Back to skill

Security audit

Opencli Rs

Security checks for vulnerabilities and agentic risk

Overview

This skill is a powerful browser, desktop, and CLI automation package, but its install path and provenance are inconsistent and under-scoped for the level of access it requests.

Review this before installing. Use a disposable browser profile and least-privilege environment, avoid logged-in personal accounts for testing, pin and verify any downloaded installer or binary, avoid npm/global latest installs from the lifecycle script, and require explicit confirmation before any posting, deletion, desktop-control, file-sending, Docker, Kubernetes, or bulk-download action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:38
Finding

Mutable Remote Installation Script Is Executed Directly by a Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38 and 363
Vulnerability Type: Remote code retrieval and execution
Risk Level: Critical

Vulnerable Code

bash
# Automatic installation
curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | sh

The same command is repeated in the update instructions:

bash
# Re-run the installation script
curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | sh

Technical Analysis

The command downloads a shell script from the mutable main branch of an external repository and passes it directly to sh. The downloaded script is not pinned to a reviewed commit, saved for inspection, or validated through a cryptographic checksum or signature.

Consequently, the effective code executed by this Skill can change after the Skill package has been reviewed. HTTPS protects data in transit but does not protect against repository compromise, malicious maintainer changes, account takeover, or an altered upstream script.

Installation requires obtaining software, but pipe-to-shell execution is not the minimum privilege or safest mechanism necessary to accomplish that function.

Attack Path

  1. An attacker compromises the upstream repository or maintainer account, or otherwise modifies main/scripts/install.sh.
  2. A user or AI Agent follows the installation or update instructions.
  3. curl retrieves the modified script.
  4. The pipe sends the script directly to sh without review or integrity verification.
  5. The script executes arbitrary commands with all privileges available to the invoking user.
  6. If the script invokes sudo or is run from a privileged context, the compromise may extend to system-level access.

Impact Assessment

Successful exploitation provides arbitrary code execution as the invoking account. The payload could access user files, browser data, Agen ...[truncated 441 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove all pipe-to-shell installation instructions.
  • Pin the installer to an immutable, reviewed commit rather than main.
  • Download the installer into a temporary file and require inspection before execution.
  • Publish a SHA-256 checksum or signed manifest through an independently authenticated release channel.
  • Verify the checksum or signature before execution.
  • Prefer a reviewed installer shipped inside the Skill package.
  • Run installation with ordinary user privileges and request elevation only for the exact filesystem operation that requires it.
  • Document the precise files and configuration that installation will create or modify.

A safer pattern is:

bash
version="REVIEWED_VERSION"
curl -fL -o install.sh \
  "https://raw.githubusercontent.com/nashsu/opencli-rs/REVIEWED_COMMIT/scripts/install.sh"
printf '%s  %s\n' "EXPECTED_SHA256" install.sh | sha256sum -c -
less install.sh
sh install.sh

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:45
Finding

Unsigned Mutable Release Binary Is Installed into a Privileged Executable Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45-47 and 366-368
Vulnerability Type: Unverified executable retrieval and privileged installation
Risk Level: High

Vulnerable Code

bash
wget https://github.com/nashsu/opencli-rs/releases/latest/download/opencli-rs-x86_64-unknown-linux-musl.tar.gz
tar -xzf opencli-rs-x86_64-unknown-linux-musl.tar.gz
sudo mv opencli-rs /usr/local/bin/

The update instructions repeat the same sequence:

bash
wget https://github.com/nashsu/opencli-rs/releases/latest/download/opencli-rs-x86_64-unknown-linux-musl.tar.gz
tar -xzf opencli-rs-x86_64-unknown-linux-musl.tar.gz
sudo mv opencli-rs /usr/local/bin/

Technical Analysis

The instructions retrieve an executable through the mutable latest release URL and install it into /usr/local/bin. They do not pin a release version, validate a checksum or signature, inspect archive members, or verify the resulting binary.

Installing into /usr/local/bin makes the executable available system-wide and may replace an existing command. The use of sudo gives the final write operation elevated privileges, even though a user-local installation would ordinarily be sufficient for the declared functionality.

