T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:32- Finding
Unpinned Runtime Retrieval and Execution of a Mutable npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This hosting skill matches its stated purpose, but it can automatically publish local directories through mutable npm code with too little confirmation or upload scoping.
Install only if you are comfortable with an agent uploading selected files to a public Ephemo URL. Before use, confirm the exact directory, remove secrets and dotfiles, avoid broad project roots, prefer a clean build output folder, and be aware that cached Ephemo credentials can make deployments permanent.
SKILL.md:32Unpinned Runtime Retrieval and Execution of a Mutable npm Package
SKILL.md:17Public Directory Upload Lacks Mandatory Secret Screening and Explicit Publication Approval
The skill promotes instant publishing but does not present an upfront warning that local files will be made publicly accessible on the internet. Because the skill targets arbitrary directories and automation, the missing disclosure materially increases the risk of accidental data exposure, especially if users assume 'share' means a private or temporary local action.
The skill says to trigger 'universally' for very broad phrases like 'share this', 'publish this', or 'make a website'. In a hosting skill that uploads local directories to a public URL, overbroad activation can cause unintended publication of sensitive files or execution in contexts where the user did not clearly consent to public exposure.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
## How to Contribute
1. **Fork the repo** and create your branch from `main`.
2. **Modify the Skill:** Make your changes strictly within the `ephemo-agent-skill/` directory.
3. **Test it:** If you have OpenClaw installed, point your local workspace to your forked skill to verify the agent follows the new instructions.
4. **Pull Request:** Submit a clear PR description detailing what has improved in the agent's behavior.
The skill explicitly supports automated operation and describes persistent credential state via ~/.ephemo_credentials. In context, this creates session persistence that can silently convert anonymous temporary publishing into authenticated permanent publishing, increasing the risk of unintended durable exposure if the agent reuses cached credentials.
**Skill version: 2.0.0**
Create a live URL from any directory containing static web files. Operations can be fully automated edge-to-edge.
## When to Use
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- Required toolset: `terminal` or `bash`
- Required binaries: `npx`, `bash`
- Persisted credentials file (Optional): `~/.ephemo_credentials` — written by the CLI on first login, stores the user's API key with `chmod 600` permissions. Users can inspect or delete this file at any time.
**[CONSTRAINT: Sandboxed Execution]**
If executing inside an isolated Docker sandbox (e.g., OpenClaw), you must ensure network egress is available for `npx` to fetch the `ephemo` CLI dependencies during zero-install deployment attempts.
The skill repeatedly instructs the agent to execute npx ephemo without pinning an exact package version. That causes runtime code to be fetched from the npm registry at execution time, creating a supply-chain risk where a newly published or compromised package version could run arbitrary code in the agent environment.
This command uses unpinned npx ephemo for update operations, so the agent may download and execute whatever version is current at the time. In an automated deployment skill, that enables registry compromise or malicious package takeover to become arbitrary code execution with access to local files being published.
Listing sites via npx ephemo list still performs code execution from an unpinned registry package. Even though the business action is lower risk than deploy, the installation path can still execute arbitrary code and access persisted credentials such as ~/.ephemo_credentials.
The delete operation uses an unpinned npx ephemo package, exposing the agent to arbitrary code execution before a destructive command runs. Combining dynamic package fetch with deletion increases the blast radius because a compromised package could both exfiltrate credentials and delete or alter hosted assets.
The delete operation is documented as immediately taking a site offline, but the skill does not require any user confirmation or safety check before destructive execution. In an agent setting, ambiguous instructions or mistaken slug selection could lead to irreversible service disruption.
The login flow relies on an unpinned npx ephemo login, which can execute unreviewed registry code during authentication. That is especially sensitive because the flow results in API key handling and persistence to a local credential file, making credential theft a realistic outcome of a supply-chain compromise.
The skill's general guidance to verify success after using npx ephemo still depends on the same unpinned execution model. In context, this is dangerous because the skill is user-invocable and intended for broad use, multiplying opportunities for registry-delivered malicious code to run.
No suspicious patterns detected.