Back to skill

Security audit

Clawpm

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a coherent local project-management skill, but it installs an unpinned external GitHub CLI that can change after review.

Review or pin the upstream clawpm package before installation. Expect it to create persistent local project-management files and logs, and avoid putting secrets or sensitive notes into tasks, issue reports, blocker notes, research entries, or work-log summaries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Git Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned dependency from a mutable Git repository
Risk Level: Medium

Complete Code Snippet:

yaml
metadata: { "openclaw": { "homepage": "https://github.com/malphas-gh/clawpm", "requires": { "bins": ["clawpm"] }, "emoji": "📋", "install": [{ "id": "uv", "kind": "uv", "package": "git+https://github.com/malphas-gh/clawpm", "bins": ["clawpm"], "label": "Install clawpm (uv)" }] } }

Technical Analysis

The installation configuration directs uv to install clawpm from a Git repository without specifying an immutable commit hash, signed tag, or fixed release version. Consequently, installation resolves the repository's mutable default branch at install time. The code installed in the future may therefore differ from the code that was originally reviewed.

The audited project contains only SKILL.md; it does not include the dependency's implementation. The external executable and its installation behavior could not be verified from this artifact. This is a supply-chain weakness rather than evidence that the current upstream repository is malicious.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or another mechanism capable of modifying its default branch.
  2. The attacker adds malicious package installation logic or runtime code to the repository.
  3. A user or agent installs the Skill dependency using the declared git+https://github.com/malphas-gh/clawpm source.
  4. uv resolves and retrieves the attacker-modified default branch because no immutable revision is pinned.
  5. Malicious code executes during package installation or when the installed clawpm executable is invoked.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account installing or running clawpm. Depending on that account's permissions, the payload could read ...[truncated 406 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the Git dependency to a reviewed immutable commit hash rather than the mutable default branch.
  • Prefer a fixed, trusted registry release with an exact version and integrity hash where feasible.
  • Verify release signatures, provenance attestations, or checksums before installation.
  • Adopt a lockfile or equivalent dependency-resolution control to make installations reproducible.
  • Review the pinned upstream source, including build and installation hooks, before approving it.
  • Use automated dependency monitoring and require security review before changing the pinned revision.
  • Run installation and the resulting CLI with least privilege in an isolated environment where practical.
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

clawpm context # Full agent context clawpm doctor # Health check clawpm use [project] # Set/show project context clawpm use --clear # Clear context

text

## Work Log Actions

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to run setup and initialize projects, which creates and modifies files under ~/clawpm/ and project directories, but it does not warn about those side effects. This can lead users to invoke the skill without understanding that it will write persistent state and alter local directories, increasing the chance of unintended filesystem changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises context, status, and work-log features that collect repository state, open issues, recent work activity, and commit metadata, but it does not disclose the privacy implications or persistence of that data. Users may unintentionally expose sensitive development activity or store sensitive notes in an append-only log without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.