Back to skill

Security audit

Gitcrawl

Security checks for vulnerabilities and agentic risk

Overview

This skill is a focused GitHub triage helper, with one supply-chain caution because its Go tool install uses a mutable latest version.

Before installing, consider pinning or verifying the exact gitcrawl version because @latest can change over time. The skill should be used for GitHub triage with live verification before any mutating action such as labeling, closing, reopening, commenting, reviewing, or merging.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Go Dependency Allows Unreviewed Executable Changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 8-12
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

yaml
install:
  - kind: go
    module: github.com/openclaw/gitcrawl/cmd/gitcrawl@latest
    bins:
      - gitcrawl

Technical Analysis

The installation configuration uses the mutable Go version selector @latest. Consequently, installations performed at different times can resolve to different source revisions without any corresponding change to the reviewed Skill package.

The dependency source is consistent with the declared Gitcrawl project and there is no evidence that its current contents are malicious. However, the lack of an immutable version pin creates a supply-chain risk: an upstream compromise, malicious release, or inadvertently vulnerable future release could cause the installer to build and install code that was not covered by this audit.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, or release process for github.com/openclaw/gitcrawl.
  2. The attacker publishes a new version containing malicious behavior.
  3. A user installs the Skill after that release.
  4. The Go installer resolves @latest to the attacker-controlled version and builds the gitcrawl executable.
  5. The Agent subsequently invokes the installed executable during GitHub issue or pull-request triage.
  6. The compromised executable operates with the privileges and environment available to the Agent process.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user or Agent performing the installation and invocation. Depending on the runtime environment, this could expose local repository data, cached GitHub archives, environment variables, or available GitHub credentials. It could also perform unauthorized filesystem, network, or GitHub operations within the permissions granted to ...[truncated 208 chars]

Remediation
View remediation

Remediation Suggestions

Replace @latest with a specific, audited semantic version or immutable commit reference. Review that exact revision before distribution and update it only through an explicit dependency-review process.

Where supported, verify downloaded module and release integrity using trusted checksums or signatures. Automated dependency updates should produce reviewable changes, run security checks, and require approval before the pinned revision is advanced. Installation documentation should also identify the expected version so operators can verify the resulting binary.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.