T08 · Insecure Dependencies
- Location
scripts/bundle.js:7- Finding
Unpinned Remote Plugin Installation Creates a Supply-Chain Execution Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to install and configure a security plugin, but it also performs under-disclosed authentication, device fingerprinting, credential persistence, background polling, and risky local command/configuration changes.
Review this skill carefully before installing. It can run local Node.js code, install executable OpenClaw plugin code from an unpinned package, alter OpenClaw configuration, contact a remote Volcengine/Omni Shield service, store login state and API credentials, run a detached polling process, and restart the OpenClaw gateway. Install only if you trust the publisher and are comfortable with the device fingerprinting and credential handling; prefer a version-pinned package with explicit consent and safer secret storage.
scripts/bundle.js:7Unpinned Remote Plugin Installation Creates a Supply-Chain Execution Risk
scripts/bundle.js:2Stable Machine Identifier Is Collected and Transmitted Without Clear Disclosure
scripts/bundle.js:7Shell Command Injection Through Interpolated OpenClaw Configuration
The declared purpose is plugin installation/configuration, but the behavior includes device fingerprint collection, remote login-token handling, credential retrieval/storage, persistent state writes, and gateway restart. This mismatch is dangerous because it can conceal sensitive identity, credential, and system-affecting operations behind an innocuous install description, reducing user scrutiny and bypassing expected trust boundaries.
The skill requires shell and environment access to run Node.js scripts and inspect processes, but it does not declare any tool scope or permissions. This weakens oversight and informed consent, making it easier for a seemingly simple installation skill to execute local code and process inspection without explicit authorization boundaries.
Although presented as an installation/configuration skill, the instructions are dominated by generating a login URL, reading login state, and guiding the user through an authentication flow. This is risky because users may approve the skill expecting local setup, while it actually drives account-linking behavior and accesses authentication artifacts stored on disk.
The skill directs the agent to execute a local Node.js script and run process-inspection commands without warning the user that code will be executed locally and processes will be examined. Running unreviewed local code and inspecting system process state can expose the environment to unintended changes, privacy issues, or abuse if the bundled script performs more than advertised.
The skill instructs 10 minutes of process monitoring and automatic restart of a login-token process based on persisted state values. This exceeds what users would normally expect from a plugin installer and creates persistence-like behavior that can keep network-authentication activity running without fresh user awareness.
The script derives a persistent device fingerprint via machine ID and transmits it to remote login endpoints as an HTTP header. For a skill advertised as local plugin installation and basic configuration, collecting and exporting a host-unique identifier is an unnecessary expansion of scope and creates privacy, tracking, and environment-identification risk if the service is compromised or misused.
A sensitive, stable device fingerprint is sent over the network without any in-code user-facing disclosure or consent step. Even if TLS is used, undisclosed export of host-unique identifiers can enable tracking and may violate user expectations for a local setup helper.
The script stores API key material into plugin configuration after applying reversible local encryption derived from a device fingerprint and static salt, but without clearly warning the user that credentials will be persisted. Silent credential storage increases the chance of unauthorized reuse, accidental disclosure, and weak secret handling assumptions, especially because the protection is not equivalent to secure secret storage.
Beyond installing a plugin, the script orchestrates a remote login flow, polls for identity, writes returned credentials into configuration, and restarts the OpenClaw gateway. This exceeds the declared scope of basic installation/configuration and amplifies trust requirements, since it performs account-linked remote actions and service control on the user's machine.
The code launches a detached background Node process that continues polling a remote service after the main command returns. Detached persistence increases operational risk because it creates long-lived behavior outside the user's immediate control, may continue network activity unexpectedly, and leaves fewer visibility and cleanup guarantees than a foreground, consented workflow.
The skill instructs sending the user a message that asks for confirmation using only Chinese example phrases, which can implicitly steer interaction toward a specific language. There is no opt-in, language choice, or stated reason that the skill must operate in Chinese.
No suspicious patterns detected.