Back to skill

Security audit

sevo-pipeline

Security checks for vulnerabilities and agentic risk

Overview

SEVO’s goal is coherent, but its reviewed package asks for broad agent-orchestration authority and contains unsafe or unverifiable installation behavior.

Review before installing. Treat this as a broad automation plugin that can change OpenClaw configuration and agent prompts, keep pipeline state, route agent work, run probes, and potentially affect releases. Do not run the documented npm/npx commands in an important environment unless the package name is clarified, the version is pinned, the postinstall behavior is removed or auditable, and rollback/disable instructions are provided.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:45
Finding

Unpinned npm Package Resolution and Execution

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 45-49; additional inconsistent package guidance appears in SKILL.md, lines 46-47
Vulnerability Type: Supply-chain risk through mutable and inconsistent npm package references
Risk Level: Medium

Vulnerable Code

README.md:45-49:

bash
## Quick Start

npm install sevo
npx sevo init

SKILL.md:46-47:

markdown
- OpenClaw plugin: installed through `scripts/init.sh`
- Standalone use: call the API after `npm install sevo-pipeline`

Technical Analysis

The installation instructions resolve npm packages without an exact version or integrity constraint. In particular, npx sevo init can resolve and execute the version currently selected by the npm registry rather than a specifically audited release.

The documentation also uses two different package identities: sevo in README.md and sevo-pipeline in SKILL.md. This inconsistency can cause users or automated agents to install an unintended package and increases exposure to package-name confusion or typosquatting.

An npm package can execute local code through its CLI and lifecycle scripts. Consequently, compromise of the mutable registry release, loss of control over one of the referenced names, or publication of a misleading package could turn the documented setup procedure into a local code-execution channel.

No evidence was found that either referenced package is currently malicious. The vulnerability is the unsafe dependency acquisition and execution pattern.

Attack Path

  1. A user or agent follows the documented quick-start procedure.
  2. npm resolves sevo or sevo-pipeline from the configured registry without requiring an audited version.
  3. The registry returns the currently selected release, which may differ from the version represented by this artifact.
  4. npm executes package lifecycle scripts during installation.
  5. npx sevo init executes the re ...[truncated 697 chars]
Remediation
View remediation

Remediation Suggestions

  1. Select and document one canonical npm package name consistently across README.md, SKILL.md, and package.json.

  2. Pin installation and execution to a reviewed release, for example:

    bash
    npm install sevo@1.13.1
    npm exec --package=sevo@1.13.1 -- sevo init
    
  3. Publish package provenance and integrity information, and recommend lockfiles for local dependencies.

  4. Protect npm publication with multi-factor authentication, trusted publishing, and restricted maintainer access.

  5. Avoid automatically executing packages selected only by a mutable tag such as latest.

  6. Verify that the published npm archive exactly matches the reviewed source and generated build artifacts.

  7. Add CI checks that reject inconsistent package names and unpinned executable examples in installation documentation.

T09 · Insecure Skill Coding Practices

Warning
Location
package.json:10
Finding

Automatic Post-Installation Shell Execution References an Absent Script

Content
View full analysis

Vulnerability Details

File Location: package.json, lines 10-15
Vulnerability Type: Unsafe npm lifecycle configuration and unverifiable installation-time execution
Risk Level: Medium

Vulnerable Code

json
"scripts": {
  "build": "tsc && node scripts/copy-assets.js",
  "test": "vitest run",
  "test:fr28-fr29": "vitest run src/scan/__tests__/l3-runtime-verifier.test.ts src/scan/__tests__/tiered-scan-orchestrator.test.ts src/stages/__tests__/clean-install-verification-stage.test.ts",
  "doctor": "node -e \"require('./index.js')\" 2>&1 | head -5",
  "postinstall": "bash scripts/init.sh"
},

Technical Analysis

npm automatically runs postinstall during a normal package installation. This configuration therefore launches Bash without requiring a separate, explicit initialization command or confirmation from the user.

The referenced scripts/init.sh file is absent from the audited artifact. The artifact also lacks other implementation paths referenced by its manifest, including src/, dist/, bin/, and index.js. As a result, the behavior claimed for initialization and plugin registration cannot be audited from the supplied project.

In the artifact as reviewed, the immediate result is expected to be installation failure because Bash cannot find the referenced script. If a registry package or downstream build adds a script under that path, npm will execute that unaudited content automatically during installation. This creates a sensitive supply-chain execution boundary, although no malicious shell implementation was present in the audited files.

Attack Path

  1. A user runs npm install for this package.
  2. npm reaches the lifecycle-script phase and automatically invokes bash scripts/init.sh.
  3. With the supplied artifact, the script is missing and installation fails, causing an availability and onboarding failure.
  4. If distributed package contents differ and inc ...[truncated 844 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the automatic postinstall lifecycle hook and require explicit, consent-based initialization through a documented CLI command.
  2. If a lifecycle script is essential, include scripts/init.sh in the reviewed repository and published archive.
  3. Keep installation-time scripts minimal, deterministic, idempotent, and non-privileged.
  4. Do not modify host configuration, agent prompts, persistent state, or external files during installation without explicit user approval.
  5. Add package-content tests using npm pack --dry-run and clean-environment installation tests to verify that every manifest-referenced file is present.
  6. Compare the published package archive against the reviewed source in CI and fail publication when contents differ.
  7. Provide clear error output rather than silently ignoring absent dependencies or incomplete installation.
  8. Document every file and configuration location modified by initialization and support rollback of those changes.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (54)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · docs/product-requirements.md (reported line 626)May include surrounding context.

