T09 · Insecure Skill Coding Practices
- Location
scripts/bundle.cjs:7- Finding
Shell Command Injection Through Untrusted Plugin Configuration Values
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but its installer handles credentials and shell commands in unsafe ways that warrant review before use.
Install only if you trust the publisher and are comfortable with a bundled script modifying OpenClaw configuration, installing an unpinned plugin, sending a device fingerprint to the ClawSentry service, and storing authentication material locally in plaintext/logs. Prefer a reviewed, pinned installer that avoids shell-string execSync, redacts logs, and protects credentials with restrictive permissions or OS secret storage.
scripts/bundle.cjs:7Shell Command Injection Through Untrusted Plugin Configuration Values
scripts/bundle.cjs:5Authentication Tokens and API Credentials Stored or Logged in Plaintext
scripts/bundle.cjs:7Unpinned Third-Party Plugin Installed Without Integrity Verification
scripts/bundle.cjs:3Persistent Machine Fingerprint Collected, Stored, and Sent to an External Service
Referenced artifact was not completely inspected
The bundled script (`bundle.cjs`) performs the following operations:
Referenced artifact was not completely inspected
The bundled script (`bundle.cjs`) performs the following operations:
The skill description is written entirely in Chinese and provides no indication that other languages are supported or that the user can choose their preferred language. Under the policy, a skill that effectively forces a specific language without user opt-in is a natural-language policy violation.
The skill instructs the agent to run a bundled Node.js script and perform environment/shell-capable actions, but it declares no explicit tool scope or permissions boundary in the manifest. This creates an authorization gap where consumers may invoke code execution without clear least-privilege constraints or reviewable limits.
The skill explicitly directs execution of a bundled script that performs system queries, network communication, local state writes, background process spawning, and plugin configuration changes. Even if presented as installation logic, bundled third-party code with shell/system access is dangerous because it can conceal additional behavior, exfiltrate host identifiers or tokens, or persist beyond the initial run.
- **Bundled Code:** The script includes bundled third-party libraries, which may execute system-level operations.
- __System Queries:__ The script uses `node-machine-id` library, which may use `child_process` to query system information.
- **Network Access:** The script communicates with remote API endpoints for authentication.
- **Arbitrary Code Execution:** Running bundled scripts from unknown sources can execute arbitrary code on your system.
### Security Measures
The script collects a stable device fingerprint via machineIdSync() and transmits it in the X-Ai-Device-Fingerprint header during login-related API calls, but there is no explicit user consent prompt or clear warning before collection/transmission. In a security-plugin installer context, this creates privacy and tracking risk because a persistent hardware-derived identifier can be used to correlate activity across sessions and services.
The script writes sensitive login state to .state/login_state.json, including loginToken, deviceFingerprint, expiredAt, loginUrl, and later marks enable=true, without any access control hardening, encryption, or user warning. It also logs API responses and polling activity to poll_login.log, increasing the chance that credentials or account identifiers are exposed to other local users, backup systems, or log collectors.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
2. **Verify Integrity:** Check the script's file integrity using a hash if provided
3. **Monitor Execution:** Run the script in a controlled environment and monitor its output
4. **Ensure Trust:** Only run the script if you trust the source of this skill
5. **Check Permissions:** Ensure the script has appropriate file permissions
### Alternative Installation
No suspicious patterns detected.