Back to skill

Security audit

GC Provider Install

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated GrowthCircle provider setup purpose, but it can install or replace executable provider code and change local OpenClaw state using unpinned, forced install commands.

Install only when you explicitly intend to modify OpenClaw or Hermes configuration. Prefer a pinned, reviewed plugin version or digest, review the GrowthCircle provider source and publisher, back up configuration before migration, avoid `--force` unless repairing a known problem, and keep `GROWTHCIRCLE_API_KEY` in a private credential store or environment variable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:84
Finding

Unpinned Third-Party Plugin Installation Enables Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation
``` Use equivalent explicit version pinning for ClawHub packages if supported. 2. Pin an immutable artifact digest or cryptographic checksum in addition to the version. Verify it before installation so that a registry cannot silently replace an artifact associated with the same version. 3. Require package or release signature verification where supported. Document the expected publisher identity, signing key, repository, and verification procedure. 4. Remove `@latest` from installation documentation. Upgrades should be deliberate and should occur only after reviewing the release source, changelog, dependency changes, and artifact integrity. 5. Avoid `--force` in the default installation path. Reserve it for an explicitly diagnosed repair procedure, warn that it replaces an existing installation, and require operator confirmation. 6. Separate installation from activation. After downloading the pinned package, inspect and verify it before running: ```sh openclaw plugins enable gc-provider openclaw gateway restart ``` 7. Run OpenClaw under a dedicated least-privileged account. Restrict filesystem access, outbound network access, environment variables, and credential availability to reduce the impact of a compromised plugin. 8. Establish a controlled update policy that records the approved version and digest and requires security review before changing either value. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
## Safety Rules

- Never ask the user to paste a GrowthCircle AI key into public chat, a public
  repo, logs, screenshots, or frontend code.
- Tell the user to create, rotate, label, and revoke keys from
  `https://growthcircle.id/app/ai`.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- Hermes: configure GrowthCircle manually as an OpenAI-compatible provider,
     because `gc-provider` is an OpenClaw plugin.
   - Hermes to OpenClaw migration: keep the skill under
     `skills/gc-provider-install/SKILL.md`, migrate skills, then install the
     native OpenClaw plugin after migration.

2. Confirm the key source.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill enables implicit invocation but does not define a narrowly scoped trigger or clear constraints on when it may run. Because this skill performs installation, repair, migration, and provider configuration for external AI services, broad auto-invocation increases the chance it is triggered in unintended contexts, causing unauthorized configuration changes or exposure of sensitive provider setup flows.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/install-guide.md (reported line 117)May include surrounding context.

Verify with a small API request:

sh
curl https://ai.growthcircle.id/v1/chat/completions \
  -H "Authorization: Bearer $GROWTHCIRCLE_API_KEY" \
  -H "Content-Type: application/json" \
  --data '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes openclaw migrate apply hermes --yes, which appears to perform a non-reversible migration and suppress confirmation, but the surrounding text only says 'Apply after review' without clearly warning that it will modify local configuration/state. For markdown files, safety-affecting behaviors should be explicitly disclosed when they can impact user data or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.