Attack Path

  1. An attacker compromises the release process, upstream account, or release artifact.
  2. The mutable latest URL begins serving a malicious archive.
  3. A user downloads and extracts the archive without integrity verification.
  4. The user uses sudo to move the executable into /usr/local/bin.
  5. Future calls to opencli-rs, including calls made by an AI Agent, execute the malicious binary.
  6. The binary operates with the privileges of each invoking user and may exploit its access to authenticated browser sessions and local tools.

Impact Assessment

Exploitation can replace a globally accessible executable with attacker-controlled code. The malicious binary would receiv ...[truncated 483 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace latest with an explicit, immutable release version.
  • Publish detached signatures and checksums for every platform artifact.
  • Verify the artifact before extraction.
  • List and validate archive members before extracting them.
  • Extract into a newly created temporary directory with restrictive permissions.
  • Verify the extracted file type, expected name, ownership, and executable mode.
  • Default to a user-owned directory such as $HOME/.local/bin.
  • Use privileged system-wide installation only after explicit user approval.
  • Refuse to overwrite an existing executable without confirmation and backup.

T08 · Insecure Dependencies

Error
Location
package.json:18
Finding

Unpinned Dependency Is Globally Installed Through an Automatic npm Lifecycle Script

Content
View full analysis

Vulnerability Details

File Location: package.json, lines 18-23; install.sh, lines 20-22; config/agent-integration.md, lines 151-153
Vulnerability Type: Mutable dependency and automatic lifecycle execution
Risk Level: High

Vulnerable Code

package.json declares a mutable dependency and an installation lifecycle script:

json
"dependencies": {
  "@jackwener/opencli": "latest"
},
"scripts": {
  "install": "./install.sh",
  "test": "./examples/basic-usage.sh",
  "collect": "./examples/collect-hot-content.sh",
  "cursor": "./examples/automate-cursor.sh",
  "download": "./examples/download-content.sh"
}

The lifecycle script performs a global installation:

bash
# Install OpenCLI
echo "📦 安装 OpenCLI..."
npm install -g @jackwener/opencli@latest

The Agent integration guide also recommends runtime installation:

bash
# Integrate OpenCLI into a skill
exec "npm install -g @jackwener/opencli"

Technical Analysis

The package resolves @jackwener/opencli through the mutable latest tag. No lockfile was present in the reviewed project, so the exact dependency version and integrity value are not fixed by this artifact.

npm installation automatically invokes the project's install lifecycle script, which starts another npm installation in the global package environment. The installed dependency and its transitive dependencies may execute their own lifecycle scripts. This makes installation non-reproducible and extends trust to future upstream releases that were not part of this audit.

The integration guide additionally encourages an AI Agent to perform package installation during operation. Runtime dependency installation expands the supply-chain attack surface and mixes dependency management with task execution.

Attack Path

  1. An attacker compromises the npm package, maintainer account, publication token, or a transitive dependency.
  2. A malici ...[truncated 962 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin @jackwener/opencli to an exact reviewed version.
  • Commit a package lockfile containing registry-resolved integrity hashes.
  • Review and pin transitive dependencies.
  • Remove the npm install lifecycle script unless automatic execution is strictly necessary.
  • Do not recursively perform a global npm installation from a package lifecycle hook.
  • Keep the dependency local to the project unless a global command is explicitly required.
  • Do not install dependencies dynamically from AI Agent task logic.
  • Use controlled update tooling that reviews version changes, integrity values, and lifecycle scripts.
  • Consider installation with lifecycle scripts disabled during verification, followed by explicit execution of reviewed setup steps.

