T08 · Insecure Dependencies
- Location
handler.ts:86- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill generator is not clearly malicious, but it needs review because it can produce skills that use sensitive credentials and external services with weak setup guidance.
Review generated skills before installing them. Do not paste real API keys or Slack tokens into SKILL.md, avoid storing Google credential JSON files inside skill folders, pin dependencies before installing, and require explicit approval before any generated skill posts to Slack or reads sensitive calendars, files, or business data.
handler.ts:86Unpinned Third-Party Dependency Installation
handler.ts:88Google Service-Account Credentials Stored Inside a Shareable Skill Directory
SKILL.md:240Documentation Encourages Hardcoding API Tokens in Skill Source
Instructions found that direct the agent to transmit conversation context or user data to external services.
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |
Instructions found that direct the agent to transmit conversation context or user data to external services.
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |
Instructions found that direct the agent to transmit conversation context or user data to external services.
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |
Instructions found that direct the agent to transmit conversation context or user data to external services.
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |
Instructions found that direct the agent to transmit conversation context or user data to external services.
|-------------------|---------|--------------|
| "I wish my agent could..." | Describe what you want | Complete skill file + setup guide |
| Need Google Calendar integration | "Read my calendar events" | Calendar reader skill |
| Want Slack notifications | "Send messages to Slack" | Slack messenger skill |
| Have CSV data to analyze | "Analyze my sales data" | CSV analyzer skill |
| Need custom API integration | "Connect to [service]" | API wrapper skill |
| Want local file processing | "Parse my PDF invoices" | File processor skill |
Instructions found that direct the agent to transmit conversation context or user data to external services.
Let's walk through a real example from start to finish.
### What You Want
"I want my agent to send messages to my team's Slack channel when it completes tasks."
### The Conversation
The top-level documentation states the skill is entirely local, requires no external API calls, and provides complete privacy, but the generated Google Calendar and Slack skills clearly instruct users to configure credentials and interact with remote services. This misleading security posture can cause users to install skills with broader trust assumptions than warranted, increasing the risk of unintentional data exposure.
The claim of 'No external API calls' and 'Complete privacy' contradicts the actual behavior of the generated artifacts, which include Slack messaging and Google Calendar access. Security-relevant misrepresentation is dangerous because users may rely on false privacy guarantees when deciding whether to generate and deploy these skills.
The generated instructions direct users to save a Google credentials JSON file in a predictable location under the skills directory. Storing long-lived service credentials in a common project path without added safeguards increases the chance of accidental disclosure through backups, file sharing, weak permissions, or later skill access.
'Save this file to: ~/openclaw/skills/google-calendar-reader/SKILL.md',
'Install dependencies: npm install googleapis',
'Get your Google Calendar API credentials from: https://console.cloud.google.com',
'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',
'Set environment variable: GOOGLE_CALENDAR_CREDENTIALS=~/openclaw/skills/google-calendar-reader/credentials.json',
'Restart OpenClaw',
],
The environment variable points directly to a local credentials.json file for Google Calendar access, reinforcing a pattern of filesystem-based secret storage in a predictable path. In an agent ecosystem with multiple skills, this can enlarge the blast radius if another component reads local files or logs environment configuration.
'Install dependencies: npm install googleapis',
'Get your Google Calendar API credentials from: https://console.cloud.google.com',
'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',
'Set environment variable: GOOGLE_CALENDAR_CREDENTIALS=~/openclaw/skills/google-calendar-reader/credentials.json',
'Restart OpenClaw',
],
testing: [
The generated guidance encourages downloading and storing a JSON key file, which normalizes handling high-value credentials as flat files. This is risky because service-account keys are sensitive and often remain valid until manually revoked, making accidental exposure impactful.
'Enable the Google Calendar API',
'Go to "Credentials" → "Create Credentials" → "Service Account"',
'Download the JSON key file',
'Save it as credentials.json in your skill folder',
],
url: 'https://developers.google.com/calendar/api/quickstart/nodejs',
},
The skill is explicitly a skill generator and describes creating integrations that may use credentials and external services, yet it does not declare any tool scope or permissions boundaries. In a framework that can infer or grant capabilities, this broad omission increases the risk that generated behavior will access environment data or sensitive resources without clear user-facing restrictions.
The description says to use the skill whenever a user wishes the agent could do something new, which overlaps with very common conversational phrasing. That can cause over-triggering, leading the agent to invoke a powerful skill generator in situations where the user did not intend code generation, credential handling, or external integration planning.
Although the document notes that generated skills may require credentials, it does not clearly warn that created skills can perform sensitive actions on user data, local files, or external services. Because this skill targets non-technical users and promises no-coding setup, the absence of a strong warning materially increases the chance of unsafe deployment.
The 'Uses this skill automatically' guidance encourages autonomous activation based on a broad request and lacks guardrails about consent, safety checks, or when not to use it. In context, this is riskier because the skill can generate files, request credentials, and propose integrations with external systems.
The generated Google Calendar template reads credentials from environment variables and retrieves calendar data from an external service, yet the generated instructions do not prominently warn about external access to personal scheduling data. In a personal-assistant setting, calendar contents are often sensitive, so silent normalization of this access increases privacy risk.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
export default listEvents;`,
installation: [
'Save this file to: ~/openclaw/skills/google-calendar-reader/SKILL.md',
'Install dependencies: npm install googleapis',
'Get your Google Calendar API credentials from: https://console.cloud.google.com',
'Save credentials as: ~/openclaw/skills/google-calendar-reader/credentials.json',
The generated Slack skill enables outbound posting to external channels using a bot token, but the generated content does not include a clear user-facing warning or recommend confirmation before sending messages. In an agent context, this can lead to unintended disclosure of sensitive information or accidental messaging to the wrong workspace or channel.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
export default sendMessage;`,
installation: [
'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
'Install dependencies: npm install @slack/web-api',
'Get your Slack Bot Token from: https://api.slack.com/apps',
'Set environment variables:',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
installation: [
'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
'Install dependencies: npm install @slack/web-api',
'Get your Slack Bot Token from: https://api.slack.com/apps',
'Set environment variables:',
' SLACK_BOT_TOKEN=xoxb-your-token-here',
' SLACK_DEFAULT_CHANNEL=#team-updates',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
installation: [
'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
'Install dependencies: npm install @slack/web-api',
'Get your Slack Bot Token from: https://api.slack.com/apps',
'Set environment variables:',
' SLACK_BOT_TOKEN=xoxb-your-token-here',
' SLACK_DEFAULT_CHANNEL=#team-updates',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
installation: [
'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
'Install dependencies: npm install @slack/web-api',
'Get your Slack Bot Token from: https://api.slack.com/apps',
'Set environment variables:',
' SLACK_BOT_TOKEN=xoxb-your-token-here',
' SLACK_DEFAULT_CHANNEL=#team-updates',
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
installation: [
'Save this file to: ~/openclaw/skills/slack-messenger/SKILL.md',
'Install dependencies: npm install @slack/web-api',
'Get your Slack Bot Token from: https://api.slack.com/apps',
'Set environment variables:',
' SLACK_BOT_TOKEN=xoxb-your-token-here',
' SLACK_DEFAULT_CHANNEL=#team-updates',
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
export default analyzeCSV;`,
installation: [
'Save this file to: ~/openclaw/skills/csv-analyzer/SKILL.md',
'Install dependencies: npm install csv-parser',
'No API key needed — this skill works locally',
'Restart OpenClaw',
No suspicious patterns detected.