T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This market-alert skill is mostly purpose-aligned, but it sends an authentication token and possible contact details through a plaintext WebSocket and asks users to globally install an unpinned npm package.
Install only if you trust the publisher and the bridge service, and avoid using this on untrusted networks until the endpoint is changed to wss://. Do not provide email or phone notifications unless you explicitly want off-platform contact, and prefer a pinned, reviewed package version instead of the documented global unpinned npm install.
SKILL.md:13Unpinned Global Installation of a Third-Party npm Package
scripts/watch-monitor.js:3Authentication Token and Personal Data Transmitted over an Unencrypted WebSocket
The declared description frames the skill as a market-watching reminder plugin, but the content also reveals fixed remote WebSocket connectivity, token-authenticated service access, and optional email/phone notification workflows. This mismatch is dangerous because users and platform reviewers may not realize the skill sends data to external services and can contact users through additional channels, undermining informed consent and security review.
The skill references environment-based credentials (OPENCLAW_WS_TOKEN) and instructs execution of a monitoring script, but it declares no explicit tool scope or permissions. This weakens reviewability and containment because a consumer cannot tell from the manifest that the skill needs secret access and runtime capabilities, increasing the chance of overbroad execution or unintended secret exposure.
The skill instructs a monitoring script to connect to a fixed external WebSocket bridge, yet it gives no warning that user-derived monitoring requests and authentication tokens will be transmitted off-platform. Hidden network communication is risky because it can expose user intent, market interests, metadata, or secrets to an external service without transparent notice.
The skill supports email and phone-call notifications and collects contact details, but it provides no privacy notice, data-sharing disclosure, or consent language. That creates a risk of sending personal data to external systems or initiating contact without adequately informing the user how their information will be used.
The code establishes an outbound WebSocket connection to an external host and submits watch requests and receives trigger events without any visible disclosure, consent handling, or minimization of transmitted data. In a plugin context, this can expose user monitoring preferences, product selections, and potentially downstream event content to a remote service in ways the user may not expect.
The code reads a credential-like value from OPENCLAW_WS_TOKEN, but there is no user-facing disclosure, warning, or explanatory documentation in this file about handling authentication material. For code files, accessing sensitive environment variables should have at least some visible explanation or warning unless clearly covered elsewhere.
The plugin is configured to send alerts to external email addresses and phone numbers, which can cause unintended disclosure of user activity or trigger unsolicited contact if recipients are wrong, stale, or attacker-controlled. Because these actions reach outside the platform, lack of explicit warning and recipient confirmation increases the risk of privacy leakage and abuse.
The manifest describes a market-monitoring plugin that sends reminders when price conditions trigger, but it does not indicate broader telephony or email delivery integrations. Adding direct email and call configurations introduces extra communication capabilities beyond the clearly stated scope of simply monitoring and reminding within the plugin context.
The file presents all user-facing instructions and examples exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale limitation is explicitly justified, which is not stated here.
The manifest describes a financial market monitoring plugin, but does not mention use of environment-provided credentials or authenticated bridge access. While backend connectivity may be expected, pulling runtime secrets from the environment is a privileged capability not evident from the stated user-facing purpose alone.
No suspicious patterns detected.