T09 · Insecure Skill Coding Practices

Error
Location
config/agent-integration.md:194
Finding

Agent Integration Templates Execute Commands from Unstructured Shell Variables

Content
View full analysis

Vulnerability Details

File Location: config/agent-integration.md, lines 194-197, 226-237, 276-284, 325-337, and 397-413
Vulnerability Type: Shell command injection and unsafe argument construction
Risk Level: High

Vulnerable Code

The Agent template constructs a command through unquoted substitutions:

bash
# Invoke from a skill
opencli ${platform} ${command} ${args} -f json

The retry function executes a complete command stored in one variable:

bash
retry_command() {
    local cmd=$1
    local max_retries=3
    
    for i in $(seq 1 $max_retries); do
        if $cmd; then
            return 0
        fi
        echo "重试 $i/$max_retries..."
        sleep 2
    done
    return 1
}

retry_command "opencli bilibili hot --limit 5 -f json"

The concurrent task example also expands unstructured task text:

bash
for task in "${tasks[@]}"; do
    while [ $current_jobs -ge $MAX_CONCURRENT ]; do
        sleep 1
        current_jobs=$(jobs -r | wc -l)
    done
    
    opencli $task &
    ((current_jobs++))
done

Logging and caching helpers execute command strings in the same manner:

bash
log_execution() {
    local command=$1
    local output_file=$2
    
    echo "[$(date)] 执行: $command" >> opencli.log
    $command > "$output_file" 2>> opencli_error.log
    local exit_code=$?
    
    if [ $exit_code -eq 0 ]; then
        echo "[$(date)] 成功: $command" >> opencli.log
    else
        echo "[$(date)] 失败($exit_code): $command" >> opencli.log
    fi
    
    return $exit_code
}
bash
get_cached_or_execute() {
    local cmd=$1
    local cache_key=$(echo "$cmd" | md5sum | cut -d' ' -f1)
    local cache_file="$CACHE_DIR/$cache_key"
    
    if [ -f "$cache_file" ]; then
        local cache_age=$(( $(date +%s) - $(stat -c %Y "$cache_file") ))
        if [ $cache_age -lt $CACHE_TTL ]; then

...[truncated 2524 chars]
Remediation
View remediation

Remediation Suggestions

  • Never store a complete command in a scalar variable and execute it with $cmd or $command.
  • Use fixed executable names and Bash arrays for arguments.
  • Validate the platform and subcommand through exact allowlists.
  • Validate every argument according to its expected type, length, and syntax.
  • Insert -- before positional values where supported to prevent option injection.
  • Do not pass generated command strings through sh -c, bash -c, or eval.
  • Apply authorization at the final execution call, not only during task generation.
  • Maintain separate allowlists for read-only and state-changing commands.
  • Require explicit user confirmation for authenticated posting, deletion, desktop control, Docker, Kubernetes, and external CLI operations.

A safer construction is:

bash
allowed_platforms=(hackernews github arxiv wikipedia)

is_allowed_platform() {
    local candidate=$1
    local allowed
    for allowed in "${allowed_platforms[@]}"; do
        [[ "$candidate" == "$allowed" ]] && return 0
    done
    return 1
}

is_allowed_platform "$platform" || exit 1
cmd=(opencli "$platform" "$subcommand" --limit "$limit" -f json)
"${cmd[@]}"

T08 · Insecure Dependencies

Warning
Location
SKILL.md:1
Finding

Conflicting Project Identities Redirect Installation Across Unrelated Supply Chains

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 1-18 and 38-63; README.md, lines 1-32; QUICK_GUIDE.md, lines 1-35; install.sh, lines 20-22
Vulnerability Type: Inconsistent dependency provenance
Risk Level: Medium

Vulnerable Code

SKILL.md identifies and installs a Rust project from one repository:

yaml
---
name: opencli-rs
description: 基于Rust的通用命令行枢纽 - 将任何网站、桌面应用、本地CLI工具转变为命令行接口,专为AI Agent和自动化工作流设计。支持55+网站、Electron应用控制和外部CLI集成,单二进制文件4.7MB,性能提升12倍。
---
text
**GitHub repository**: https://github.com/nashsu/opencli-rs
bash
curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | sh

The bundled installer instead installs a Node.js package maintained under another identity:

bash
# Install OpenCLI
echo "📦 安装 OpenCLI..."
npm install -g @jackwener/opencli@latest

The README and quick guide identify the Skill and dependency through additional repositories:

bash
git clone https://github.com/smallnest/opencli-skill.git
cd opencli-skill
bash install.sh
text
https://github.com/jackwener/opencli

Technical Analysis

The primary Skill file describes opencli-rs, the bundled installer installs @jackwener/opencli, and the package documentation identifies smallnest/opencli-skill. These identities also differ in executable names, runtime requirements, configuration directories, and daemon ports.

