Back to skill

Security audit

Ai Intelligent Demand Forecasting

Security checks for vulnerabilities and agentic risk

Overview

The skill’s forecasting purpose is coherent, but its install instructions tell users to clone and run mutable remote Python code that was not included in the reviewed artifact.

Review the external GitHub repository, pin a specific commit, and install only in an isolated environment before use. Treat forecasting and replenishment outputs as recommendations requiring human approval, especially before any purchasing or inventory changes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:38
Finding

Unpinned Remote Repository and Dependencies Are Installed and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38-41
Vulnerability Type: Unreviewed remote code and insecure dependency installation
Risk Level: High

Complete Code Snippet:

bash
git clone https://github.com/openclaw-skills/ai-intelligent-demand-forecasting
cd ai-intelligent-demand-forecasting
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions clone a mutable external Git repository without selecting a reviewed commit or validating its contents. They then install dependencies from a remotely obtained requirements.txt and execute the remotely obtained app.py.

The audited package does not contain requirements.txt, app.py, a dependency lock file, package hashes, or a pinned repository revision. The effective application and dependency set therefore cannot be verified from the supplied artifact and may change after this skill has been reviewed. Python packages can execute code during installation through build backends or setup logic, while python app.py directly executes the downloaded application.

The repository organization in the clone URL also differs from the author declared in skill.json, which weakens provenance clarity but does not independently prove malicious behavior.

Attack Path

  1. An attacker compromises the referenced repository, gains control of a dependency, or causes unsafe dependency resolution.
  2. The attacker adds malicious behavior to app.py, package installation logic, or a dependency selected by requirements.txt.
  3. A user follows the documented commands and clones the current, mutable repository state.
  4. pip install -r requirements.txt executes malicious package build or installation behavior, or python app.py runs the altered application.
  5. The payload performs actions with the privileges and environmental access of the invoking user.

Impact Assessment

Successful exploitation co ...[truncated 640 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the implementation and dependency manifests in the audited skill package so the executed code can be reviewed with the documentation.
  2. Pin the external repository to a specific, reviewed commit hash rather than cloning and executing its default branch.
  3. Use an exact dependency lock file and require cryptographic hashes for all packages, such as with pip install --require-hashes.
  4. Verify repository provenance and align the documented publisher, repository owner, and author metadata.
  5. Validate downloaded artifacts using trusted signatures or checksums before installation or execution.
  6. Install dependencies inside an isolated virtual environment or container using a non-privileged account.
  7. Restrict filesystem, credential, and network access to the minimum required for forecasting operations.
  8. Review app.py, all transitive dependencies, and package build scripts before permitting execution.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill advertises '自动补货' (automatic replenishment) as a feature without any warning, approval requirement, or explanation of operational safeguards. In an inventory and purchasing context, acting on automated replenishment recommendations can directly affect stock levels, purchasing decisions, and cash flow, so omitting cautionary guidance can lead users to over-trust the output and cause business harm.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The skill content is entirely in Chinese, and the file does not indicate that this is a region-specific skill or provide an opt-in or alternative language, which may amount to an implicit forced locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description is entirely in Chinese ("AI 需求预测 - 销售预测、补货计划"), which signals a language-specific skill experience without stating that language choice is optional or that the skill is intentionally region-specific. The file does not provide any opt-in, alternative language support, or justification for the locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.