T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Unpinned External Code Installation and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent workflow purpose, but it asks users to install and run a mutable external daemon with model credentials and local workspace authority.
Review this before installing. Use a pinned, reviewed ODW commit or release, install in a restricted environment, avoid exposing provider API keys during dependency installation, and run the daemon only for repositories where you are comfortable granting multi-agent workflow authority. Watch for plan.json overwrites in the working directory.
SKILL.md:32Unpinned External Code Installation and Execution
scripts/daemon-bridge.js:61Unconditional Overwrite of Predictable plan.json Path
Referenced artifact was not completely inspected
node scripts/daemon-bridge.js --check
Referenced artifact was not completely inspected
node scripts/daemon-bridge.js --check
Referenced artifact was not completely inspected
node scripts/daemon-bridge.js --check
Referenced artifact was not completely inspected
node scripts/daemon-bridge.js --check
Referenced artifact was not completely inspected
node scripts/daemon-bridge.js --check
The skill advertises operational capabilities that involve environment secrets and network-dependent setup/execution, but it does not declare an explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and informed consent, because an agent may invoke code paths that access sensitive environment data or external resources without a clearly bounded capability contract.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety
- Read-only tools are auto-approved; file writes, shell, and git are approval-gated by ODW's config — never mutate without authorization.
- Model provider keys live in the environment / `~/.odw/config.json`, never in prompts or source.
- Respect the per-workflow token/cost budget.
The code writes a new file to the current working directory with fs.writeFileSync, but there is no confirmation prompt before writing and no user-facing warning in the command usage or surrounding comments that running the plan command will create or overwrite plan.json. For this file, that file write is safety-relevant because it changes user workspace state silently.
Detected: suspicious.potential_exfiltration