This prevents users from reliably determining which implementation was reviewed and which implementation will execute. It also makes security updates and provenance verification ambiguous. A user following SKILL.md receives different software from a user running the bundled install.sh.

Attack Path

  1. A user trusts the metadata and README for the Node.js OpenCLI integration.
  2. OpenClaw loads SKILL.md, which redirects installation to a separate Rust repository.
  3. Alternatively ...[truncated 886 chars]
Remediation
View remediation

Remediation Suggestions

  • Select one implementation and one authoritative upstream repository.
  • Make SKILL.md, README.md, QUICK_GUIDE.md, package.json, and install.sh consistently identify that implementation.
  • Align the executable name, configuration directory, runtime requirements, extension package, daemon port, and command examples.
  • Remove stale instructions and references to unrelated implementations.
  • State the exact package owner, source repository, release version, and artifact checksum.
  • Add a verification command that confirms the installed executable corresponds to the documented implementation.
  • Publish a clear migration notice if the project has intentionally transitioned from Node.js to Rust.

T09 · Insecure Skill Coding Practices

Warning
Location
examples/download-content.sh:45
Finding

User-Controlled Identifiers Are Embedded in Download Paths Without Traversal Validation

Content
View full analysis

Vulnerability Details

File Location: examples/download-content.sh, lines 45-51, 67-73, and 98-107
Vulnerability Type: Path traversal through unvalidated output directory components
Risk Level: Medium

Vulnerable Code

bash
read -p "📝 输入小红书笔记ID (如 abc123): " note_id
if [ -n "$note_id" ]; then
    mkdir -p xiaohongshu
    echo "⏬ 下载小红书笔记: $note_id"
    opencli xiaohongshu download "$note_id" --output "./xiaohongshu/$note_id" || {
        echo "❌ 下载失败,请检查:"
        echo "   1. Chrome 是否登录小红书"
        echo "   2. 笔记ID是否正确"
        echo "   3. 网络连接"
    }
fi
bash
read -p "📺 输入B站视频BV号 (如 BV1xxx): " bv_id
if [ -n "$bv_id" ]; then
    mkdir -p bilibili
    echo "⏬ 下载B站视频: $bv_id"
    opencli bilibili download "$bv_id" --quality 1080p --output "./bilibili/$bv_id" || {
        echo "❌ 下载失败,可能原因:"
        echo "   1. 需要大会员的高清视频"
        echo "   2. 视频不可用"
        echo "   3. yt-dlp 配置问题"
    }
fi
bash
read -p "👤 输入 Twitter 用户名 (如 elonmusk): " twitter_user
if [ -n "$twitter_user" ]; then
    mkdir -p twitter
    read -p "📊 下载数量 (默认10): " limit
    limit=${limit:-10}
    echo "⏬ 下载 Twitter 用户媒体: @$twitter_user"
    opencli twitter download "$twitter_user" --limit "$limit" --output "./twitter/$twitter_user" || {
        echo "❌ 下载失败,请检查:"
        echo "   1. Chrome 是否登录 Twitter"
        echo "   2. 用户名是否正确"
        echo "   3. 用户是否有公开媒体"
    }
fi

Technical Analysis

Shell quoting prevents these identifiers from being split into separate shell arguments, so this is not direct shell command injection. However, each identifier is concatenated into an output path without validating path separators, .. components, control characters, or a platform-specific identifier format.

A value such as ../../target can produce an output path outside the intended platform directory. Whether an existing file is overwritten depends on the downs ...[truncated 1090 chars]

Remediation
View remediation

Remediation Suggestions

  • Validate every platform identifier against its documented syntax.
  • For simple identifiers, allow only letters, digits, underscores, and hyphens.
  • Reject /, backslashes, .., null bytes, newlines, and control characters.
  • Validate limit as a bounded positive integer.
  • Resolve the canonical destination and confirm it remains beneath the expected base directory.
  • Configure the downstream downloader not to overwrite existing files unless explicitly approved.
  • Generate a safe local directory name independently of untrusted display values.

