Back to skill

Security audit

Event Manager

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local Chinese novel event-management CLI with ordinary project-file writes and dependency hygiene issues, but no hidden data access, exfiltration, or persistence.

Before installing, prefer a virtual environment and pinned or locked dependency versions. Use the file-changing commands only on the intended novel project directory, and be aware that create/export may overwrite chosen output files while delete prompts for confirmation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Versions

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1-2; installation instructions at SKILL.md:12-16 and SKILL.md:136-144
Vulnerability Type: Unpinned and integrity-unverified third-party dependencies
Risk Level: Medium

Vulnerable Code

requirements.txt:1-2:

text
pyyaml>=6.0.1
rich>=13.7.0

SKILL.md:12-16:

bash
cd ~/.openclaw/workspace/skills/event-manager

# Install dependencies
pip3 install -r requirements.txt --user

SKILL.md:136-144:

bash
pip3 install -r requirements.txt --user

The documented dependencies are:

text
pyyaml>=6.0.1
rich>=13.7.0

Technical Analysis

The requirements use open-ended minimum-version constraints. Consequently, installation can resolve to any current or future package release that satisfies the minimum version. The installation instructions do not require cryptographic hashes, a lock file, or an isolated virtual environment.

The package names are consistent with the application's imports and there is no evidence of typosquatting, a suspicious package index, or a currently malicious release. Nevertheless, the dependency policy allows code that was not reviewed with this project to enter the execution environment. Python package installation can execute package build logic, while imported dependency code subsequently executes with the privileges of the user running the event manager.

The use of --user avoids a system-wide installation but still modifies the user's Python environment and grants dependency code access to resources available to that user.

Attack Path

  1. An attacker compromises a qualifying release of pyyaml or rich, its package-index account, or a package mirror configured in the user's environment.
  2. The attacker publishes or serves a malicious version whose number satisfies the open-ended constraint.
  3. A user follows the documented command:
    bash
    pip3 install -r requirements.txt --user
    
  4. pip resolves the ...[truncated 783 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace open-ended constraints with exact, reviewed versions:

    text
    PyYAML==6.0.2
    rich==13.7.1
    

    Select versions based on compatibility and a current vulnerability review rather than copying these illustrative versions without verification.

  2. Generate a reproducible lock file containing hashes for every direct and transitive dependency. Install it with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.lock
    
  3. Install dependencies in an isolated virtual environment rather than the user's shared Python environment:

    bash
    python3 -m venv .venv
    . .venv/bin/activate
    python3 -m pip install --require-hashes -r requirements.lock
    
  4. Configure pip to use a trusted package index or controlled internal mirror and reject unexpected alternative sources.

  5. Add automated dependency vulnerability and provenance checks to the release process. Review and regenerate hashes whenever dependency versions change.

  6. Update SKILL.md so its installation instructions use the locked, hash-verified dependency file and isolated environment.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a fully functional event-management capability for narrative planning, but the actual code does not implement any such behavior. It is a minimal example script whose only effect is printing a placeholder string. There are no undeclared dangerous capabilities, but there is a clear description-to-behavior mismatch because the code lacks the described core functionality.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises commands that create, update, delete, and export files, but the skill manifest does not declare any tool scope such as permissions or allowed-tools. In an agent setting, undocumented file-write capability weakens policy enforcement and increases the risk of unintended or overly broad filesystem modification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and main documentation are written as a Chinese-only skill description, with no indication that users may choose another language or that the restriction is required for a region-specific purpose. Under SQP-3, a language or locale constraint without user opt-in or clear justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented interface includes create, update, delete, and export operations that modify or remove project files, yet it provides no warning about destructive behavior or overwrite risk. In an automated-agent workflow, this can lead to accidental data loss, unsafe writes to user-supplied paths, or unreviewed destructive actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Several user-facing natural-language values are hard-coded in Chinese, including the emotion arc, title, and type fields. This indicates a language constraint in the skill data without any documented user choice or opt-in, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and user-facing descriptions present the skill as a Chinese-language tool, including Chinese-only labels and command help text, with no indication that users may choose another language or locale. This is a natural-language locale constraint embedded in the skill and matches the policy category for forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This YAML manifest contains only Chinese natural-language comments and default text values, which effectively impose a specific language/locale on the skill output or configuration experience. The file does not indicate that Chinese is optional, user-selected, or justified as a region-specific tool, so it conflicts with the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified with a lower bound only, so builds may resolve to different versions over time and across environments. This weakens reproducibility and can unintentionally introduce a vulnerable or breaking release, especially for a package like PyYAML with a history of security advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pyyaml>=6.0.1
rich>=13.7.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

PyYAML has multiple known advisories, and because the manifest does not pin a specific version, there is no assurance that deployed environments will avoid affected releases. In a tool that manages structured event data, YAML may plausibly be used for import/export or configuration, making version ambiguity more concerning if untrusted content is ever processed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The rich package is also unpinned, which means installations are not deterministic and may pull in unexpected future releases. While this is typically a supply-chain hygiene issue rather than an immediately exploitable flaw, it still increases risk and operational instability.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pyyaml>=6.0.1
rich>=13.7.0

Static analysis

No suspicious patterns detected.