T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent install guide for a security guardrail, but it gives a third-party plugin broad visibility into tool calls and includes risky credential-display troubleshooting.
Review the actual @capsulesecurity/clawguard package version before installing, pin a known version where possible, avoid printing gateway tokens, and disable or tightly control tool-call logging, metrics, and LLM providers in environments where prompts or tool arguments may contain secrets.
SKILL.md:17Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
SKILL.md:76Troubleshooting Commands Expose the Gateway Authentication Token
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
# Check env var
printenv OPENCLAW_GATEWAY_TOKEN
# Check config token
cat ~/.openclaw/openclaw.json | grep -A2 '"token"'
The skill explicitly states that tool call JSON is logged and that tool context is sent to an LLM for security evaluation, but it does not clearly warn that prompts, tool arguments, session context, secrets, or other sensitive operational data may be transmitted to logs and potentially to external model providers. In a security-plugin installation guide, this omission is particularly risky because users may assume the guardrail improves security without realizing it also increases data exposure surfaces.
No suspicious patterns detected.