Back to skill

Security audit

OpenClaw Infer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using the OpenClaw inference CLI, with expected provider and install risks that users should understand before sending private data or installing the package.

Before installing, confirm the `openclaw` npm package and provider configuration are the ones you intend to use. Treat prompts, local files, audio, video, images, and search queries as potentially sent to configured providers, and avoid secrets or regulated data unless you have verified the provider's handling rules.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Global npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 35
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Technical Analysis

The setup instructions recommend globally installing the openclaw npm package without specifying an exact version or integrity constraint:

bash
npm install -g openclaw

Because no version is pinned, npm resolves the package version associated with the current registry tag, normally latest, at installation time. The reviewed skill therefore does not identify an immutable dependency artifact.

npm installation can execute package lifecycle scripts, such as preinstall, install, and postinstall, with the permissions of the user running npm. A compromised package release, compromised maintainer account, registry compromise, or maliciously changed future version could consequently execute code during installation. Global installation also places package files and executable shims into shared user-level or system-level npm locations, increasing the scope of a compromised dependency.

The audited file does not itself contain a malicious payload, and there is no evidence in the reviewed project that the current openclaw package is malicious. The issue is the unsafe, mutable dependency installation method.

Attack Path

  1. An attacker compromises the npm package, its publisher account, release workflow, or relevant registry distribution channel.
  2. The attacker publishes a malicious version under the version selected by the package's default registry tag.
  3. A user follows the skill instructions and runs npm install -g openclaw.
  4. npm downloads the attacker-controlled package because the command does not constrain the version or artifact integrity.
  5. Malicious lifecycle scripts may execute during installation with the invoking user's privileges.
  6. The globally installed openclaw executable may subsequently run attacker-con ...[truncated 684 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a reviewed exact version, for example:
    bash
    npm install -g openclaw@<reviewed-exact-version>
    
  • Update the pinned version only after reviewing its provenance, release notes, dependency changes, and published package contents.
  • Prefer a project-local installation with a committed lockfile over a global installation where the workflow permits it.
  • Use npm provenance and signature verification mechanisms where available, and obtain packages only from the expected registry.
  • Consider installing with lifecycle scripts disabled when compatible with the package:
    bash
    npm install --ignore-scripts openclaw@<reviewed-exact-version>
    
  • Avoid running npm installation commands with sudo or an administrative account.
  • In controlled environments, mirror and approve the exact package artifact internally and enforce integrity hashes or lockfile verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes provider-backed inference operations for text, images, audio, video, web search, and embeddings, but it does not warn that prompts, uploaded files, and search queries may be transmitted to external services. This can cause users or downstream agents to send sensitive data off-host without informed consent, especially because the examples encourage direct use of local files and free-form prompts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.