
markdown
4. Add tests and a `TEST.md`
5. Install the resulting package to PATH
6. Verify real backend execution, not mock-only behavior

Technical Analysis

The documented workflow installs an editable Python package from /root/.openclaw/workspace/CLI-Anything, a local checkout that is outside the audited project. Consequently, this audit cannot verify its package sources, setup.py, pyproject.toml, build backend, or transitive dependencies.

Python package installation can execute package-controlled build or setup logic. The -e option additionally links runtime behavior to a mutable checkout, meaning later modifications to that checkout may alter the installed command without another conventional installation. The use of --break-system-packages bypasses Python distribution safeguards and permits pip to modify the system-managed Python environment.

The listed dependencies are not version-pinned or hash-verified. Although the Skill instructs users to treat generated code as reviewable output, the concrete installation example does not require source review, repository revisio ...[truncated 1683 chars]

Remediation
View remediation

Remediation Suggestions

  1. Use an isolated virtual environment

    Replace the system-level installation workflow with:

    bash
    python3 -m venv /root/.openclaw/workspace/.venvs/cli-anything-gimp
    /root/.openclaw/workspace/.venvs/cli-anything-gimp/bin/python -m pip install --upgrade pip
    /root/.openclaw/workspace/.venvs/cli-anything-gimp/bin/python -m pip install -e /root/.openclaw/workspace/CLI-Anything/gimp/agent-harness
    

    Remove --break-system-packages from all documentation.

  2. Review package execution surfaces before installation

    Require inspection of:

    • pyproject.toml
    • setup.py
    • setup.cfg
    • build-backend configuration
    • console entry points
    • package initialization code
    • installation hooks and dependency declarations
  3. Pin the external source

    Pin the CLI-Anything checkout to a reviewed commit hash. Verify the repository state before installation and reject unexpected uncommitted changes.

  4. Lock and verify dependencies

    Pin exact dependency versions and use hashes, for example through a reviewed requirements lock file and pip’s --require-hashes option. Avoid unconstrained dependency resolution.

  5. Avoid shared command installation

    Invoke the CLI through the dedicated virtual environment rather than installing unverified entry points onto a system-wide or shared PATH.

  6. Apply least privilege

    Perform review, installation, and validation as an unprivileged account with access limited to a disposable workspace. Do not use sudo or a privileged service account.

  7. Prefer disposable validation

    Test generated or third-party harnesses in a container, sandbox, or disposable virtual machine before allowing them to access sensitive workspace files or credentials.

Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents this skill as a tool for creating or refining CLI harnesses and packaging them for agent use. The supplied code does none of that. It only scans a hard-coded workspace directory for existing harness layouts and emits a JSON summary of their structure and completeness. While this may be tangentially related to CLI-Anything artifacts, its primary purpose is inspection/auditing of an existing repository, which is materially different from the declared generation/refinement behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
- keep the OpenClaw `SKILL.md` focused on **when to use** and **how to navigate the local repo**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
- keep the OpenClaw `SKILL.md` focused on **when to use** and **how to navigate the local repo**

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to run local Python scripts and inspect a repository, which implies shell/code execution capability, but it does not declare any tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent may execute commands more broadly than a reviewer or runtime policy expects, increasing the chance of unintended command execution against workspace content.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/recommend_harness.py (reported line 28)May include surrounding context.

python
def main():
    raw = subprocess.check_output(['python3', str(INSPECT)], text=True)
    data = json.loads(raw)
    harnesses = data.get('harnesses', [])
    ranked = []

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly states that the harness packaging/docs are 'not perfectly aligned,' with setup.py describing a GIMP batch-mode harness while the README describes a Pillow-based image editing CLI. That is a direct documentation-level contradiction about what the harness actually is, which fits intent-code/documentation divergence in the referenced skill materials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.