T08 · Insecure Dependencies
- Location
README.md:34- Finding
Unpinned Third-Party Installer Executes Mutable Supply-Chain Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to do what it says, but it can automatically broker very broad external API searches and executions with user-provided data, so users should review it before installing.
Install only if you are comfortable with OpenClaw using QVeris as a broad external API broker. Use a scoped, revocable QVERIS_API_KEY, avoid sending secrets or sensitive personal, health, financial, or account data as tool parameters, review discovered tools before execution where possible, and prefer pinned or verified installation methods over the unpinned npx command.
README.md:34Unpinned Third-Party Installer Executes Mutable Supply-Chain Code
Referenced artifact was not completely inspected
node scripts/qveris_tool.mjs search "weather forecast API"
Referenced artifact was not completely inspected
node scripts/qveris_tool.mjs search "weather forecast API"
Referenced artifact was not completely inspected
node scripts/qveris_tool.mjs search "weather forecast API"
Referenced artifact was not completely inspected
node scripts/qveris_tool.mjs search "weather forecast API"
Referenced artifact was not completely inspected
node scripts/qveris_tool.mjs search "weather forecast API"
The README promotes dynamic discovery and execution of arbitrary external tools via the QVeris API but does not warn that tool use may trigger outbound network requests, send user prompts or parameters to third parties, or invoke sensitive external actions. In this skill's context, that omission is more dangerous because the core purpose is to search and execute thousands of external APIs dynamically, expanding the chance of unintended data disclosure or risky side effects.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill exposes sensitive capabilities (environment variable access and outbound network access) but does not declare an explicit tool scope such as allowed tools or permissions. That makes the trust boundary implicit rather than enforceable, increasing the chance the skill can be invoked with broader effective capabilities than reviewers or policy expect.
The skill is marked auto_invoke and its description is extremely broad, covering thousands of external APIs and many unrelated domains. This creates ambiguous trigger conditions that can cause the agent to call an external dynamic tool broker unexpectedly, sending user prompts or derived parameters off-platform and enabling actions across a very large capability surface without deliberate user selection.
The execute path forwards user-supplied parameters directly to a third-party API, but the CLI provides no explicit warning, consent step, or data-classification guidance before transmitting them. In a tool-discovery/execution skill, users may reasonably pass sensitive prompts, identifiers, health, finance, or location data, so silent exfiltration to an external service creates a real privacy and compliance risk even if the network behavior is part of the feature.
No suspicious patterns detected.