Back to skill

Security audit

Windows Esm Installer

Security checks for vulnerabilities and agentic risk

Overview

This Windows repair skill matches its stated purpose, but it can change npm settings, overwrite local files, and tell users to run npm installs as Administrator without clear confirmation.

Review carefully before installing. Use diagnostic mode first, avoid running generated npm install scripts as Administrator, check whether install.bat, install.ps1, or INSTALL_REPORT.md already exist in the working directory, and be aware that the skill changes npm's registry setting to npmmirror.com unless modified.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:109
Finding

Unconfirmed Global npm Registry Modification

Content
View full analysis

Vulnerability Details

File Location: src/index.ts:109-115, invoked at src/index.ts:349-350
Vulnerability Type: Unapproved persistent environment configuration change
Risk Level: Medium

Vulnerable Code

typescript
export async function setupNpmMirror(): Promise<boolean> {
  try {
    await execAsync('npm config set registry https://registry.npmmirror.com');
    return true;
  } catch {
    return false;
  }
}

Invocation from the main handler:

typescript
// 设置 npm 镜像源
await setupNpmMirror();

Technical Analysis

A matching non-diagnostic message causes the handler to execute npm config set registry without obtaining explicit user consent. Unless npm is configured otherwise, this command changes the user's npm configuration and affects package installations outside the current project.

The previous registry value is not recorded, project-level scope is not specified, and no rollback mechanism is provided. The function also suppresses errors and returns a Boolean that the caller ignores. Consequently, the handler later reports that the registry was successfully configured even if the command failed.

Redirecting package resolution to a third-party mirror expands the software supply-chain trust boundary. Future npm commands may retrieve package metadata and artifacts through that mirror rather than the registry previously selected by the user or organization.

Attack Path

  1. A user submits a message containing one of the broad trigger phrases, such as /win-fix or a matching natural-language phrase.
  2. The handler runs dependency checks and then invokes setupNpmMirror() without requesting confirmation.
  3. npm's configured registry is changed to https://registry.npmmirror.com.
  4. Later npm installations, including installations unrelated to this Skill, use the changed registry.
  5. If the alternate registry or delivery path is compromised, manipulate ...[truncated 422 chars]
Remediation
View remediation

Remediation Suggestions

  1. Obtain explicit user confirmation before changing any npm configuration.
  2. Prefer project-scoped configuration, such as writing a reviewed .npmrc in the selected project, instead of modifying the user's global npm behavior.
  3. Read and preserve the existing registry value before making a change.
  4. Provide a documented and automated rollback option.
  5. Check the result of setupNpmMirror() and never report success when the operation failed.
  6. Allow the user or administrator to supply an approved registry rather than hardcoding a third-party mirror.
  7. Clearly disclose the persistence and scope of the configuration change before execution.

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.ts:226
Finding

Unconditional Overwrite of Files in the Process Working Directory

Content
View full analysis

Vulnerability Details

File Location: src/index.ts:226-231, src/index.ts:352-359
Vulnerability Type: Unsafe filesystem write and unintended file replacement
Risk Level: Medium

Vulnerable Code

typescript
const batPath = join(projectPath, 'install.bat');
const ps1Path = join(projectPath, 'install.ps1');

writeFileSync(batPath, batContent, 'utf-8');
writeFileSync(ps1Path, ps1Content, 'utf-8');

return { batPath, ps1Path };

The destination is selected and the report is written as follows:

typescript
// 生成安装脚本
const projectPath = process.cwd();
const { batPath, ps1Path } = generateInstallScript(projectPath);

// 生成安装报告
const report = generateInstallReport(systemDeps, true);
const reportPath = join(projectPath, 'INSTALL_REPORT.md');
writeFileSync(reportPath, report, 'utf-8');

Technical Analysis

The Skill writes three fixed filenames—install.bat, install.ps1, and INSTALL_REPORT.md—using writeFileSync without first checking whether those paths already exist. The default write behavior truncates and replaces existing files.

Although the documentation advertises a --path option, the handler does not parse it. Instead, it always uses process.cwd(). The optional context parameter is also ignored. This creates a discrepancy between the documented destination and the actual destination, making unintended writes more likely.

There is no destination validation, confirmation prompt, backup, atomic replacement strategy, or exclusive-create flag. If the host invokes the Skill from an unexpected project or privileged working directory, files at those fixed paths can be destroyed or replaced.