Example validation:

bash
if [[ ! "$note_id" =~ ^[A-Za-z0-9_-]+$ ]]; then
    echo "Invalid note identifier" >&2
    exit 1
fi

base_dir=$(realpath -m "./xiaohongshu")
destination=$(realpath -m "$base_dir/$note_id")

case "$destination" in
    "$base_dir"/*) ;;
    *)
        echo "Output path escapes the download directory" >&2
        exit 1
        ;;
esac
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (36)

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
### 3. Install Chrome Extension
1. Download `opencli-extension.zip` from [OpenCLI Releases](https://github.com/jackwener/opencli/releases)
2. Open `chrome://extensions`, enable Developer mode
3. Click "Load unpacked extension" and select the extracted folder

## 🚀 Quick Start

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents the skill as the actual OpenCLI product: a Rust-based universal CLI hub with broad website/app/CLI integration. However, the supplied code chunk is only an installer script written in Bash. Its primary behavior is environment checking, npm-based package installation, config/example file creation, and optional dependency detection. This is materially different from the declared primary purpose. The technology claim is also inconsistent: the code installs a Node.js package and requires Node.js 20+, which does not align with a self-contained Rust single-binary implementation. While installer/setup behavior can support the described product, this chunk alone does not implement the declared functionality and contradicts key implementation details.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The shell pipeline curl ... | sh chains remote content retrieval directly into execution, eliminating any opportunity for inspection or integrity verification. In a skill intended for automation and agents, this pattern is especially dangerous because it can be triggered in a high-trust, low-scrutiny environment.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

自动安装 (推荐)

bash
# 使用官方安装脚本
curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | sh

手动安装

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The update path repeats the same remote-fetch-to-shell execution chain, exposing users to arbitrary code execution during maintenance as well as initial install. Re-running such commands over time compounds supply-chain exposure.

Content

Scanner excerpt · SKILL.md (reported line 363)May include surrounding context.

更新到最新版本

bash
# 重新运行安装脚本
curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | sh

# 或手动下载最新版本
wget https://github.com/nashsu/opencli-rs/releases/latest/download/opencli-rs-x86_64-unknown-linux-musl.tar.gz

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

卸载

bash
# 删除二进制文件
sudo rm /usr/local/bin/opencli-rs

# 删除用户配置
rm -rf ~/.opencli-rs/

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

md
sudo rm /usr/local/bin/opencli-rs

# 删除用户配置
rm -rf ~/.opencli-rs/

# 删除Chrome扩展
# 在 chrome://extensions 中移除扩展

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 377)May include surrounding context.

md
sudo rm /usr/local/bin/opencli-rs

# 删除用户配置
rm -rf ~/.opencli-rs/

# 删除Chrome扩展
# 在 chrome://extensions 中移除扩展

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · examples/collect-hot-content.sh (reported line 35)May include surrounding context.

sh
echo "✅ $platform 数据收集成功 ($size bytes)"
        else
            echo "⚠️  $platform 返回数据过小,可能未登录或连接问题"
            rm -f "$OUTPUT_DIR/$filename"
        fi
    else
        echo "❌ $platform 数据收集失败"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide instructs users to clone, install, and enable browser/automation components that can interact with websites and desktop applications, but it does not warn that these actions may exercise privileged access through the user's logged-in browser sessions and local environment. In an agent-skill context, omission of safety boundaries increases the chance of unintended automation, account actions, or system-side effects being triggered without informed user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example scripts for content collection, IDE automation, and downloading demonstrate impactful operations but provide no warning about possible effects on user data, authenticated accounts, rate limits, local files, or application state. Because this skill is designed for AI-agent automation, copy-pasting these examples could cause unattended actions at scale or against sensitive logged-in contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The feature list advertises desktop automation and content download as benefits without clarifying that these capabilities may access local applications, browser-authenticated resources, and user files. In this context, the missing warning is security-relevant because the skill is explicitly meant for agent-driven orchestration, which amplifies the risk of misuse, overbroad access, or accidental exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README promotes desktop automation, application control, and content downloading but does not warn users that these capabilities can affect local applications, send inputs to active desktop sessions, or fetch untrusted content from external sites. In an agent-oriented skill, this omission increases the chance of unsafe use because users may invoke automation on sensitive apps or process downloaded content without understanding the risks.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill clearly instructs use of shell commands including network fetches, installation, process killing, and file deletion, but it does not declare any tool scope or allowed-tools boundary. In an agent setting, missing capability scoping increases the chance the agent will invoke powerful shell actions implicitly and without adequate review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill description and usage guidance are written in Chinese, with no indication that the user can choose another language or that the skill is intentionally region-specific. This creates a natural-language policy issue because it imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documented use of sudo to move a downloaded binary into a system path requires elevated privileges and can turn a compromised download or typo into full-system impact. In agent-driven or copy-paste workflows, privileged install commands are especially risky because users may execute them without careful review.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
# Linux x86_64
wget https://github.com/nashsu/opencli-rs/releases/latest/download/opencli-rs-x86_64-unknown-linux-musl.tar.gz
tar -xzf opencli-rs-x86_64-unknown-linux-musl.tar.gz
sudo mv opencli-rs /usr/local/bin/

