Back to skill

Security audit

OpenCLI Universal CLI Hub

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for turning websites and local tools into CLI commands, but it relies on unverified install paths and logged-in browser access that users should review carefully.

Install only if you trust the OpenCLI publisher and are comfortable giving a CLI plus browser extension access to logged-in website sessions. Prefer a dedicated Chrome profile with only the needed accounts, avoid sensitive accounts, verify the npm package and extension source yourself, and be cautious with commands that may auto-install tools or inspect authenticated web requests.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:10
Finding

Mutable npm Package Installed Globally Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–11
Vulnerability Type: Unpinned global dependency installation
Risk Level: High

Vulnerable Code

yaml
setup: |
  npm install -g @jackwener/opencli@latest

The same mutable installation command is also repeated in the installation instructions at line 25.

Technical Analysis

The skill instructs users to install the @jackwener/opencli npm package globally through the mutable latest distribution tag. Although the metadata elsewhere identifies an installed version, 1.5.9, the actual installation command does not pin that version or verify a package digest or signature.

npm packages may execute lifecycle scripts during installation. Because this package is installed globally, a future package release—or a release published after compromise of the package publisher or registry account—could run attacker-controlled code with the privileges of the user performing the installation. The effective code installed by this instruction can therefore change after the skill has been audited.

No malicious package content is included in the reviewed project, and the audit does not establish that the named package is currently malicious. The vulnerability is the unsafe, mutable dependency acquisition process.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component.
  2. The attacker publishes a malicious package version under the latest distribution tag.
  3. A user follows the skill instructions and runs npm install -g @jackwener/opencli@latest.
  4. npm retrieves the attacker-controlled release.
  5. Malicious lifecycle scripts or package code execute with the installing user's privileges.
  6. The installed global CLI can subsequently access local files, invoke other programs, or abuse browser-connected capabilities when the user runs it.

Impact Assessment

...[truncated 487 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with an exact, reviewed version, such as @jackwener/opencli@1.5.9, after independently validating that release.
  • Publish and verify a cryptographic digest or signed provenance for the expected package artifact.
  • Document the canonical npm registry, package scope, publisher identity, and release source.
  • Avoid elevated privileges during installation and prefer a project-local or isolated installation over a global one.
  • Disable npm lifecycle scripts during initial acquisition where operationally possible, then explicitly review any required scripts before enabling them.
  • Use lockfiles, trusted registries, dependency monitoring, and reproducible release procedures.
  • Ensure every installation example uses the same pinned and verified version.

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Unverified Unpacked Browser Extension Is Granted Access to Authenticated Sessions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 35
Vulnerability Type: Unverified third-party browser component
Risk Level: High

Vulnerable Code

markdown
- **Browser Bridge extension** (download opencli-extension.zip from GitHub Releases → chrome://extensions → Developer mode → Load unpacked)

Technical Analysis

The skill directs users to download an extension archive from an unspecified GitHub Releases location and load it as an unpacked extension in Chrome developer mode. It supplies no canonical repository URL, pinned release version, checksum, signature, extension identifier, manifest permissions, or verification procedure.

Loading an unpacked extension bypasses browser-store review and normal package identity guarantees. The extension is explicitly intended to bridge the CLI with websites where the user is already logged in. Consequently, a substituted or compromised archive could receive browser permissions and interact with authenticated pages, network traffic, or session-bound APIs.

No extension archive or malicious extension implementation is present in the audited project. The confirmed issue is that the documented acquisition and installation process provides no reliable means to authenticate this highly privileged dependency.

