Back to skill

Security audit

Local Model Optimizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with setting up local AI, but its automatic setup can execute an unverified remote installer and change OpenClaw configuration without a clear approval step.

Review this skill before installing. Use its detect or recommend modes first, and avoid the auto setup unless you are comfortable letting it install Ollama, download models, and edit OpenClaw configuration. Prefer manually installing Ollama from a verified source and backing up `~/.openclaw/openclaw.json` before running configuration commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/local-model-optimizer.py:229
Finding

Unverified Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/local-model-optimizer.py:229-234
Vulnerability Type: Unverified remote payload retrieval and shell execution
Risk Level: High

Vulnerable Code:

python
if platform.system() == 'Linux':
    result = subprocess.run(
        ['sh', '-c', 'curl -fsSL https://ollama.com/install.sh | sh'],
        capture_output=True, text=True, timeout=300
    )

Technical Analysis

When the auto command determines that Ollama is absent on Linux, install_ollama() retrieves the current contents of https://ollama.com/install.sh and pipes them directly into sh.

Although the URL belongs to Ollama's declared domain and installing Ollama supports the Skill's setup function, the implementation does not pin an installer version, verify a cryptographic checksum or vendor signature, inspect the downloaded content, or request explicit confirmation immediately before execution. Consequently, the code reviewed in this package is not the complete code that will execute at runtime: the effective payload can change after the audit.

The use of an argument list does not mitigate this issue because sh -c intentionally interprets the pipeline as shell code. A compromise of the vendor distribution endpoint, its deployment pipeline, or the applicable DNS/TLS trust chain could therefore convert this installation step into arbitrary command execution.

This behavior also exceeds the minimum privileges needed for the Skill's detection and recommendation functions. Installation is necessary only for optional automated setup and should use a separately verified, consent-based process.

Attack Path

  1. An attacker compromises or gains influence over the script returned by https://ollama.com/install.sh, or compromises a relevant distribution or network trust component.
  2. A user or Agent runs:
    bash
    python3 scripts/local-model-optimizer.py auto
    
  3. `cmd_auto() ...[truncated 1277 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh pipeline and do not execute network responses directly.
  2. Prefer a trusted operating-system package manager with repository signature verification.
  3. If an upstream artifact must be used:
    • Pin an explicit Ollama release version.
    • Download the artifact to a securely created local file.
    • Verify a vendor-provided cryptographic signature or a trusted, pinned SHA-256 digest.
    • Reject the artifact if verification fails.
    • Execute it only after successful verification.
    • Delete the downloaded file safely when finished.
  4. Prompt for explicit user consent before installing software, clearly identifying the source, version, commands, filesystem changes, and any required privilege elevation.
  5. Do not request or automatically obtain administrative privileges unless a specific installation operation requires them. Keep hardware detection, model recommendation, and configuration operations unprivileged.
  6. Provide manual installation instructions as the default behavior. Consider requiring a dedicated flag such as --install-ollama for automated installation.
  7. After installation, rerun check_ollama() before attempting model operations rather than relying on stale installed and running values.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script automatically installs Ollama by executing a remote installer script without prior confirmation, exposing users to silent system modification and arbitrary code execution if the install endpoint or transport is compromised. In an automation/agent setting, lack of an interactive consent gate materially increases the risk because the action may be triggered as part of a broader workflow.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
100% confidence
Finding

curl -fsSL https://ollama.com/install.sh | sh is a classic high-risk pattern: network-fetched code is executed immediately with no integrity verification, review opportunity, or user confirmation. This is particularly dangerous in a local-setup skill because the declared purpose already encourages privileged host changes, making exploitation highly impactful if the fetched script is tampered with.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 232)May include surrounding context.

python
try:
        if platform.system() == 'Linux':
            result = subprocess.run(
                ['sh', '-c', 'curl -fsSL https://ollama.com/install.sh | sh'],
                capture_output=True, text=True, timeout=300
            )
        elif platform.system() == 'Darwin':

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that can read system information, install software, pull models, and write configuration files, but it declares no explicit tool scope or permissions. This creates an authorization ambiguity where an agent may invoke shell, file read, or file write actions without clear least-privilege boundaries, increasing the risk of unintended local system modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description includes many broad trigger phrases such as 'free AI', 'run AI locally', and 'reduce API costs', which can cause the skill to activate in situations where the user did not intend system-level changes. Because this skill can install software and modify configuration, overbroad invocation materially raises the chance of unexpected shell execution and local file changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents automated installation, model pulling, provider configuration, and hybrid routing setup, but it does not prominently warn users that it will write configuration files and modify local AI tooling. This lack of disclosure increases the risk of users consenting to what appears to be advisory behavior when the skill actually performs persistent system changes.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 78)May include surrounding context.

