Back to plugin

Security audit

sil

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed shopping plugin that stores sil credentials locally and uses sil services for profile, brief, catalog, and offer workflows.

Install only if you want your agent to use sil as a personal shopping service. Expect browser registration, local credential storage, reads/writes to your sil profile and shopping briefs, and possible operator-run config repair if sil tools are filtered. Review the allowlist helper before running it because it edits OpenClaw configuration.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is extremely broad ('use on any shopping intent'), which can cause the skill to activate in many loosely related conversations and gain access to profile, brief, domain, and seller tools more often than necessary. Overbroad triggering increases the chance of unnecessary data access, unintended tool use, and higher exposure to any unsafe instructions embedded in the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation tells the agent/operator to run local Node.js commands and use absolute paths from the plugin install directory to change tool admission. In an adversarial skill, instructions to execute local commands create a dangerous trust boundary break: they can lead to unauthorized local code execution or unsafe environment modification, especially if the referenced plugin path or script has been tampered with.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document states that name must be "what the thing is called, in English, and there is one," which imposes a fixed language requirement. This is a natural-language locale policy constraint and no opt-in, alternative, or region-specific justification is provided in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.