Attack Path

  1. The Skill host starts with its working directory set to a project containing an existing install.bat, install.ps1, or INSTALL_REPORT.md.
  2. A user invokes the Skill using a matching trigger and may supply --path, reasonably expecting that argument to ...[truncated 723 chars]
Remediation
View remediation

Remediation Suggestions

  1. Implement real parsing of the documented --path option.
  2. Resolve the requested path canonically and verify that it is an authorized project directory.
  3. Display the resolved destination and request confirmation before writing.
  4. Check for existing files and refuse to overwrite them by default.
  5. Use exclusive creation, such as the wx filesystem flag, where replacement is not explicitly authorized.
  6. If replacement is approved, create timestamped backups and use atomic file replacement.
  7. Return clear per-file errors rather than reporting a successful repair when writes fail.
  8. Add tests covering existing-file handling, invalid paths, relative-path traversal, and --path behavior.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/index.ts:159
Finding

Elevated Execution Guidance for Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: src/index.ts:159-181, src/index.ts:184-216, and user guidance at src/index.ts:384-390
Vulnerability Type: Violation of least privilege during dependency lifecycle execution
Risk Level: High

Vulnerable Code

The generated batch script performs dependency installation:

batch
:: 设置国内镜像源
echo [1/3] 设置 npm 镜像源...
npm config set registry https://registry.npmmirror.com

:: 安装依赖
echo [2/3] 安装项目依赖...
call npm install --verbose

The generated PowerShell script is labeled for administrative execution and also installs dependencies:

powershell
# OpenClaw Windows PowerShell 安装脚本
# 以管理员身份运行

# 设置国内镜像源
Write-Host ""
Write-Host "[1/3] 设置 npm 镜像源..." -ForegroundColor Cyan
npm config set registry https://registry.npmmirror.com

# 安装依赖
Write-Host ""
Write-Host "[2/3] 安装项目依赖..." -ForegroundColor Cyan
npm install --verbose

The handler explicitly directs the user to elevate the generated scripts:

typescript
**方式 1:双击运行脚本**
1. 打开文件资源管理器
2. 找到 \`install.bat\` 或 \`install.ps1\`
3. 右键 → "以管理员身份运行"

Technical Analysis

The generated installers execute npm install, which can run lifecycle hooks such as preinstall, install, and postinstall from the project and its dependencies. The Skill instructs users to launch these scripts as Administrator even though ordinary local dependency installation and user-level npm registry configuration generally do not require administrative privileges.

The scripts do not themselves request elevation, but the generated comments and returned instructions encourage the user to grant it manually. This unnecessarily combines package installation—a supply-chain-sensitive operation—with elevated operating-system privileges.

The scripts use npm install rather than a reproducible installation based strictly on a reviewed lockfile. They also do not disable lifecycle scripts, verify dependency ...[truncated 1465 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions recommending Administrator execution for normal dependency installation.
  2. Add an explicit check that refuses to run package installation under an elevated token unless a separately documented operation genuinely requires it.
  3. Run npm with the least-privileged user account.
  4. Prefer npm ci when a reviewed lockfile is present to improve reproducibility.
  5. Consider a two-stage process using npm ci --ignore-scripts, followed by explicit review and separately authorized execution of required lifecycle steps.
  6. Require confirmation before installing dependencies and display the exact project path and command.
  7. Warn users that npm lifecycle scripts execute code from the project and its dependencies.
  8. Do not combine npm registry modification, dependency installation, and privilege elevation in one generated script.
  9. Correct the documentation that claims automatic elevation, because the implementation only instructs the user to elevate manually.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (22)

Known Vulnerable Dependency: brace-expansion==1.1.13 — 3 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro); CVE-2026-69152 (brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-1)

High
Category
Supply Chain
Confidence
92% confidence
Finding

brace-expansion 1.1.13 is a real outdated package with reported denial-of-service issues involving exponential or unbounded expansion. Even though it is transitive and used in development tooling, algorithmic-complexity flaws can still be triggered if untrusted patterns are accepted by tools or scripts during testing, build, or CI.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.2 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
86% confidence
Finding

browserslist 4.28.2 is flagged for crash/prototype-write and unbounded memory growth issues, making this a credible vulnerable dependency finding. In this repository it is part of the development toolchain rather than runtime code, which reduces but does not eliminate risk if attacker-supplied browserslist queries or stats data are processed in CI or local automation.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==3.14.2 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

js-yaml 3.14.2 has multiple CPU-consumption advisories and is a known high-risk parser when given crafted YAML input. This is a true dependency vulnerability; while it is only used transitively in dev tooling here, YAML parsing bugs are especially relevant in CI and developer environments where configuration files may be attacker-influenced.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

