T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/check-prices.js:12- Finding
Caller-Controlled Flag Bypasses Authorization for Global Alert Processing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a Solana price-alert wrapper, but its important alert logic depends on unaudited external code and includes under-disclosed global alert processing.
Review before installing. This skill may be acceptable only in a controlled OpenClaw deployment where the ../../../shared modules are trusted, versioned, and permissioned, and where global alert checks are restricted to an authorized scheduler. Users should understand that it handles user identifiers and persistent alert records, and that the included stop-loss/take-profit scripts go beyond the documented simple price-threshold workflow.
scripts/check-prices.js:12Caller-Controlled Flag Bypasses Authorization for Global Alert Processing
scripts/check-prices.js:6Security-Sensitive Operations Depend on Mutable Executable Modules Outside the Audited Package
If the implementation creates profit-percentage take-profit alerts instead of absolute price alerts, users may set what they believe are simple threshold notifications but actually trigger different financial monitoring behavior. In an asset-tracking context, this can lead to incorrect actions, unintended notifications, mishandling of user identifiers, and misuse of the skill under false pretenses.
If the implementation creates profit-percentage take-profit alerts instead of absolute price alerts, users may set what they believe are simple threshold notifications but actually trigger different financial monitoring behavior. In an asset-tracking context, this can lead to incorrect actions, unintended notifications, mishandling of user identifiers, and misuse of the skill under false pretenses.
Referenced artifact was not completely inspected
| `create-alert.js` | 创建警报 | `<user_id> <token> <above\|below> <price>` |
Referenced artifact was not completely inspected
| `delete-alert.js` | 删除警报 | `<user_id> <alert_id>` |
Without declared permissions the skill's intent is opaque and cannot be validated.
The natural-language content of the skill, including description, workflow, prompts, and guardrails, is presented only in Chinese. This effectively imposes a language choice on users without any opt-in mechanism or documented reason for limiting the skill to that locale.
The invocation guidance includes generic phrases like “提醒”, “通知”, and “到了xxxx通知我”, which are common conversational expressions and are not narrowly scoped to token price alerts. Without explicit exclusions or tighter context, the skill could be invoked unintentionally for unrelated reminder or notification requests.
The script defaults lang to zh when --lang is not provided, which imposes a specific locale choice on the user. The policy allows locale constraints only when the user is given a choice or the constraint is clearly justified and documented; neither is evident here.
The script sets the language to 'zh' by default when the user does not pass --lang. This imposes a specific locale choice rather than offering a neutral default or requiring explicit user selection, which matches the language/locale policy violation criteria.
The manifest describes alerts that notify users when a token price is above or below a target value, which implies absolute price-threshold alerts. This script instead creates a stop-loss alert based on cost-basis drawdown percentage, a distinct alert model tied to user position performance rather than simply crossing a target price.
The manifest describes this skill as creating and managing alerts when a token price goes above or below a target value. This script instead creates a take-profit alert based on profit percentage relative to cost basis, which is a different alert model requiring portfolio/cost-basis semantics beyond a simple price threshold.
The script defaults lang to zh when --lang is not provided, which imposes a specific language preference without user opt-in. The applicable policy only permits locale constraints when the user is given a choice or the constraint is clearly justified.
No suspicious patterns detected.