Back to skill

Security audit

Ocli Api

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent but gives an agent broad authenticated API-calling power with limited safety scoping and an unpinned global npm install.

Install only if you are comfortable giving the agent shell-based access to call your chosen APIs. Use trusted OpenAPI specs, least-privilege or read-only tokens where possible, avoid privileged production tokens, review commands before writes or deletions, and consider pinning or locally installing the npm package instead of using an unpinned global install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24 and ISSUE.md:70
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code Snippets

SKILL.md:24:

bash
npm install -g openapi-to-cli

ISSUE.md:70:

bash
npm install -g openapi-to-cli

Technical Analysis

The installation instructions retrieve the current npm release of openapi-to-cli without specifying an exact reviewed version or verifying an integrity digest. Consequently, the package installed by a user can differ from the package that existed when this Skill was audited.

npm packages may contain lifecycle scripts that execute during installation. The global installation option (-g) also places the package and its executable in the user's global npm environment. If a future release or the package's publishing account is compromised, following these instructions could execute unreviewed code with the privileges of the user running npm and replace the globally available ocli executable.

This is a supply-chain weakness rather than evidence that the current openapi-to-cli package is malicious.

Attack Path

  1. An attacker compromises the npm publisher account, release process, or another component of the package's dependency chain.
  2. The attacker publishes a malicious version under the legitimate package name.
  3. A user follows the documented npm install -g openapi-to-cli instruction.
  4. npm resolves the mutable latest version rather than a previously audited version.
  5. Malicious lifecycle scripts can execute during installation, or malicious package code can execute when the agent later invokes ocli.
  6. Because ocli is intended to manage API profiles and issue authenticated API requests, malicious code running in that process could access credentials available to it, alter requests, or disclose API responses.

Impact Assessment

Successful exploitation would provide code execution with the priv ...[truncated 587 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific reviewed version, for example:

    bash
    npm install -g openapi-to-cli@<reviewed-version>
    
  2. Verify the package provenance, publisher identity, release signatures, and expected integrity digest before installation.

  3. Prefer a project-local installation governed by a committed lockfile instead of a global installation where operationally practical.

  4. Use npm ci with a reviewed lockfile in controlled deployments to ensure deterministic dependency resolution.

  5. Disable npm lifecycle scripts during installation with --ignore-scripts if the package functions correctly without them. If scripts are required, review them before execution.

  6. Avoid running npm as root or through sudo; install and execute the CLI under a dedicated, least-privileged account.

  7. Grant API bearer tokens only the minimum scopes required and keep sensitive profiles inaccessible to other local users.

  8. Establish a documented update process in which each new package version and its dependency changes are reviewed before changing the pinned version.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The issue text promotes a skill that can execute arbitrary REST API operations, including authenticated requests, but it does not warn users that commands may transmit sensitive data and can trigger real side effects on external systems. In an agent context, this is risky because discovery and execution are streamlined into a generic shell workflow, increasing the chance of unintended writes, deletions, or data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The onboarding instructions tell users to supply a bearer token for API access without any warning about secret exposure, shell history leakage, token scope, or use with untrusted API specs. Because the skill is designed to convert arbitrary OpenAPI definitions into executable commands, mishandled credentials could be used broadly against external services.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · ISSUE.md (reported line 77)May include surrounding context.

Onboard your first API

ocli profiles add myapi
--api-base-url https://api.example.com
--openapi-spec https://api.example.com/openapi.json
--api-bearer-token "$TOKEN"

text

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · ISSUE.md (reported line 81)May include surrounding context.

--api-bearer-token "$TOKEN"

text

Or manually — copy `skills/ocli-api/SKILL.md` to `~/.openclaw/skills/ocli-api/SKILL.md`.

### Why this belongs in openclaw skills

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs users to configure a bearer token and then execute arbitrary API operations derived from an OpenAPI spec, but it does not warn about data exfiltration, destructive side effects, or the trust boundary of the target API/spec. Because the skill can target any URL or local spec and then invoke matching endpoints, an unsuspecting user or agent could send sensitive credentials and perform state-changing actions against unintended systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.