Back to skill

Security audit

Openclaw Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent personal finance tracker, but users should be careful with the unpinned external CLI install and the sensitive local finance data it manages.

Install only if you are comfortable adding an external finance CLI to your system and storing personal finance records locally in JSON files. Prefer pinning a reviewed npm version or Git commit, review the package source and lifecycle scripts first, and keep the data directory permissions appropriate for sensitive financial records.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned External Package and Source Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22–33
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable Code

markdown
**Via npm (Recommended)**

```bash
npm install -g openclaw-personal-cfo

Via GitHub

bash
git clone https://github.com/ZhenRobotics/openclaw-personal-cfo.git
cd openclaw-personal-cfo
npm install
npm run build
text

### Technical Analysis

The documented installation procedures retrieve and execute mutable third-party content without pinning a reviewed npm package version, Git commit, dependency lockfile, or integrity digest.

The recommended global npm installation can run package lifecycle scripts and place executable aliases on the user's `PATH`. The alternative procedure clones the repository's mutable default branch, installs its dependency graph, and runs its build scripts. Consequently, the code executed by these commands can change after this Skill artifact has been reviewed.

The external package implementation and dependency manifests are not included in the audited project. Therefore, the claims in `SKILL.md` that the tool stores all data locally and makes no external API or analytics calls cannot be verified from the available artifact. This finding identifies supply-chain exposure rather than establishing that the current external package is malicious.

### Attack Path

1. An attacker compromises the npm package, upstream repository, maintainer account, release process, or a transitive dependency.
2. The attacker publishes a modified release or changes content on the repository's default branch.
3. A user or agent follows the installation instructions in `SKILL.md`.
4. `npm install`, an npm lifecycle script, or `npm run build` executes the attacker-controlled code with the privileges of the installing user.
5. The malicious code can access resources available to that user, including the advertised local financial data, and may alter installed exec
...[truncated 713 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm package to a specific reviewed version rather than installing the latest mutable release.
  2. Pin source installations to a reviewed Git commit hash or signed release tag instead of cloning and building the default branch.
  3. Include a committed lockfile and use reproducible installation commands such as npm ci.
  4. Publish and verify package integrity hashes, signed release artifacts, and npm provenance attestations.
  5. Audit all npm lifecycle and build scripts before execution; use --ignore-scripts when lifecycle scripts are unnecessary.
  6. Prefer a project-local installation over a global installation to reduce PATH exposure and limit unintended system-wide effects.
  7. Bundle the reviewed implementation and dependency metadata with the Skill, or otherwise make them available for the same audit.
  8. Document the exact network behavior and data handling of the CLI, and verify the local-only privacy claims against the pinned source version.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The auto-trigger rules are extremely broad, matching common words like 'money', 'income', 'expense', and 'finance' in ordinary conversation. This can cause the agent to invoke the skill in contexts where the user did not intend financial recordkeeping, increasing the risk of unintended command execution, inappropriate data handling, or privacy-sensitive responses.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

Solution:

bash
mkdir -p ~/openclaw-personal-cfo/data
chmod 755 ~/openclaw-personal-cfo/data

Issue 3: Invalid Category

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file mixes English and Chinese trigger phrases and examples, but does not explain whether multilingual handling is optional, user-selected, or required. Under the stated policy, locale or language behavior should be offered as a choice or explicitly justified when constrained.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.