# 2. 验证安装
opencli-rs --version

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Using sudo to copy a locally built binary into /usr/local/bin still introduces elevated-risk installation behavior without warnings. If the build context or source repository is compromised, this step grants trusted execution system-wide.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

git clone https://github.com/nashsu/opencli-rs.git cd opencli-rs cargo build --release sudo cp target/release/opencli-rs /usr/local/bin/

text

### Chrome 扩展安装 (用于浏览器命令)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises sensitive actions on third-party services and desktop apps such as posting, deleting, following, blocking, commenting, joining groups, and reading messages, but does not prominently warn about account, privacy, or irreversible action risks. In an AI-agent context, this can lead to unintended account actions, data exposure, or policy violations at scale.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
opencli-rs explore https://example.com

# 自动检测认证策略
opencli-rs cascade https://api.example.com/data

# 一键生成适配器
opencli-rs generate https://example.com --goal "hot posts"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

md
columns: [rank, title, score]

pipeline:
  - fetch: https://api.mysite.com/hot
  - select: data.posts
  - map:
      rank: "${{ index + 1 }}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

"${{ item.tags | join(', ') }}"

字符串插值

"https://api.com/${{ item.id }}.json"

text

### 环境变量

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
82% confidence
Finding

The update instructions again normalize privileged replacement of binaries in a system path. Updating from the network combined with sudo increases the consequences of supply-chain compromise or operator error.

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

或手动下载最新版本

wget https://github.com/nashsu/opencli-rs/releases/latest/download/opencli-rs-x86_64-unknown-linux-musl.tar.gz tar -xzf opencli-rs-x86_64-unknown-linux-musl.tar.gz sudo mv opencli-rs /usr/local/bin/

text

### 卸载

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
72% confidence
Finding

The uninstall command uses sudo to remove a system-installed binary, which is a legitimate administrative task but still deserves caution because it runs with elevated privileges. The risk here is limited to accidental removal or misuse rather than covert compromise.

Content

Scanner excerpt · SKILL.md (reported line 374)May include surrounding context.

卸载

bash
# 删除二进制文件
sudo rm /usr/local/bin/opencli-rs

# 删除用户配置
rm -rf ~/.opencli-rs/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation encourages AI agents to control websites and desktop applications and to download content, but it does not consistently require explicit user consent, scope limitation, or prominent warnings about side effects. In an agent context, this can lead to unintended actions on a user's authenticated sessions or local system because the examples normalize powerful operations as routine automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples show sending prompts and local files to a connected desktop application (opencli cursor send and --file mycode.py) without warning that code or other sensitive content may be transmitted to external software or services. In an AI-agent workflow, this increases the risk of accidental exfiltration of proprietary code, secrets, or personal data through an already-authenticated desktop tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The batch download workflow instructs the agent to bulk-download content into local directories without warning about storage impact, copyright/compliance concerns, or the creation of potentially sensitive local artifacts. In autonomous execution, this can cause excessive file creation, policy violations, or unreviewed retention of downloaded material on the host system.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.