During normal handler execution, the skill both changes npm registry settings and writes multiple files as soon as the trigger matches, with no confirmation barrier. In an agent-skill context, triggerable side effects on package source configuration and filesystem state are especially risky because a user may only be seeking advice, yet the skill performs persistent system changes automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises actions that modify global npm configuration, generate executable installer scripts, and may request administrator privileges, but it does not present a clear upfront warning that running the skill changes system and project state. This can mislead users into executing a 'repair' tool that persists environment changes or introduces privileged scripts without informed consent, increasing the chance of unsafe execution in sensitive Windows environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description highlights convenience features like one-click repair and script generation but does not prominently warn that the skill can modify system configuration, create executable .bat/.ps1 files, change npm registry settings, or request privilege escalation. This omission can mislead users into authorizing the skill without informed consent, making accidental or unsafe execution more likely in a sensitive system-administration context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes activation through broad natural-language phrases such as 'Windows 安装', '修复安装', and '一键安装', which can match common user intent too loosely and trigger a system-modifying workflow unexpectedly. Because the skill is designed to generate installer scripts, change npm mirror configuration, and potentially request elevation, overly broad triggers increase the risk of accidental invocation of actions that alter the host environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly encourages users to generate and then execute local scripts such as install.bat and install.ps1, but it does not include any safety guidance to review script contents, verify provenance, or understand the effects before execution. In an agent setting, this increases the risk of unsafe automation or social engineering, because users may treat generated scripts as trusted and run them without scrutiny.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest lists triggers such as "Windows 安装", "修复安装", and "一键安装", which are generic phrases likely to overlap with ordinary user requests rather than uniquely identifying this specific skill. The trigger list also lacks scope boundaries or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function changes the user's global npm registry configuration by running npm config set registry https://registry.npmmirror.com without prompting, scoping the change to the current project, or clearly disclosing the side effect. This can redirect future package installs to an unintended third-party mirror, affecting software supply-chain trust and potentially breaking unrelated workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The handler writes executable installer scripts and a report into process.cwd() without prior consent or a dry-run mode. Silent file creation in the current directory can overwrite user expectations, introduce executable content that may later be run with elevated privileges, and create side effects simply from invoking the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file defines the communication style entirely in Chinese and instructs the assistant to use fixed expressions and tone, without indicating that the user can choose another language or locale. Under the language/locale policy, forcing one language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @babel/core==7.29.0 — 1 advisory(ies): CVE-2026-49356 (@babel/core: Arbitrary File Read via sourceMappingURL Comment)

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The lockfile pins @babel/core 7.29.0, and the cited advisory describes an arbitrary file read condition tied to processing crafted sourceMappingURL comments. In this package-lock context it is a real vulnerable dependency, though it is a devDependency and the practical risk depends on whether the project processes untrusted JavaScript during build or test steps.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: baseline-browser-mapping==2.10.16 — 1 advisory(ies): CVE-2026-45819 (baseline-browser-mapping process termination on invalid input causes denial of s)

Low
Category
Supply Chain
Confidence
78% confidence
Finding

baseline-browser-mapping 2.10.16 is present in the lockfile and the advisory indicates malformed input can terminate the process, causing denial of service. This appears to be a genuine vulnerable dependency, but it is only a development-time transitive dependency, so exposure is limited unless attacker-controlled input reaches tooling that uses it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The user-facing description, category, tags, and feature names are written entirely in Chinese, with no indication that the skill is region-specific or that users can choose another language. This can violate language/locale policy when a skill implicitly enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"author": "郑宇航",
  "license": "MIT",
  "devDependencies": {
    "@types/jest": "^29.0.0",
    "@types/node": "^20.19.39",
    "jest": "^29.0.0",
    "ts-jest": "^29.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"license": "MIT",
  "devDependencies": {
    "@types/jest": "^29.0.0",
    "@types/node": "^20.19.39",
    "jest": "^29.0.0",
    "ts-jest": "^29.0.0",
    "typescript": "^5.9.3"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"devDependencies": {
    "@types/jest": "^29.0.0",
    "@types/node": "^20.19.39",
    "jest": "^29.0.0",
    "ts-jest": "^29.0.0",
    "typescript": "^5.9.3"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"@types/jest": "^29.0.0",
    "@types/node": "^20.19.39",
    "jest": "^29.0.0",
    "ts-jest": "^29.0.0",
    "typescript": "^5.9.3"
  },
  "clawhub": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 25)May include surrounding context.

json
"@types/node": "^20.19.39",
    "jest": "^29.0.0",
    "ts-jest": "^29.0.0",
    "typescript": "^5.9.3"
  },
  "clawhub": {
    "category": "工具",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The report generation uses toLocaleString('zh-CN'), which hard-codes Chinese locale output regardless of user preference or environment. This is a natural-language policy concern because it imposes a specific locale without opt-in or documented justification in the code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The diagnostic report timestamp is formatted with toLocaleString('zh-CN'), enforcing a Chinese locale for generated output. The file does not provide a user choice or indicate that the skill is restricted to that locale for compliance reasons.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.