md
1. 无硬编码路径(`/root/`、`/home/`、`~/.openclaw/` 等内部路径)。
  2. 无内部引用(内部 agent 名称、内部 API 地址、内部配置键名)。
  3. 无调试残留(`console.log` 调试输出、TODO/FIXME/HACK 注释)。
  4. 无敏感信息(API key、token、密钥文件、.env 文件)。
  5. 依赖声明完整——package.json 的 dependencies 和 peerDependencies 覆盖所有 import,无遗漏无冗余。

**第二层:包完整性**

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The requirements explicitly authorize automatic git reset --hard during the ratchet mechanism. In an agent-driven system, destructive VCS commands are dangerous because a logic error, wrong baseline SHA, or malicious task shaping could cause irreversible loss of uncommitted work or rollback of unrelated changes.

Content

Scanner excerpt · docs/product-requirements.md (reported line 1207)May include surrounding context.

md
1. Implement 阶段开始前,记录基线快照(git commit SHA + 基线指标值)。
  2. 编码 Agent 在时间预算内执行优化实现。
  3. 实现完成后(或时间预算耗尽时),运行关联的可执行评估器,获取优化后的指标值。
  4. 比较优化后指标与基线:改进(指标优于基线)→ 保留变更,提交 commit;退步(指标劣于基线)→ 自动 `git reset --hard` 到基线 SHA,记录回退原因。
  5. 时间预算耗尽且未产出改进 → 回退到基线,标记为「预算内未达成改进」,不视为 pipeline 失败。
  6. 棘轮结果写入 Stage Record,包含基线值、优化后值、是否保留、回退原因(如有)。
- **输出**:棘轮执行结果(Ratchet Result),包含基线快照、优化后指标、保留/回退决定和执行耗时。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This acceptance criterion codifies the same automatic hard-reset behavior as a success condition, increasing the likelihood it will be implemented exactly. In the context of an autonomous coding pipeline, destructive repository operations materially raise integrity and availability risk because the agent may discard valid work beyond the intended optimization scope.

Content

Scanner excerpt · docs/product-requirements.md (reported line 1215)May include surrounding context.

md
- **验收标准**:
  - AC-26.1:项目配置中可为特定工作包启用棘轮模式,配置包含时间预算、基线指标名称和基线值。
  - AC-26.2:棘轮模式启用时,Implement 阶段开始前自动记录基线快照(git commit SHA + 指标值)。
  - AC-26.3:优化后指标优于基线时,变更被保留并提交;劣于基线时,自动 `git reset --hard` 到基线 SHA。
  - AC-26.4:时间预算耗尽且未产出改进时,自动回退到基线,不视为 pipeline 失败,Stage Record 中标记「预算内未达成改进」。
  - AC-26.5:棘轮执行结果纳入 Stage Record 和 Ledger 证据链,包含基线值、优化后值和保留/回退决定。
  - AC-26.6:棘轮模式未启用时,Implement 阶段行为与 FR-05 定义完全一致,无任何副作用。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description is written entirely in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to execute npx sevo, which fetches and runs the latest package version at execution time unless a specific version is pinned. That creates a supply-chain risk: if the package is compromised, typosquatted, or unexpectedly changed, users may execute unreviewed code directly from the registry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and primary documentation are written entirely in Chinese, and the file does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, a skill that effectively enforces a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document gives contradictory semantics for clarification handling: one part says clarification does not block stage execution, while the detailed flow says stages pause when ambiguity exceeds a threshold and later become blocked on timeout. In a pipeline that automates review, implementation, and release gating, such inconsistency can cause unsafe implementations, bypassed controls, or deadlocked workflows depending on which behavior engineers implement.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/arc42-architecture.md (reported line 749)May include surrounding context.

md
│                      │                    │  模式=auto-route  │
 │                      │                    │  classifyLevel()  │
 │                      │                    │  → Level 1        │
 │                      │  { action: create }│                  │
 │                      │◀───────────────────│                  │
 │                      │                    │                  │
 │                      │  createPipeline()  │                  │

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The auto-route mode automatically creates pipelines and injects SEVO labels into tasks without a clearly stated explicit user warning or consent step at the moment behavior is altered. In an agent orchestration environment, transparent task interception and relabeling can materially affect execution flow, audit semantics, and user expectations, making this a real safety concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

sevo init is documented as automatically modifying host configuration (openclaw.json) and writing role SOUL.md files, but the architecture text does not clearly require explicit user confirmation or prominent warning before those writes. Silent mutation of host config and agent prompt files is security-relevant because it changes future agent behavior and plugin loading surfaces, which can surprise users and weaken trust boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document declares that SEVO does not perform code editing, compilation, or test execution, but later defines implement, regression, deploy, and verify stages that do exactly those things through the pipeline. That contradiction creates security-relevant ambiguity about system trust boundaries, making it easier to under-scope permissions, logging, and isolation for code execution and deployment actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The architecture states that review/audit agents have no Edit/Write/Bash access, yet the same document assigns audit-role stages responsibilities that inherently require producing or persisting artifacts such as test cases, reports, or gate outputs. This inconsistency can cause teams to silently relax tool restrictions in production or, conversely, break gate execution and push operators toward ad hoc privilege grants, undermining the intended security boundary around high-trust audit agents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 适用于所有文件类型。该文件从标题到正文均以中文撰写,且未见任何提供语言选择、用户 opt-in,或说明该技能/文档仅适用于特定中文场景的声明;这会构成对特定语言/locale 的默认强制。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.