T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned npm Package Execution in Installation Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward CSTCloud search wrapper that sends search terms and the configured API key to the documented provider, with install hygiene as the main caution.
Install this only if you are comfortable sending your search queries to CSTCloud and storing a CSTCloud API key in your OpenClaw environment. Avoid searching for secrets or confidential internal text, and prefer a verified or pinned clawhub installer under a non-administrative account.
SKILL.md:26Unpinned npm Package Execution in Installation Instructions
The skill advertises and requires shell-capable dependencies (bash, curl, jq) and provides executable command examples, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, this weakens least-privilege controls and can let the skill invoke broader shell functionality than users or platform policy expect.
The trigger phrase "帮我搜 xxx" is broad and overlaps with ordinary conversation, making accidental or contextually inappropriate invocation more likely. In an agent setting, ambiguous activation can cause unintended outbound requests, disclosure of sensitive user text to the search API, or tool use when the user only meant casual discussion.
The installation instruction uses npx clawhub without pinning an exact version, which makes installs dependent on whatever package version is current at execution time. This creates a supply-chain risk: a compromised or incompatible upstream release could be fetched and run automatically in the user's environment.
This script performs an outbound HTTPS request containing the user's query and bearer token to a remote service. In the context of an agent skill, external transmission is security-relevant because it can exfiltrate sensitive prompts or internal data if users treat the tool as a general assistant capability rather than a third-party network call.
exit 1
fi
response=$(curl -s --connect-timeout 30 -X POST "$ENDPOINT" \
-H "Authorization: Bearer $API_KEY" \
-H "Content-Type: application/json" \
-d "$(jq -n --arg model "$MODEL" --arg query "$QUERY" --argjson count "$COUNT" \
The script sends the user-provided search query to an external third-party API, but it does not clearly warn the user at runtime that their input will leave the local environment. This matters because search terms may contain sensitive internal, personal, or confidential information, and users invoking a generic 'search' skill may not realize the exact provider receiving the data.
The natural-language description repeatedly frames the skill as intended for domestic Chinese users and emphasizes avoiding foreign APIs, but it does not offer language or locale choice. This can be interpreted as a locale-specific constraint without an explicit user opt-in or clearly documented compliance justification.
Several user-visible messages are only in Chinese, while others are in English, which can make the skill unusable or confusing for users who do not read Chinese. The file does not provide any language selection, opt-in, or justification for enforcing this locale behavior.
No suspicious patterns detected.