Back to skill

Security audit

sense-wonder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent philosophical content package, but users should notice that it installs an unpinned external Python package.

Install this only if you are comfortable running the published sense-wonder Python package. Prefer pinning the reviewed version, such as sense-wonder==0.1.2, and install it in a least-privilege or virtual environment if you want to reduce supply-chain risk.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Python Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:10-13, SKILL.md:25-27, and metadata.json:20-22
Vulnerability Type: Unpinned external dependency
Risk Level: Medium

Vulnerable Code

SKILL.md:10-13:

yaml
install:
  - kind: uv
    package: sense-wonder
    bins: []

SKILL.md:25-27:

bash
pip install sense-wonder

metadata.json:20-22:

json
"install": {
  "pip": "sense-wonder"
},

Technical Analysis

The project directs users and agents to install the externally hosted sense-wonder Python package without an exact version constraint or cryptographic artifact hash. Although the project metadata declares version 0.1.2, none of the installation specifications enforce that version.

Consequently, package resolution depends on the registry contents at installation time. The downloaded artifact can differ from the package that existed when this skill was reviewed. The repository contains no local implementation of the package, so statements such as “Zero dependencies” and “Just data and access functions” cannot be verified from the audited files.

This creates a Python supply-chain risk. If the registry account, package release process, package name, or an indirectly selected build artifact is compromised, package installation may process an attacker-controlled source distribution and its build backend. Subsequent imports may also execute attacker-controlled module initialization code.

No evidence establishes that the current external package is malicious. The finding concerns the unsafe, mutable dependency resolution process.

Attack Path

  1. An attacker compromises the package publisher, release pipeline, or registry-hosted package, or otherwise causes a malicious version to be published under the expected package name.
  2. A user or agent follows the documented pip install sense-wonder instruction, or the OpenClaw installer processes the equivalent ...[truncated 1152 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to the reviewed version in every installation declaration:

    bash
    pip install sense-wonder==0.1.2
    
    yaml
    install:
      - kind: uv
        package: sense-wonder==0.1.2
        bins: []
    
  2. Require cryptographic hashes for approved distribution artifacts, for example through a generated requirements file used with pip install --require-hashes.

  3. Commit a reproducible lock file that records the precise package version, artifact, index source, and any transitive dependencies.

  4. Configure installation to use an explicitly trusted package index rather than permitting unreviewed alternative indexes or dependency sources.

  5. Verify the published wheel and source distribution against the corresponding repository source in CI. Review build-system configuration and import-time behavior before approving each release.

  6. Prefer audited wheels over source distributions where feasible, and disable unnecessary source builds in deployment environments.

  7. Perform installation and execution in a least-privilege sandbox without sensitive credentials, unrestricted filesystem access, or unnecessary network access.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.