T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Mutable Latest Release Executed Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a legitimate Clawhome messaging connector, but its installer runs mutable remote packages and immediately loads an unpinned plugin into OpenClaw.
Review before installing. Use only if you trust the Clawhome package publisher and OpenClaw plugin source, prefer a pinned reviewed version, verify the package/plugin provenance, and treat `channelSecret` like a password. Run the Gateway with least privilege because the installed plugin will persist and process messaging traffic.
SKILL.md:14Mutable Latest Release Executed Through npx
cli.mjs:6Unpinned OpenClaw Plugin Installation and Immediate Gateway Loading
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The skill instructs users to execute an npm package via npx using @latest, which fetches and runs whatever code is currently published under that package name. This creates a supply-chain risk: a compromised maintainer account, malicious update, or dependency hijack could result in arbitrary code execution on the user's system during installation.
The skill instructs users to set a channelSecret credential but provides no warning about secure handling, storage, rotation, or avoiding disclosure in logs, screenshots, and shared shell history. In a messaging integration, exposure of this secret could let an attacker impersonate the agent, send unauthorized actions, or access the associated channel.
The user-facing strings throughout the installer and help output are written only in Chinese, including errors, status messages, and usage instructions. This imposes a specific language on all users without any opt-in, fallback, or indication that the tool is intended only for a Chinese-language audience.
The help text instructs users to run the package via npx -y @clawhome/openclaw-clawhome-cli without pinning a specific version. That means execution will fetch and run whatever version is current at install time, which creates a supply-chain risk if the package is later compromised, maliciously updated, unpublished/replaced, or unexpectedly changed. In this skill context, the command is especially sensitive because the script then performs plugin installation and shell-based command execution on the user's machine.
Detected: suspicious.dangerous_exec