T08 · Insecure Dependencies
- Location
scripts/upgrade.py:47- Finding
Remote Skill Updates Are Installed Without Version or Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This updater is not clearly malicious, but it can bulk-install remote skill updates without an enforced confirmation or integrity check, so it deserves review before use.
Install only if you are comfortable with a skill that can inspect all installed OpenClaw skills and update them through external registries. Avoid --all unless you have reviewed the configured sources, and prefer per-skill updates after checking publisher, version, and changelog manually.
scripts/upgrade.py:47Remote Skill Updates Are Installed Without Version or Integrity Verification
scripts/upgrade.py:124Configuration Slugs Bypass Validation in Bulk Upgrade Mode
The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.
The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.
The document promises a safety workflow of check, notify, obtain confirmation, then upgrade, but it also advertises direct execution paths including bulk upgrade via --all. In an updater skill with shell and network capability, this mismatch is dangerous because operators may rely on the stated confirmation gate even though the exposed command paths enable immediate modification of local installations.
Referenced artifact was not completely inspected
2. **全量字段核对**:`_meta.json`(ownerId / slug / version / publishedAt)+ `SKILL.md`(author / slug / homepage / metadata)全部纳入核对
Referenced artifact was not completely inspected
2. **全量字段核对**:`_meta.json`(ownerId / slug / version / publishedAt)+ `SKILL.md`(author / slug / homepage / metadata)全部纳入核对
The skill declares capabilities to read/write files, use the network, and execute shell commands, but does not define any explicit tool scope or permission boundaries. For an updater skill, this combination is especially risky because it can modify installed skills and fetch remote content, creating a clear path for unintended code execution or supply-chain compromise if the surrounding platform does not enforce least privilege.
Broad trigger phrases like '更新skill' and 'skill更新' increase the chance of accidental activation during normal conversation. In this skill's context, accidental activation is more serious than usual because the skill can inspect local files, access the network, and potentially initiate upgrade-related actions.
Repeating ambiguous trigger examples and extending them with '等' leaves the activation boundary undefined. Given that this skill manages installed skills and writes local state, underspecified triggering can cause unintended scans or preparation steps without a clearly intentional user request.
The top-level docstring presents the skill name, description, and usage entirely in Chinese, with no indication that other languages are supported. This creates a natural-language locale constraint without user opt-in, which matches the policy-violation category for forced language or locale.
The script enumerates both the global skills directory and every workspace-* skills directory under OPENCLAW_HOME, which broadens visibility far beyond a single targeted skill. In a multi-workspace or multi-tenant environment this can expose the existence, metadata, versions, and source hints of unrelated installed skills, violating least-privilege and potentially leaking sensitive local configuration details into the generated report.
Although presented as a check operation, the script persists results to last-report.md and may also write pending-sources.json when unknown skills are found. This creates side effects from a nominally read-only action, which can overwrite prior state, leave audit artifacts, and store metadata about local installations without explicit consent at execution time.
The script persists data to pending-sources.json and later last-report.md, which are file-write operations affecting local state. Although the module docstring explains report generation, there is no comparable disclosure before the pending file write, and the main report write at REPORT_PATH.write_text occurs without any prior user-facing warning or confirmation in code comments or prompts.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
dest = skill_dir(slug)
print(f"[skillhub] 升级 {slug} → {dest}")
try:
result = subprocess.run(
["skillhub", "install", slug],
capture_output=True, text=True, timeout=120
)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""通过 clawhub CLI 升级 clawhub 来源的 skill"""
print(f"[clawhub] 升级 {slug}")
try:
result = subprocess.run(
["clawhub", "install", slug],
capture_output=True, text=True, timeout=120
)
The script supports --all batch upgrades of all skills from the manifest without an explicit per-upgrade confirmation step, which conflicts with the stated behavior of notifying and confirming before upgrade. In a skill-updater context, automatic bulk installation of updated code materially increases supply-chain risk: a compromised registry entry, malicious update, or mistaken source mapping could propagate code changes across all installed skills without user approval.
The skill documentation is written entirely in Chinese, including usage and operational instructions, with no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly justified.
This Python file contains natural-language documentation and user-facing messages entirely in Chinese, including usage and safety notes, without any indication of language selection or opt-in. Under the policy rule for language/locale constraints, this is a natural-language policy issue because it imposes a specific language on all users.
No suspicious patterns detected.