Back to skill

Security audit

Ai Humanizer Local

Security checks for vulnerabilities and agentic risk

Overview

The skill largely does what it claims, but it needs review because its developer install path trusts third-party and parent-directory code and its always-on guidance can persistently change agent writing behavior.

Review before installing as a standalone project. Prefer using only the SKILL.md if you need the OpenClaw prompt behavior, and be cautious with npm install, lint, or check until dependencies are regenerated from a trusted registry and the parent-directory ESLint import is removed. Do not use the humanization guidance to hide required AI disclosure or invent personal experience.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
package-lock.json:26
Finding

Development Dependencies Are Resolved Through a Third-Party Package Mirror

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
eslint.config.js:1
Finding

ESLint Configuration Executes JavaScript Outside the Project Boundary

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/cli.js:376
Finding

Untrusted Text Is Written to Interactive Terminals Without Control-Character Sanitization

Content
View full analysis
80 ? '...' : '') : ''; ``` Suggestion reports also include untrusted matched text: ```js lines.push(` ${color.dim(truncate(s.text, 60))}`); ``` Auto-fix mode prints the resulting document without sanitization: ```js if (flags.autofix && result.autofix) { console.log(`\n${color.bold('── AUTO-FIXED TEXT ──────────────────────────────')}\n`); console.log(result.autofix.text); console.log(`\n${color.dim('════════════════════════════════════════════════')}`); } ``` ### Technical Analysis The CLI accepts arbitrary text from stdin or from a user-selected file. Portions of that text are interpolated into terminal reports, and auto-fix mode prints the entire transformed document. The code truncates some previews but does not remove or escape C0/C1 control characters, particularly the ESC byte used to begin ANSI, OSC, and related terminal sequences. When stdout is connected to an interactive terminal, the terminal may interpret embedded control sequences instead of displaying them as text. Depending on terminal capabilities and configuration, crafted input may clear or rewrite visible output, create deceptive hyperlinks, alter terminal state, manipulate window titles, or invoke terminal-specific clipboard features. The project's own color helper intentionally emits ANSI sequences, but it does not distinguish trusted formatting sequences from escape sequences contained in analyzed text. ### Attack Path 1. An attacker supplies a text or Markdown document containing embedded t ...[truncated 1210 chars]
Remediation
View remediation
{ return `\\x${char.charCodeAt(0).toString(16).padStart(2, '0')}`; }); } ``` 3. Apply the sanitizer to `match.match`, `s.text`, suggestions derived from input, error messages containing user-controlled paths, and `result.autofix.text`. 4. Separate trusted ANSI formatting from untrusted content. Sanitize content first, then wrap the sanitized value with trusted color helpers. 5. Disable terminal formatting and escape all controls when stdout is not a TTY. 6. Provide an explicit raw-output option for users who intentionally redirect transformed text to a file; document that raw mode should not be displayed directly in a terminal. 7. Add tests containing CSI, OSC 8 hyperlink, OSC 52 clipboard, carriage return, backspace, and terminal-clear sequences to verify that reports display them as inert text. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
90% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vitest==3.2.4 — 2 advisory(ies): CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The manifest includes vitest 3.2.4, which is flagged as affected by critical advisories involving arbitrary file read and possible execution in Vitest UI/mocking flows. Although this is a devDependency, test tooling is commonly installed and run in developer or CI environments, so exploitation could expose source code, secrets, or compromise build infrastructure.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a natural-language processing skill focused on detecting AI-generated writing patterns and rewriting text. However, the actual code chunk only configures ESLint for JavaScript files and tests. It does not process user text, detect AI-writing traits, rewrite prose, or perform any of the claimed statistical or vocabulary-based analysis. The code’s primary purpose is materially different from the declared purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a substantial natural-language processing capability: detecting AI-like writing patterns and rewriting text to sound more human. The actual code chunk does none of that. It is only a test configuration file for Vitest, specifying test globals and which test files to include. This is a materially different primary purpose and provides no implementation evidence of the claimed text-analysis or rewriting behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
echo "Your text here" | node src/cli.js score

Known Vulnerable Dependency: brace-expansion==1.1.13 — 3 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro); CVE-2026-69152 (brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-1)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.8 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: vite==7.3.1 — 5 advisory(ies): CVE-2026-39365 (Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling); CVE-2026-53571 (vite: `server.fs.deny` bypass on Windows alternate paths); CVE-2026-39363 (Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket) +2 more

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation language is broad enough to match generic writing-help requests, which can cause the skill to trigger when the user did not ask for AI-humanization or stylistic masking. In context, that can silently steer outputs toward concealment of machine-generated provenance and override user intent, especially in compliance, academic, or authenticity-sensitive workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The 'always-on mode' guidance encourages persistent style manipulation without per-request opt-in, effectively changing the agent's default behavior across unrelated tasks. That is dangerous because it can suppress transparency, distort user-requested tone, and facilitate covert evasion of AI-detection or authorship-review controls in contexts where authenticity matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire usage guide is written in Chinese and presents all instructions, examples, and workflow guidance only in that language. Under the policy, a skill that forces a specific language without user opt-in or an explicit justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The summary logic presents AI-authorship conclusions in categorical language such as 'The text looks human-written' and labels like 'heavily AI-generated' without uncertainty qualifiers or explicit user opt-in. In a skill whose purpose is to detect and rewrite 'AI-like' text, this can mislead users into treating a heuristic score as a definitive provenance judgment, enabling false accusations, moderation errors, or deceptive laundering of content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guidance explicitly recommends adding first-person phrasing such as 'I found' or 'In my experience' to make text seem more human. In a humanization skill, that can encourage users to fabricate personal experience, authorship, or firsthand knowledge, which is deceptive and can be especially harmful in professional, academic, journalistic, or compliance-sensitive contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code includes a natural-language locale constraint in its documentation and implementation: syllable estimation is explicitly limited to English and strips non-[a-z] characters. Under the policy, forcing a specific language or locale without user opt-in can be a violation when no alternative or choice is offered.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @humanfs/node==0.16.7 — 1 advisory(ies): GHSA-p498-v437-472g (humanfs: Recursive copy follows symlinked files and copies data from outside the)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: @vitest/mocker==3.2.4 — 1 advisory(ies): CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.