T08 · Insecure Dependencies
- Location
package-lock.json:26- Finding
Development Dependencies Are Resolved Through a Third-Party Package Mirror
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill largely does what it claims, but it needs review because its developer install path trusts third-party and parent-directory code and its always-on guidance can persistently change agent writing behavior.
Review before installing as a standalone project. Prefer using only the SKILL.md if you need the OpenClaw prompt behavior, and be cautious with npm install, lint, or check until dependencies are regenerated from a trusted registry and the parent-directory ESLint import is removed. Do not use the humanization guidance to hide required AI disclosure or invent personal experience.
package-lock.json:26Development Dependencies Are Resolved Through a Third-Party Package Mirror
eslint.config.js:1ESLint Configuration Executes JavaScript Outside the Project Boundary
src/cli.js:376Untrusted Text Is Written to Interactive Terminals Without Control-Character Sanitization
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
The manifest includes vitest 3.2.4, which is flagged as affected by critical advisories involving arbitrary file read and possible execution in Vitest UI/mocking flows. Although this is a devDependency, test tooling is commonly installed and run in developer or CI environments, so exploitation could expose source code, secrets, or compromise build infrastructure.
The declared description describes a natural-language processing skill focused on detecting AI-generated writing patterns and rewriting text. However, the actual code chunk only configures ESLint for JavaScript files and tests. It does not process user text, detect AI-writing traits, rewrite prose, or perform any of the claimed statistical or vocabulary-based analysis. The code’s primary purpose is materially different from the declared purpose, so this is a clear mismatch.
The declared description describes a substantial natural-language processing capability: detecting AI-like writing patterns and rewriting text to sound more human. The actual code chunk does none of that. It is only a test configuration file for Vitest, specifying test globals and which test files to include. This is a materially different primary purpose and provides no implementation evidence of the claimed text-analysis or rewriting behavior.
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Referenced artifact was not completely inspected
echo "Your text here" | node src/cli.js score
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Without declared permissions the skill's intent is opaque and cannot be validated.
The activation language is broad enough to match generic writing-help requests, which can cause the skill to trigger when the user did not ask for AI-humanization or stylistic masking. In context, that can silently steer outputs toward concealment of machine-generated provenance and override user intent, especially in compliance, academic, or authenticity-sensitive workflows.
The 'always-on mode' guidance encourages persistent style manipulation without per-request opt-in, effectively changing the agent's default behavior across unrelated tasks. That is dangerous because it can suppress transparency, distort user-requested tone, and facilitate covert evasion of AI-detection or authorship-review controls in contexts where authenticity matters.
The entire usage guide is written in Chinese and presents all instructions, examples, and workflow guidance only in that language. Under the policy, a skill that forces a specific language without user opt-in or an explicit justified locale constraint is a natural-language policy violation.
The summary logic presents AI-authorship conclusions in categorical language such as 'The text looks human-written' and labels like 'heavily AI-generated' without uncertainty qualifiers or explicit user opt-in. In a skill whose purpose is to detect and rewrite 'AI-like' text, this can mislead users into treating a heuristic score as a definitive provenance judgment, enabling false accusations, moderation errors, or deceptive laundering of content.
The guidance explicitly recommends adding first-person phrasing such as 'I found' or 'In my experience' to make text seem more human. In a humanization skill, that can encourage users to fabricate personal experience, authorship, or firsthand knowledge, which is deceptive and can be especially harmful in professional, academic, journalistic, or compliance-sensitive contexts.
This code includes a natural-language locale constraint in its documentation and implementation: syllable estimation is explicitly limited to English and strips non-[a-z] characters. Under the policy, forcing a specific language or locale without user opt-in can be a violation when no alternative or choice is offered.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
No suspicious patterns detected.