T08 · Insecure Dependencies
- Location
README.md:23- Finding
Mutable npm Release Executed During Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
TokenSaver appears purpose-built for reducing token usage, but it automatically processes full conversation history through an unverifiable dependency and has unclear cache retention and installation provenance.
Review this skill before installing in sensitive workspaces. It is aligned with token saving, but it may transform and cache conversation content, and the core optimizer is not present or pinned in the artifact. Prefer a pinned installer and a reviewed, locked @token-saver/core version, and avoid using it with secrets or confidential conversations unless cache scope, retention, and clearing behavior are acceptable.
README.md:23Mutable npm Release Executed During Installation
apps/openclaw-integration/dist/index.js:3Unpinned External Core Dependency Receives Complete Conversation Context
The README instructs users to execute npx clawhub@latest install tokensaver, which pulls and runs the latest published package version without pinning to a known-good release. If the package is compromised, unpublished/replaced in a supply-chain incident, or a breaking/malicious version is released, users may execute attacker-controlled code during installation.
The semantic cache feature explicitly reuses responses to similar queries, but the skill does not clearly warn users that prior query content may be retained, compared, and surfaced later. This creates confidentiality and privacy risk, especially if prompts contain secrets, proprietary material, or sensitive user context that could be reused across later interactions.
The skill maps broad natural-language phrases directly to command execution, which can cause unintended activation during ordinary conversation rather than explicit user intent. In an agent environment, ambiguous triggers can silently change optimization modes or disable protections, creating a prompt/command confusion risk even without malicious code execution.
Phrases such as 'Use balanced mode' or 'Default settings' are generic enough to appear in normal discussion, making accidental command invocation likely. Because these triggers alter runtime behavior, an attacker could also embed them in conversational content to influence the skill indirectly through prompt injection-style phrasing.
The plugin automatically rewrites conversation context before each AI request by calling the optimizer on the full conversation without obtaining explicit per-request consent or clearly surfacing that content may be compressed, summarized, or altered. In an AI-assistant context, silent transformation of prompts can change meaning, omit critical safety or user instructions, and produce integrity and privacy risks if users believe the original context is being sent unchanged.
Analytics/status triggers are less dangerous than mode-changing commands, but broad phrases like 'Token status' or 'How much am I saving?' can still collide with ordinary speech and cause unintended disclosure of session metadata. In shared or sensitive contexts, even token usage and cache statistics may expose operational details the user did not mean to request.
The detailed report text states 'TokenSaver auto-suggests new chat when topics change', which is an affirmative capability claim in the skill's inline documentation/output. In this file, the implemented behavior is limited to context optimization, cache/stat reporting, mode changes, and notifications; there is no code that detects topic changes or suggests a new chat.
No suspicious patterns detected.