Back to skill

Security audit

Deepvista Chat

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed DeepVista chat CLI wrapper, with expected external messaging and user-confirmed write/delete actions, but it has ordinary supply-chain and remote-agent scope risks.

Install only if you trust DeepVista and the deepvista-cli package source. Confirm before using delete or +send, and avoid sending sensitive information unless you intend DeepVista's remote agent to process it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Third-Party CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8–14
Vulnerability Type: Unpinned external package installation
Risk Level: Medium

Vulnerable Code

yaml
requires:
  bins:
    - deepvista
  skills:
    - deepvista-shared
install:
  - kind: uv
    package: deepvista-cli
    bins: [deepvista]

Technical Analysis

The Skill instructs the host to install the third-party deepvista-cli package without specifying an exact version, cryptographic hash, lockfile, signature, or immutable source reference. Consequently, package resolution depends on the mutable state of an external package registry at installation time.

The installed package supplies the deepvista executable used by all documented operations. Its implementation is not included in the audited project, so the package's installation hooks, executable entry point, network behavior, and credential handling cannot be verified from this artifact.

If the package, maintainer account, publication process, or package registry is compromised, a malicious release could execute code during installation or whenever the CLI is invoked. Dependency confusion or unsafe registry configuration may also cause an unintended package to be selected.

Attack Path

  1. An attacker compromises the package publisher, package registry, or dependency-resolution configuration, or publishes a package selected through dependency confusion.
  2. The attacker publishes a malicious release under the package identity resolved as deepvista-cli.
  3. The Skill installation process resolves the unpinned dependency to that release.
  4. Malicious package code executes during installation or when the deepvista entry point is invoked.
  5. The code runs with the privileges of the installing or invoking process and may access its environment, files, authentication material, and chat data.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the proces ...[truncated 574 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin deepvista-cli to a specific, reviewed version rather than resolving the latest available release.
  2. Require cryptographic hashes through a locked dependency manifest or equivalent integrity-verification mechanism.
  3. Configure an explicit trusted package index and disable unintended fallback registries to reduce dependency-confusion exposure.
  4. Verify package provenance and signatures where the distribution ecosystem supports them.
  5. Audit the selected package version, including installation hooks and executable entry points, before deployment.
  6. Perform installation and execution in a least-privileged, isolated environment with restricted filesystem, secret, and network access.
  7. Establish a controlled update process that reviews and tests each dependency upgrade before changing the pinned version.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: deepvista-chat
description: "DeepVista Chat: Send messages to the AI agent and manage chat sessions."
metadata:
  openclaw:
    category: service

Static analysis

No suspicious patterns detected.