Back to skill

Security audit

OmniWire

Security checks for vulnerabilities and agentic risk

Overview

OmniWire is a coherent remote-infrastructure skill, but it grants very broad unattended control over servers, credentials-adjacent data, sync stores, and persistent services without enough scoping or approval guidance.

Install only if you intentionally want an agent to administer remote machines. Pin and review the npm package before installing, avoid root SSH accounts, use least-privilege keys, disable or tightly gate unattended execution, and do not sync agent configs, memory, cookies, TOTP data, or secrets unless you explicitly approve each path and destination.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:70
Finding

Mutable npm Dependency Installed Globally

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19 and SKILL.md:70
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: Medium

Complete Code Snippets

yaml
install:
  - kind: node
    package: omniwire@latest
    bins: ["omniwire", "ow"]
bash
npm install -g omniwire@latest

Technical Analysis

The Skill directs the agent to globally install omniwire@latest. The latest distribution tag is mutable, so the installed artifact can change after this Skill has been reviewed. Neither an exact package version nor an integrity hash is specified.

npm installation may execute package lifecycle scripts. A global installation gives the package access under the privileges of the user running npm and places executable files in a shared command path. The actual npm package is not included in the audited project, which contains only SKILL.md; consequently, its implementation and lifecycle scripts could not be verified.

This is a supply-chain weakness rather than evidence that the current OmniWire release is malicious.

Attack Path

  1. An attacker compromises the npm publisher account, package publication process, or a future release assigned to the latest tag.
  2. The attacker publishes a modified package containing a malicious lifecycle script or executable.
  3. An agent follows the Skill and runs npm install -g omniwire@latest.
  4. npm retrieves the attacker-controlled release and may execute its lifecycle scripts during installation.
  5. The malicious package executes with the installing user's privileges and can persist executable content in globally accessible npm locations.
  6. Subsequent invocations of omniwire or ow execute the compromised implementation.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the account performing the installation. Potential impact incl ...[truncated 647 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace omniwire@latest with an exact, reviewed version in both the metadata and installation command, for example omniwire@3.5.0.
  2. Verify the package archive against a trusted integrity digest or signed provenance before installation.
  3. Inspect package contents and lifecycle scripts before approving a new version.
  4. Initially install with lifecycle scripts disabled, where operationally feasible, and explicitly review any scripts required for functionality.
  5. Avoid global installation where possible. Run the package from an isolated environment, dedicated container, or restricted service account.
  6. Apply least privilege to the installation account and keep administrative SSH credentials unavailable to the package unless required for an explicitly approved operation.
  7. Establish a controlled upgrade process that reviews and pins each new release instead of automatically following the mutable latest tag.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises powerful remote capabilities including command execution, file transfer, firewall management, browser automation, and TOTP/cookie handling, but the introductory description does not prominently warn that these are sensitive and potentially destructive operations. This omission is dangerous because it normalizes broad privileged control and may lead users or calling agents to authorize risky actions without understanding the consequences.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
91% confidence
Finding

The presence of a self-update capability means the skill can modify its own code or operational components after installation. In an already high-privilege infrastructure tool, self-modification increases supply-chain and persistence risk, especially if updates can occur without strong verification and explicit operator approval.

Content

Scanner excerpt · SKILL.md (reported line 453)May include surrounding context.

md
| `omniwire_snippet` | Store and retrieve command snippets. Args: `action`, `name`, `content` |
| `omniwire_tail_log` | Tail last N lines of a log file. Args: `node`, `path`, `lines` |
| `omniwire_trace` | Distributed trace for debugging command chains. Args: `trace_id`, `action` |
| `omniwire_update` | Check for OmniWire updates + self-update. Args: `action` |
| `omniwire_schedule` | Schedule tasks (cron-style). Args: `action`, `schedule`, `task` |
| `omniwire_dns` | DNS lookup and management. Args: `node`, `query`, `type` |
| `omniwire_doctor` | Diagnose OmniWire setup issues. Args: `checks[]` |

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The OpenClaw integration text explicitly says agents can execute tasks across the mesh and persist state without user intervention. For a skill with remote execution and data persistence across multiple nodes and tools, removing the approval boundary significantly increases the risk of unauthorized actions, silent spread, and accidental misuse.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
99% confidence
Finding

The skill explicitly includes syncing Claude Code configuration, memory, and agent directories such as ~/.claude/settings.json and related files. Agent config and memory locations commonly contain secrets, tokens, system prompts, and operational context, so broad sync support for these paths creates a high-risk exfiltration and overexposure channel.

