Back to skill

Security audit

Claw Desktop Pet - Enterprise-grade 7x24 AI Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill is a setup guide for a desktop assistant, but it asks users to run unreviewed, unpinned code from GitHub with npm and pip, so it needs Review before installation.

Before installing, review the referenced GitHub repository and use a specific trusted commit or signed release. Run it as a normal user, not as administrator, preferably in an isolated environment. Be aware that the app is intended to run continuously, write logs, use a local OpenClaw port, and install npm/Python dependencies that were not included in this reviewed package.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
QUICKSTART.md:5
Finding

Execution of Unpinned External Code and Dependencies

Content
View full analysis

Vulnerability Details

File Location: QUICKSTART.md:5-22 and SKILL.md:44-56
Vulnerability Type: Unverified external repository and unpinned third-party dependencies
Risk Level: High

Vulnerable Code

bash
### 1. 克隆项目

```bash
git clone https://github.com/kk43994/claw-desktop-pet.git
cd claw-desktop-pet

2. 安装依赖

bash
npm install
pip install edge-tts

3. 启动应用

bash
npm start
text

The same installation sequence is also documented in `SKILL.md:44-56`.

### Technical Analysis

The supplied artifact contains documentation rather than the advertised application source. Its installation procedure clones a mutable remote repository without selecting or verifying a reviewed commit, tag, release signature, or cryptographic checksum. It then installs unpinned npm and Python dependencies before executing the downloaded application.

Because the remote source, package manifests, lockfiles, lifecycle scripts, and dependency contents are absent from the audited artifact, their integrity and behavior cannot be validated. An npm installation may execute package lifecycle scripts, while `npm start` directly executes code obtained from the mutable repository. The unpinned `edge-tts` installation also allows a later package version to be selected without review.

This creates a supply-chain trust boundary in which the code ultimately executed by the user may differ from the content that was reviewed.

### Attack Path

1. An attacker compromises the referenced repository, its maintainer account, an npm dependency, or the selected Python package release.
2. The attacker inserts malicious application code or an installation lifecycle script into the mutable source or dependency chain.
3. A user follows the documented commands and clones the current repository state.
4. `npm install` or `pip install edge-tts` retrieves the attacker-controlled component.
5. An npm lifecycle script may execute during installation, or the malicious code 
...[truncated 778 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete application source and dependency manifests in the reviewed skill artifact so that runtime behavior can be audited.
  2. Pin the external repository to a specific reviewed commit hash rather than cloning a mutable default branch.
  3. Distribute signed releases and require users to verify the release signature or a checksum obtained through a trusted channel.
  4. Commit an npm lockfile with integrity metadata and replace npm install with npm ci to enforce the reviewed dependency graph.
  5. Pin edge-tts to an explicitly reviewed version and use a Python requirements file containing cryptographic hashes, installed with pip install --require-hashes.
  6. Review npm lifecycle scripts and, where compatible with the application, install dependencies with scripts disabled before explicitly running only trusted build steps.
  7. Add automated dependency scanning, provenance verification, and maintainer-account protections to the release process.
  8. Run installation and execution with least privilege in an isolated environment; users should not run these commands as an administrator.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This changelog uses Chinese throughout the user-facing descriptive content, which can impose a language/locale constraint on users without opt-in. The policy allows locale-specific behavior only when it is clearly documented and justified, which is not evident here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document presents all user-facing instructions and examples in Chinese, including headings, setup steps, and FAQ content. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · QUICKSTART.md (reported line 59)May include surrounding context.

javascript
// 查看健康分数
const health = await fetch('http://localhost:18788/health');
console.log(await health.json());

Static analysis

No suspicious patterns detected.