python
# Try nvidia-smi first (NVIDIA)
    try:
        result = subprocess.run(
            ['nvidia-smi', '--query-gpu=name,memory.total,driver_version',
             '--format=csv,noheader,nounits'],
            capture_output=True, text=True, timeout=10

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 100)May include surrounding context.

python
# Try rocm-smi (AMD)
    if not gpus:
        try:
            result = subprocess.run(
                ['rocm-smi', '--showmeminfo', 'vram', '--json'],
                capture_output=True, text=True, timeout=10
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 121)May include surrounding context.

python
# macOS — Apple Silicon (unified memory acts as VRAM)
    if not gpus and platform.system() == 'Darwin':
        try:
            result = subprocess.run(
                ['sysctl', '-n', 'hw.memsize'],
                capture_output=True, text=True, timeout=5
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 159)May include surrounding context.

python
# macOS — Apple Silicon (unified memory acts as VRAM)
    if not gpus and platform.system() == 'Darwin':
        try:
            result = subprocess.run(
                ['sysctl', '-n', 'hw.memsize'],
                capture_output=True, text=True, timeout=5
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 130)May include surrounding context.

python
# Apple Silicon shares RAM as VRAM — ~75% is usable for ML
                usable_gb = round((total_bytes / (1024**3)) * 0.75, 1)
                # Detect chip name
                chip_result = subprocess.run(
                    ['sysctl', '-n', 'machdep.cpu.brand_string'],
                    capture_output=True, text=True, timeout=5
                )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 216)May include surrounding context.

python
if installed:
        try:
            result = subprocess.run(
                ['ollama', 'list'], capture_output=True, text=True, timeout=10
            )
            running = result.returncode == 0

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

This command executes a remote shell script fetched over the network using curl ... | sh, which gives the remote content immediate code execution on the host. In an agent skill context, this is especially dangerous because the automation may run without the user understanding that arbitrary installer logic from the internet will be executed locally.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 231)May include surrounding context.

python
print("  📥 Installing Ollama...")
    try:
        if platform.system() == 'Linux':
            result = subprocess.run(
                ['sh', '-c', 'curl -fsSL https://ollama.com/install.sh | sh'],
                capture_output=True, text=True, timeout=300
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 236)May include surrounding context.

python
capture_output=True, text=True, timeout=300
            )
        elif platform.system() == 'Darwin':
            result = subprocess.run(
                ['brew', 'install', 'ollama'],
                capture_output=True, text=True, timeout=300
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 259)May include surrounding context.

python
"""Pull a model from Ollama registry."""
    print(f"  📥 Pulling {model_name}... (this may take a while)")
    try:
        result = subprocess.run(
            ['ollama', 'pull', model_name],
            capture_output=True, text=True, timeout=1800  # 30 min timeout for large models
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 278)May include surrounding context.

python
"""Run a quick test prompt against a model."""
    print(f"  🧪 Testing {model_name}...")
    try:
        result = subprocess.run(
            ['ollama', 'run', model_name, 'Say "Hello, I am working!" in exactly those words.'],
            capture_output=True, text=True, timeout=60
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This function rewrites the user's OpenClaw configuration automatically, which can alter model routing behavior and network destinations without an approval step or backup. In an agent skill, silent configuration changes can have downstream security and privacy effects, especially if they redirect prompts or enable local services unexpectedly.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/local-model-optimizer.py (reported line 337)May include surrounding context.

python
"local_tasks": ROUTING_RULES["local_tasks"],
            "cloud_tasks": ROUTING_RULES["cloud_tasks"],
        },
        "timestamp": __import__('datetime').datetime.utcnow().isoformat(),
    }

    os.makedirs(os.path.dirname(CONFIG_PATH), exist_ok=True)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The table labels Phi-3.5 Mini as 'EN-focus', which introduces a language preference in natural-language guidance without offering a user opt-in or explaining a justified region-specific constraint. Under the policy, language or locale constraints should either be optional for the user or clearly documented as necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script writes a configuration artifact into the user's home directory without advance consent. This is low severity, but still a real behavior-risk issue because agent-driven file writes can surprise users, leak environment details into persistent storage, or interfere with existing state.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.