Content

Scanner excerpt · SKILL.md (reported line 614)May include surrounding context.

md
| Tool | Synced Config |
|------|-------------|
| Claude Code | `~/.claude/settings.json`, CLAUDE.md, memory, agents/ |
| OpenCode | `~/.opencode/config.json`, rules/ |
| OpenClaw | `~/.openclaw/config.json`, skills/, agents/ |
| Codex | `~/.codex/config.json` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

The documented sync coverage includes ~/.codex/config.json, which is a sensitive agent configuration path likely to contain tokens, endpoints, or behavior settings. Including this as normal sync material increases the risk that privileged configuration is copied across nodes or persisted into additional storage systems without strong need-to-know controls.

Content

Scanner excerpt · SKILL.md (reported line 617)May include surrounding context.

md
| Claude Code | `~/.claude/settings.json`, CLAUDE.md, memory, agents/ |
| OpenCode | `~/.opencode/config.json`, rules/ |
| OpenClaw | `~/.openclaw/config.json`, skills/, agents/ |
| Codex | `~/.codex/config.json` |
| Gemini | `~/.gemini/settings.json` |
| PaperClip | `~/.paperclip/config.json`, workflows/ |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

The skill also targets ~/.gemini/settings.json, another agent configuration location that may hold secrets or security-relevant preferences. In the broader context of cross-node sync and unified storage, enumerating this path as in-scope materially raises the risk of credential leakage and unintended cross-environment propagation.

Content

Scanner excerpt · SKILL.md (reported line 618)May include surrounding context.

md
| OpenCode | `~/.opencode/config.json`, rules/ |
| OpenClaw | `~/.openclaw/config.json`, skills/, agents/ |
| Codex | `~/.codex/config.json` |
| Gemini | `~/.gemini/settings.json` |
| PaperClip | `~/.paperclip/config.json`, workflows/ |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The setup instructions encourage global installation and immediate remote configuration, including collecting SSH infrastructure details and writing them into a persistent mesh config, while framing execution as something the agent should run and the user should simply approve. That combination reduces informed consent and increases the chance of users enabling broad remote access without appreciating the operational and security risks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The mesh configuration setup creates durable session-like access by storing remote node definitions for future reuse, effectively establishing persistent remote control state. This is not inherently malicious, but it is security-sensitive because it lowers the barrier for subsequent remote operations and concentrates access metadata in one location.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
### Step 2: Configure Your Mesh

Create the mesh config. Ask the user for their server details:

> **AGENT: Ask the user:**
> "What servers do you want to control? For each one I need:

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions direct the agent to solicit sensitive infrastructure details including hostnames, usernames, and SSH key filenames, then persist them in ~/.omniwire/mesh.json. Even if private key material is not directly requested, this still centralizes access metadata and creates a durable target that can assist lateral movement or follow-on compromise if the local machine or config is exposed.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

systemd enable/start/stop capabilities can establish or alter persistent services on remote nodes, which affects state beyond the current session. While such functionality is expected in a DevOps tool, it becomes security-relevant because the same skill can be broadly activated and used for unattended remote operations.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
| `omniwire_process_list` | List and filter processes. Args: `node`, `filter`, `sort` |
| `omniwire_disk_usage` | Disk usage — all mounts or specific path. Args: `node`, `path` |
| `omniwire_install_package` | Install packages via apt/npm/pip/brew. Args: `node`, `package`, `manager` |
| `omniwire_service_control` | systemd start/stop/restart/status/enable. Args: `node`, `service`, `action` |
| `omniwire_docker` | Docker commands (ps, logs, exec, stats, images). Args: `node`, `action`, `container` |
| `omniwire_container` | Container lifecycle — pull, run, stop, rm, inspect. Args: `node`, `action`, `image` |
| `omniwire_kernel` | dmesg, sysctl, modprobe, strace, perf. Args: `node`, `action`, `args` |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation guidance uses very broad triggers like mentions of servers, scraping, browser use, sync, memory, and security tasks, which could cause the agent to invoke this high-privilege skill during ordinary conversation without sufficiently clear user intent. In a skill that can execute remote commands, manage firewalls, access cookies, and persist data, over-broad activation materially increases the chance of unintended sensitive actions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The agent instructions encourage saving user memory and configuration-related content into synchronized knowledge stores spanning CyberBase, Obsidian, and Canvas. That broad persistence surface increases the chance that sensitive data is replicated beyond the user's expectation, making accidental disclosure and over-retention more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Authorizing remote task execution and state persistence without user intervention creates a clear path for unattended collection, modification, and storage of sensitive operational data. In context, the skill includes blackboards, knowledge storage, sync tools, and agent messaging, so this guidance magnifies both data exposure and operational control risks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.