Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md `python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed OpenClaw theme installer that changes UI files and assets, with no artifact-backed evidence of deception, exfiltration, or unsafe automatic execution.
Install only if you want this theme to modify your OpenClaw workspace and live control-ui files. Review the Chinese-only UI/text behavior, use --skip-apply if you want to stage files before touching the live UI, and be aware that missing default assets may be downloaded from ClawHub and verified during installation.
Referenced artifact was not completely inspected
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`
Referenced artifact was not completely inspected
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`
Referenced artifact was not completely inspected
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`
Referenced artifact was not completely inspected
`python3 scripts/install_cyberpunk_theme.py --workspace <target-workspace>`
This file defines logic that sorts messages, assigns synthetic timestamps, mutates app.chatMessages and app.chatToolMessages, and triggers app.requestUpdate(). That changes underlying chat data ordering/state, which goes well beyond a theme skill's stated purpose of installation, repair, import, or visual customization.
The code does more than style the UI: it edits message.timestamp fields, stores original timestamps, replaces app.chatMessages/app.chatToolMessages, and forces a re-render. Direct mutation of application conversation data is not an expected or necessary capability for a theme installation/customization skill.
The skill advertises installation and update workflows that write files, invoke Python scripts, and may download assets, but it declares no explicit tool scope or permission boundaries. This increases the chance that an agent executes file, shell, or network actions without clear user-visible constraints, which is risky because the skill modifies a target workspace and applies changes to a live UI by default.
The user-facing instructions and operational guidance are predominantly in Chinese, while the file does not state that the skill is region-specific or provide an opt-in language choice. This can violate a language/locale policy when users are forced into a specific language without prior consent.
The documentation states that installation will place files into the workspace, generate an apply script, and immediately apply the theme to the live OpenClaw control UI, but this behavior is not surfaced as a prominent warning before use. Users or agents may treat the skill as a passive theme package when it actually performs immediate state-changing actions on a live environment.
The default prompt is broadly framed to install, repair, import, or swap assets for the theme without clear user-confirmation boundaries or narrow activation constraints. In an agent ecosystem, vague trigger language can cause the skill to be invoked in contexts where the user did not explicitly intend theme modification, increasing the risk of unintended workspace changes or asset replacement.
The code unconditionally converts quota labels like "week" and "weekly" to the Chinese string "周". This imposes a specific locale in user-visible UI text without any opt-in, fallback, or justification, which matches the language/locale policy violation criteria.
The manifest describes a skill for installing, repairing, importing, and customizing a specific visual theme, including swapping avatars and background images. This code also implements logic to detect session-picker interactions and forcibly navigate to another chat session via URL changes, which is application behavior control rather than theme presentation or asset customization.
The skill claims to manage a cyberpunk chat and dream theme, but this code queries model authentication/quota status from the OpenClaw app and rewrites quota badge UI based on provider usage data. Reading live auth/quota state is not an obvious implementation detail of installing or customizing avatars/backgrounds/theme visuals.
Calling app.client.request('models.authStatus', ...) to retrieve provider auth/quota information is a capability that reaches into internal application state and service APIs. For a theme skill focused on visual appearance and bundled media replacement, this capability is not clearly justified by the stated purpose.
This CSS injects visible UI text via pseudo-elements, including a fixed assistant nameplate string containing Chinese text. Because the file is code and these labels are hard-coded rather than user-configurable, it enforces a specific language/locale in the interface without any visible opt-in mechanism.
The stylesheet uses pseudo-element content to render substantial Chinese-language text directly in the UI. Hard-coding displayed language in CSS prevents localization controls and effectively forces one locale on all users.
This rule injects a Chinese label directly into the rendered interface through CSS content. That is a natural-language locale choice embedded in code, with no indication of user selection or regional scoping.
The stylesheet renders Chinese-language metadata text directly in the UI through a pseudo-element. This creates a fixed-language experience and does not offer the user any locale choice.
The CSS prepends Chinese text to status details using a pseudo-element, making the interface language fixed for all users. This is a locale policy issue because there is no visible mechanism for language choice or justification for region-specific behavior.
This rule injects mixed English/Chinese header text directly into the interface. Embedding user-visible language in CSS hard-codes the locale and bypasses any normal localization or user-consent flow.
This later rule repeats the pattern of injecting a fixed Chinese/English assistant label through CSS content. Repeated hard-coded locale-specific strings in UI chrome indicate the skill enforces a language choice rather than honoring user preference.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
return candidate
try:
npm_root = subprocess.run(
['npm', 'root', '-g'],
check=True,
capture_output=True,
When local assets are missing, the installer fetches a ZIP bundle from a remote service and consumes files from it during installation. Although individual decoded payloads are SHA-256 checked later, the skill still performs network-based supply-chain behavior during install, creating availability and trust risks and expanding the attack surface for a theme installer that modifies a live UI distribution.
The skill notes in compatibility documentation that missing default assets may be downloaded from an official package, but this network behavior is not clearly disclosed as an installation warning. Undisclosed downloads can violate expected offline or restricted-environment assumptions and may surprise users in sensitive environments even if integrity checks are present.
The display name and short description are written in Chinese, with no indication that the user can choose their preferred language or locale. This can violate language/locale policy expectations when a skill imposes a language presentation without documented opt-in or region-specific justification.
No suspicious patterns detected.