T08 · Insecure Dependencies
- Location
README.md:16- Finding
Documented Installation Command Resolves a Different Python Distribution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a legitimate OpenClaw model manager, but it handles API keys and local OpenClaw configuration in ways users should review carefully before installing.
Install only after verifying the package name and source you are installing, and treat this as a tool with authority to store API keys, rewrite OpenClaw model configuration, contact provider APIs, and restart OpenClaw. Rotate any keys previously passed on a command line, check permissions on `~/.openclaw`, and avoid running `modelpool repair` unless you are comfortable with it testing configured provider URLs and changing local state.
README.md:16Documented Installation Command Resolves a Different Python Distribution
scripts/freeswitch.py:76OpenRouter Bearer Credentials Are Stored in Plaintext Without Enforced File Permissions
scripts/freeswitch.py:542API Keys Accepted as Command-Line Arguments Can Leak Through Shell and Process Metadata
scripts/repair.py:114Repair Command Sends Provider Bearer Credentials to Unrestricted Configured URLs
The README advertises automated diagnostics, cleanup, config modification, and service restarts, but does not clearly warn users that running the repair flow will change local state and may disrupt active sessions or alter configuration unexpectedly. In an agent-skill context, users may trigger commands with elevated trust and limited review, making undocumented state-changing behavior more dangerous even if the underlying intent is operational convenience rather than harm.
The setup flow shows users entering API keys, saving them, reconfiguring providers, and restarting OpenClaw, but it does not disclose how credentials are stored, whether they are encrypted or file-permission protected, or that service interruption will occur. Because this is an installation/setup skill intended for quick execution, the omission increases the risk of insecure secret handling and unexpected downtime in local development environments.
The skill advertises behaviors implying file access, configuration changes, network calls, and process/control actions, but it declares no explicit tool scope or permissions. In an agent ecosystem, this creates an authorization ambiguity where a user may invoke a seemingly simple setup command without understanding that it can read/write config, contact external services, and trigger repair or restart flows.
The invocation language is highly promotional and underspecified, using phrases like 'one command' and 'everything auto-configured' without defining boundaries, side effects, or safety checks. This can mislead users and agent runtimes into approving broad autonomous actions that include credential handling, network access, and configuration changes beyond what the user reasonably expects.
The skill instructs users to enter and manage multiple API keys but provides no warnings about secret handling, masking, storage, redaction, or display in status/list commands. Because the skill explicitly includes commands like 'status' and 'keys list', omission of key-safety guidance materially increases the risk of credential exposure in terminal output, logs, screenshots, or persisted config.
The 'one-click repair' workflow promises automatic diagnosis, cleanup, memory/log cleanup, and full restart, but it does not warn users about system-state changes, interruption risk, or the scope of those actions. In context, this is dangerous because the skill is positioned as a convenience tool for OpenClaw management, so users may trigger disruptive or potentially destructive maintenance actions without informed consent.
The guide tells users to copy and paste an API key but does not clearly state that the key is a sensitive secret that must never be shared, committed to source control, pasted into chats, or stored insecurely. In a skill that targets non-expert users and encourages quick setup, this omission materially increases the risk of credential leakage and unauthorized use of the user's OpenRouter account.
The guide explicitly encourages creating multiple OpenRouter accounts to multiply free quota, which may violate provider terms, trigger abuse detection, or lead users to account suspension. In the context of a tool marketed around free-quota maximization and key rotation, this behavior normalizes circumvention of platform limits and increases both compliance and operational risk for users.
API keys are stored in plaintext in a predictable path under the user's home directory without permission hardening or a clear warning to the user. If the file is exposed through permissive filesystem permissions, backups, or local compromise, the credentials can be recovered and abused to access the user's provider account and quota.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Validate and restart
print("\n 🔍 Validating...")
subprocess.run(["openclaw", "config", "validate"], capture_output=True)
print(" 🔄 Restarting OpenClaw...")
subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
subprocess.run(["openclaw", "config", "validate"], capture_output=True)
print(" 🔄 Restarting OpenClaw...")
subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
time.sleep(15)
print("")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
subprocess.run(["openclaw", "config", "validate"], capture_output=True)
print(" 🔄 Restarting OpenClaw...")
subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
time.sleep(15)
print("")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
subprocess.run(["openclaw", "config", "validate"], capture_output=True)
print(" 🔄 Restarting OpenClaw...")
subprocess.run(["openclaw", "daemon", "restart"], capture_output=True)
time.sleep(15)
print("")
The auto-configuration path writes a new OpenClaw configuration and restarts the daemon without explicit confirmation, which can silently alter provider settings and operational behavior. In a security-sensitive environment, unexpected config replacement can disrupt existing safeguards, reroute model traffic, or overwrite carefully managed settings.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
print(f" {i}. {fb}")
# Test gateway
result = subprocess.run(["ss", "-tlnp"], capture_output=True, text=True)
gw_ok = "18789" in result.stdout
print(f"\n Gateway: {'✅ running' if gw_ok else '❌ down'}")
print("")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
script_dir = os.path.dirname(os.path.abspath(__file__))
repair_script = os.path.join(script_dir, "repair.py")
if os.path.exists(repair_script):
subprocess.run([sys.executable, repair_script])
else:
print(f" ❌ repair.py not found at {script_dir}")
print(" Try running from the freeswitch/scripts directory")
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
if isinstance(cmd, str):
cmd = shlex.split(cmd)
r = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
return r.stdout.strip(), r.returncode
except subprocess.TimeoutExpired:
return "TIMEOUT", -1
The save_config function unconditionally backs up and rewrites ~/.openclaw/openclaw.json, with no prior disclosure at the point of execution and no user consent gate. Automatic modification of a user's application config is security-relevant because it can change operational behavior, break trust assumptions, or overwrite intentional settings if the script's logic is wrong or manipulated upstream.
The repair workflow automatically rewrites the user's OpenClaw model configuration when rebuilding the fallback chain, without interactive confirmation or a dry-run mode. This can silently alter service behavior and model routing, which is risky in an agent-install/repair context because it changes trusted local configuration based on network test results and script logic.
The script stops and restarts the OpenClaw daemon automatically, causing service interruption without prior warning or confirmation. In an agent skill context, unexpected daemon restarts can disrupt active workloads and may be abused socially by packaging impactful operational changes as a 'repair' action users might run without understanding the consequences.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
name="modelpool-free",
version="1.0.3",
description="Free AI Model Manager for OpenClaw — auto-discover, multi-key rotation, smart fallback, one-click repair",
long_description=open("README.md", encoding="utf-8").read() if __import__("os").path.exists("README.md") else "",
long_description_content_type="text/markdown",
author="LeeHub",
url="https://github.com/meilihulee/modelpool",
The manifest describes discovery, configuration, fallback setup, and repair of free AI models for OpenClaw. In addition to that, the status command runs ss -tlnp to inspect local listening sockets/process information and infer gateway health, which is host-level introspection not clearly justified by the stated model manager role.
The cleanup step removes .log files older than three days using os.remove. While cleanup may be part of maintenance, the script gives only a post-action status message and no advance warning that files will be deleted.
No suspicious patterns detected.