Back to skill

Security audit

Super Dev Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a legitimate development-governance workflow, but it exposes broad local command execution and under-documents important installation and network-research risks.

Review this before installing in a sensitive repository. Use it only in an isolated or low-privilege workspace unless the publisher provides pinned package versions, an audited plugin/CLI release, clear restrictions on `super_dev_run`, and privacy guidance for online research. Avoid using it with secrets, proprietary code, or customer data unless you can enforce offline mode and command restrictions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Third-Party Dependencies

Content
View full analysis
`pip install super-dev` → `openclaw plugins install @super-dev/openclaw-plugin` ``` ### Technical Analysis The Skill instructs users to install the executable `super-dev` Python package and the `@super-dev/openclaw-plugin` package without pinning either dependency to an exact version or integrity digest. Consequently, the effective code installed by these commands can change after this Skill has been reviewed. Neither dependency's implementation is included in the audited project. Their installation-time and runtime behavior therefore cannot be verified from this repository. This creates a supply-chain trust boundary in which a compromised publisher account, malicious replacement release, dependency confusion event, or unexpectedly changed upstream version could introduce arbitrary executable behavior. ### Attack Path 1. An attacker compromises an upstream publisher, distribution account, package source, or dependency release process. 2. The attacker publishes a malicious version under the referenced package name. 3. A user follows the Skill's unversioned installation instructions. 4. The package manager resolves the installation to the attacker-controlled or compromised release. 5. Malicious installation hooks or runtime code execute when the package is installed, the plugin is loaded, or its tools are invoked. 6. The payload operates with the permissions of the user running OpenClaw or the installation command. ### Impact Assessment A malicious dependency could potentially: - Read or modify project files available to the in ...[truncated 590 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly exposes super_dev_run as a generic command runner with command: 任意 CLI 命令, which exceeds the stated governance/orchestration scope and enables arbitrary local command execution through the agent-tool boundary. In an agent setting, this can be abused to run destructive shell commands, access sensitive files, install additional tooling, or exfiltrate data, making the surrounding workflow gates ineffective as a security control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill content, trigger instructions, workflow steps, and first-response template are written entirely in Chinese, and the prescribed initial reply at L125-L135 is also fixed in Chinese. This imposes a specific language on users without opt-in or an explicit region-specific justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation presents Super Dev as a governance-only layer while separately claiming the agent performs operational actions, but the tool inventory includes arbitrary CLI execution under Super Dev. This mismatch is dangerous because it can cause reviewers or users to underestimate the tool's execution power and approve a skill that effectively grants broad command execution under the guise of process governance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is written entirely in Chinese and all example prompts are Chinese-language inputs, which implicitly constrains use to a specific language. The policy requires flagging language or locale restrictions unless the skill offers a language choice or clearly documents that the tool is region-specific and why.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all invocation examples require Chinese input ("你的问题") and present the role descriptions exclusively in Chinese. This creates a language policy concern because the skill appears to assume or require a specific language without documenting user choice, opt-in, or a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational instructions, prompts, and confirmation phrases only in Chinese. That can violate language/locale policy when users are not given an explicit language opt-in and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The pipeline explicitly includes online research when not in offline mode, but the documentation provides no warning that user prompts, project details, or proprietary context may be transmitted to external services. In a development-governance skill, this is risky because sensitive business requirements, source context, or customer data could be exposed during the research phase without informed user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.