T08 · Insecure Dependencies
- Location
README.md:14- Finding
Unpinned Third-Party Package Installation Instruction
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed shopping cashback integration that calls FiberAgent APIs and returns tracked affiliate links, with no evidence of hidden persistence, exfiltration, or destructive behavior.
Before installing, be comfortable with a third-party shopping service receiving product queries, agent IDs, and wallet addresses, and with purchases through returned links being affiliate-tracked for crypto rewards and reputation. Prefer the reviewed local/ClawHub install path over the future unpinned npm command unless the package version and provenance are verified.
README.md:14Unpinned Third-Party Package Installation Instruction
index.js:21Unvalidated Parameters Interpolated into API Request URLs
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
mkdir -p ~/.openclaw/workspace/skills
cp -r fiberagent ~/.openclaw/workspace/skills/
openclaw restart # or restart OpenClaw gateway
The README explicitly describes returning tracked affiliate URLs and registering agents with wallet addresses through an external API, but it does not disclose tracking behavior, third-party data sharing, or consent expectations. In an agent context, this can cause users or operators to unknowingly send identifiers and shopping activity to a remote service, creating privacy, profiling, and compliance risk.
The skill instructs the agent to send product queries to an external API but does not clearly warn that user shopping interests and search terms will be transmitted off-platform. This creates a privacy and transparency issue because users may disclose sensitive purchasing intent or preferences without informed consent, and the third party can log or profile that data.
The skill describes affiliate links, wallet-linked earnings, and on-chain reputation but does not clearly warn users that clicks and purchases may be attributed to the agent wallet and tracked for compensation and reputation building. This is dangerous because it obscures a material financial incentive and creates undisclosed tracking of user purchase activity tied to a blockchain identity.
The natural-language task example encourages sending free-form intent and budget context to an external endpoint without warning that this user context leaves the local environment. Such context can contain sensitive personal or financial information, enabling unnecessary data exposure, third-party profiling, or retention beyond user expectations.
The skill sends user-linked identifiers and a wallet address to an external third-party service (fiberagent.shop) through search, stats, and registration requests without any visible consent, disclosure, minimization, or validation controls in the code. In an agent/tooling context, this is risky because users may not realize their agent ID and wallet address are being transmitted off-platform, enabling privacy leakage, profiling, and unintended exposure of sensitive financial identifiers.
No suspicious patterns detected.