T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
MoltGuard appears purpose-aligned as a security plugin, but it asks users to install unaudited external code that can process sensitive agent data and store API credentials with limited scoping details.
Review this before installing. It may send sensitive prompt, command, file-derived, PII, or secret-related security data to a Core service, creates and stores an API key under the user's OpenClaw credentials directory, and installs external plugin code that was not included in this artifact review. Prefer a pinned, verified plugin version, confirm the Core endpoint you trust, and protect or rotate the stored API key as you would any credential.
SKILL.md:19Unpinned Third-Party Plugin Installation Creates a Supply-Chain Risk
SKILL.md:82External Security Processing and Credential Storage Lack Documented Data-Minimization Safeguards
The onboarding flow explicitly states that credentials are saved under ~/.openclaw/credentials/moltguard/ and the claim flow exposes an Agent ID and API Key, but the skill provides no warning about local secret storage, file permission expectations, shared-machine risk, or the sensitivity of account-linking tokens. In a security-focused skill, omission of these warnings is dangerous because users may disclose or leave credentials accessible to other local users or processes.
The enterprise enrollment instructions tell the user to run a local script with a custom Core URL, which changes the service endpoint and therefore trust boundary/network destination, but do not warn about the security implications of redirecting telemetry or enforcement to another server. This is especially risky in a security product because a misconfigured or malicious endpoint could capture data, alter protections, or weaken detection coverage.
The markdown tells the user to run an uninstall script and notes that it removes configuration, plugin files, and credentials, but it does not prominently warn that this is a destructive local operation. For markdown guidance, actions that delete files or credentials should include a clear caution so users understand the impact before proceeding.
No suspicious patterns detected.