Back to skill

Security audit

WristClaw - Smartwatch control channel for OpenClaw

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent watch-to-agent channel, but it installs a high-impact external plugin through mutable, unpinned paths that users should review carefully.

Install only if you are comfortable giving a paired watch ongoing access to your OpenClaw agent. Prefer an exact audited package version, verify the package or release hash before global installation, avoid the shell installer unless you inspect it first, and revoke the channel with the documented remove command when no longer needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
skill.md:114
Finding

Unpinned Third-Party Plugin Installed Globally

Content
View full analysis

Vulnerability Details

File Location: skill.md:114
Vulnerability Type: Unpinned third-party dependency and globally scoped installation
Risk Level: Medium

Vulnerable Code

bash
npm install -g @wristclaw/openclaw

The same installation method is recommended again in the security guidance at skill.md:416:

text
Preferred: npm install -g @wristclaw/openclaw

Technical Analysis

The documented command installs the latest version of @wristclaw/openclaw available from the configured npm registry rather than an exact, previously audited version. Consequently, the effective code installed when a user follows these instructions can differ from the code that existed when this Skill was reviewed.

The installation is also global. This gives the downloaded package access within the npm global installation context and makes the plugin available across OpenClaw sessions. A project lockfile does not pin the resolution performed by this direct global installation command.

This is a supply-chain weakness rather than evidence that the current package is malicious. Exploitation would require compromise of the package, its publisher account, the configured registry, or another relevant distribution mechanism.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or package distribution path for @wristclaw/openclaw.
  2. The attacker publishes a malicious package version or modifies a future release to include malicious installation or runtime behavior.
  3. A user follows the Skill instructions and runs npm install -g @wristclaw/openclaw.
  4. npm resolves and downloads the attacker-controlled release because no exact version or independently verified digest is specified.
  5. Package lifecycle code, if present and permitted, can execute during installation. The installed OpenClaw plugin can subsequently execute when loaded by OpenClaw.
  6. The malicious com ...[truncated 733 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the plugin to an exact audited version, for example @wristclaw/openclaw@0.2.0, rather than installing the latest registry release.
  2. Publish and verify a cryptographic digest for the exact package archive before installation. The expected digest should be stored in the reviewed Skill artifact or another authenticated release manifest.
  3. Avoid global installation where possible. Install the dependency in a dedicated, least-privileged plugin directory with a committed lockfile.
  4. Disable npm lifecycle scripts during acquisition when they are not required, inspect the unpacked package, and only then perform the controlled installation.
  5. Run OpenClaw and the plugin under a dedicated non-administrative account with narrowly scoped filesystem and network permissions.
  6. Include the audited plugin source or a verifiable immutable package reference in the reviewed artifact so that the installed implementation can be assessed together with the Skill instructions.
  7. Correct the statement that the direct global installation is pinned by package-manager lockfiles, or replace the command with an installation workflow that actually uses a reviewed lockfile.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

External Script Fetching

High
Category
Supply Chain
Confidence
81% confidence
Finding

The skill includes a shell-based fallback that fetches a remote installer from wristclaw.app. Although it does not auto-execute and requires confirmation, encouraging retrieval of a mutable remote script still creates a supply-chain risk: a compromised domain, CDN, or TLS termination point could deliver a malicious installer that a user later runs.

Content

Scanner excerpt · skill.md (reported line 23)May include surrounding context.

md
label: "Install the WristClaw OpenClaw channel (npm)"
    - id: plugin-script-fallback
      kind: shell
      cmd: "curl -fsSL https://wristclaw.app/install.sh -o /tmp/wristclaw-install.sh && sha256sum /tmp/wristclaw-install.sh && echo 'Inspect /tmp/wristclaw-install.sh, then run: bash /tmp/wristclaw-install.sh'"
      label: "Fetch the installer for review (does NOT auto-execute)"
      requires_confirmation: true
---

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skill.md (reported line 481)May include surrounding context.

md
- [`skill.md`](https://github.com/salam/WristClaw/blob/main/skill.md) — this file

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 24)May include surrounding context.

md
- id: plugin-script-fallback
      kind: shell
      cmd: "curl -fsSL https://wristclaw.app/install.sh -o /tmp/wristclaw-install.sh && sha256sum /tmp/wristclaw-install.sh && echo 'Inspect /tmp/wristclaw-install.sh, then run: bash /tmp/wristclaw-install.sh'"
      label: "Fetch the installer for review (does NOT auto-execute)"
      requires_confirmation: true
---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction says to always reply in the user's detected language, which imposes a language/locale behavior automatically rather than offering the user a choice. The policy allows language constraints only when the skill offers opt-in or the constraint is clearly documented and justified as region-specific; this instruction is neither user-selectable nor region/compliance-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.