Back to skill

Security audit

OpenCLI Tool Integration

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides broad control over authenticated websites, desktop apps, and powerful local CLIs, but it does not define safeguards proportional to that access.

Install only if you intentionally want an agent to use your logged-in Chrome sessions, desktop applications, and local CLIs through OpenCLI. Prefer a separate Chrome profile and least-privileged accounts, avoid enabling Docker or Kubernetes access unless needed, review the upstream package and extension before installation, and confirm any write, message-sending, download, or administrative action before allowing it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:51
Finding

Unpinned Third-Party Packages and Browser Extension Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:51-58, SKILL.md:185-190
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Snippets

SKILL.md:51-54:

bash
npm install -g @jackwener/opencli

SKILL.md:56-58 additionally directs the user to download the latest Browser Bridge extension from the project's GitHub Releases page without identifying an immutable release or integrity value.

SKILL.md:185-190:

bash
pip install yt-dlp
# Alternative:
brew install yt-dlp

Technical Analysis

The Skill directs users to install mutable, unpinned versions of OpenCLI, its browser extension, and yt-dlp. It provides no package version constraints, immutable artifact URLs, cryptographic checksums, or signature-verification procedure.

The global npm installation is particularly sensitive because npm installation and lifecycle scripts can execute with the invoking user's privileges. The browser extension is also security-sensitive because OpenCLI is documented as reusing authenticated Chrome sessions. Installing the unspecified “latest” release means the reviewed Skill does not uniquely determine the code that will eventually execute.

This is a supply-chain weakness rather than evidence that the named upstream projects are malicious. Exploitation would require compromise of an upstream package, maintainer account, registry, release process, download channel, or a future unsafe release.

Attack Path

  1. An attacker compromises an upstream maintainer account, package registry entry, GitHub release channel, or another component of the distribution process.
  2. The attacker publishes a malicious package or extension as the current version.
  3. A user follows the Skill and installs the dependency without a version pin or integrity check.
  4. Malicious package lifecycle code, executable code, or browser-extension logic runs locally.
  5. The payload accesses resource ...[truncated 749 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin OpenCLI and yt-dlp to explicitly reviewed versions rather than installing the latest available release.
  2. Provide immutable, official download URLs for the browser extension.
  3. Publish and verify SHA-256 checksums or trusted cryptographic signatures for downloaded artifacts.
  4. Avoid global npm installation where possible; use an isolated project environment, container, or restricted package runner.
  5. Consider disabling npm lifecycle scripts during initial package acquisition and explicitly reviewing required scripts before enabling them.
  6. Document the permissions requested by the browser extension and require users to verify them before installation.
  7. Establish a controlled dependency-update process that reviews release notes, source changes, signatures, and requested permissions before changing pinned versions.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:177
Finding

Overly Broad Access to Authenticated Browser Sessions and Privileged External CLIs

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13, SKILL.md:35-41, SKILL.md:151-175, SKILL.md:177-182
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

Vulnerable Snippets

The Skill states at SKILL.md:13 and SKILL.md:177-182 that browser commands reuse Chrome's existing authenticated state and instructs users to remain logged into target websites.

It also documents direct access to external tools with potentially extensive privileges:

bash
opencli gh pr list --limit 5
opencli docker ps
opencli kubectl get pods

Desktop-application integrations include operations such as:

bash
opencli notion search --query "project"
opencli chatgpt send --message "Hello"
opencli discord-app read

Technical Analysis

The Skill combines several high-authority trust domains behind one command interface:

  • Authenticated Chrome sessions for numerous websites.
  • Desktop applications such as Notion, Discord, ChatGPT, Cursor, and Codex.
  • External CLIs such as GitHub CLI, Docker, and Kubernetes tooling.
  • Automated discovery and installation of external CLI components.

The documentation does not establish a read-only execution mode, command allowlist, per-platform authorization boundary, confirmation requirement for state-changing operations, or separation between low-risk data retrieval and privileged administrative actions.

Docker access can be equivalent to host-level control in common configurations. Kubernetes access can expose cluster resources according to the active context and credentials. GitHub CLI access can act with the permissions of the authenticated GitHub token. Reused browser sessions can allow actions under the user's existing website accounts.

The broad functionality is intentional, but exposing it without documented least-privilege controls creates an authorization risk. A mistaken request, prompt injection originating in r ...[truncated 1966 chars]

Remediation
View remediation

Remediation Suggestions

  1. Separate read-only retrieval commands from mutation and administrative commands.
  2. Require explicit, per-operation user confirmation before sending messages, writing pages, downloading private data, changing remote resources, or invoking Docker and Kubernetes commands.
  3. Implement command and subcommand allowlists; deny arbitrary argument forwarding by default.
  4. Require least-privileged browser profiles, application accounts, GitHub tokens, Docker contexts, and Kubernetes service accounts.
  5. Display the target platform, account, command, arguments, and expected side effects before execution.
  6. Prevent content retrieved from websites or applications from being treated as executable Agent instructions.
  7. Disable automatic installation of external CLIs and require a separately reviewed administrative setup process.
  8. Add audit logging that records authorization decisions and executed operations without recording session cookies, tokens, or other secrets.
  9. Use sandboxed execution for external CLIs and block access to credential stores unless specifically required.
  10. Document clear privilege boundaries and provide a safe default profile that excludes Docker, Kubernetes, desktop-application writes, and authenticated browser mutations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad everyday terms such as '热门', 'opencli', '网站数据', and '社交媒体', which can cause the skill to activate in contexts where the user did not intend to grant broad data-access or local-control capabilities. In this skill, accidental invocation is particularly risky because it can lead to browser-session reuse, desktop app control, and external CLI execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill relies on reusing Chrome login state to access data from many websites, but the description does not clearly foreground the privacy and account-access implications of this design. Because the skill can inherit authenticated sessions, it may access private user data or perform authenticated operations across multiple services if invoked unexpectedly or too broadly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises control over desktop applications and write-capable integrations like Notion, Discord, ChatGPT, and external CLIs, but it does not prominently warn that these actions may send messages, modify content, or operate local tools on the user's machine. This omission increases the chance of users unknowingly authorizing sensitive local or account actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

该技能元数据中的描述整体以中文规定使用场景和触发词,但没有说明是否支持其他语言或允许用户选择语言/locale。按政策要求,若技能在自然语言层面隐含固定语言而未提供选择,属于语言/locale 约束未获用户明确选择的情况。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.