Attack Path

  1. An attacker compromises the referenced release channel or causes a user to locate an unofficial repository because no canonical URL is specified.
  2. The attacker distributes a modified archive named opencli-extension.zip.
  3. The user enables Chrome developer mode, extracts the archive, and loads it as an unpacked extension.
  4. Chrome grants the extension its declared permissions.
  5. The malicious extension observes authenticated pages or requests, reads accessible content, or submits actions through the user's existing sessions.
  6. Captured information or unauthorized actions affect the websites and accounts available through the ...[truncated 519 chars]
Remediation
View remediation

Remediation Suggestions

  • Provide the exact canonical repository and release URL rather than referring generically to GitHub Releases.
  • Pin a specific reviewed extension version and publish its SHA-256 digest and a verifiable release signature.
  • Document the expected extension identifier, signing key, archive contents, and manifest permissions.
  • Prefer a signed, verified browser-store distribution when possible.
  • Apply least-privilege permissions, narrow host access to explicitly supported sites, and use optional permissions requested only when needed.
  • Clearly disclose whether the extension can inspect network requests, cookies, headers, or page content.
  • Recommend a dedicated browser profile with only the minimum required accounts logged in.
  • Add a verification step that rejects an archive whose signature or digest does not match the audited release.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:81
Finding

Ordinary CLI Invocation May Automatically Install Unverified Tools

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 81–82
Vulnerability Type: Implicit third-party tool installation
Risk Level: Medium

Vulnerable Code

bash
opencli register mycli           # Register a local CLI for discovery through opencli list
opencli gh pr list               # Automatically detect and install missing tools

Technical Analysis

The documentation states that a normal-looking command can automatically detect and install missing tools. It does not identify the installer, package source, package name, selected version, integrity controls, destination, privilege level, or whether explicit user confirmation is required.

Installation is a security-sensitive operation and should not be an implicit side effect of a command that appears to list pull requests. If dependency resolution selects an attacker-controlled, substituted, or compromised package, installation scripts or the resulting executable may run arbitrary code. Ambiguous package resolution also increases dependency-confusion and tool-spoofing risks.

The reviewed file does not prove that the automatic installer currently retrieves a malicious tool. The issue is the undocumented and potentially non-consensual dependency installation behavior.

Attack Path

  1. The required external executable is absent from the user's environment.
  2. The user invokes opencli gh pr list, expecting a read-only GitHub operation.
  3. OpenCLI enters its automatic installation path.
  4. A compromised source, unsafe resolver, or ambiguous package mapping supplies an attacker-controlled tool.
  5. Installation hooks or the installed executable run with the user's privileges.
  6. The attacker gains access to data available to the process, potentially including local files and GitHub CLI authentication material.

Impact Assessment

Successful exploitation could execute code as the current user, modify user-level files, or steal credenti ...[truncated 287 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not install software implicitly during ordinary operational commands.
  • Fail safely when a dependency is missing and display a separate, explicit installation command.
  • If assisted installation is retained, require informed confirmation showing the exact source, package name, version, digest, destination, and requested privileges.
  • Use an allowlist that maps each supported tool to a canonical publisher and repository.
  • Pin reviewed versions and verify signatures or cryptographic hashes before installation.
  • Provide a strict mode that permanently disables automatic installation.
  • Avoid administrative installation and execute downloaded components in an isolated, least-privileged environment where practical.
  • Log all installation decisions and make package resolution auditable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill markets itself as "Zero risk" while explicitly reusing Chrome login state and enabling account-backed actions across third-party services. This is misleading because authenticated browser reuse can expose private data, perform actions on behalf of the user, and increase the blast radius if the tool or extension is misused or compromised.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

opencli explore https://example.com --site mysite # 发现 API opencli synthesize mysite # 生成 YAML 适配器 opencli generate https://example.com --goal "hot" # 一键生成 opencli cascade https://api.example.com/data # 自动探测认证策略

text

## 退出码

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

Most of the instructional content and command descriptions are written in Chinese, while the file does not offer an explicit language choice or explain that the skill is intended for a Chinese-speaking audience only. The policy calls for flagging language or locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation states that missing tools may be automatically detected and installed, but it does not warn users that running commands can trigger software installation or modification of the local environment. Undisclosed installation behavior can violate user expectations and increase supply-chain and integrity risks, especially in automated agent contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.