Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md | `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
Security audit
Security checks for vulnerabilities and agentic risk
The plugin’s memory features are mostly disclosed and purpose-aligned, but the install skill can run an unpinned npm helper during setup or uninstall.
Review the backup install path before using it. Prefer the normal ClawHub install path, or require a pinned and trusted setup-helper version before allowing the agent to run `npx`. Only install if you are comfortable sending conversation content and selected tool outputs to the configured OpenViking server for long-term memory and retrieval.
Referenced artifact was not completely inspected
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
Referenced artifact was not completely inspected
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
Referenced artifact was not completely inspected
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
Referenced artifact was not completely inspected
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Important Rules
1. **Never ask the user to run commands.** You run everything via your shell tool.
2. **Never skip STEP 5 (connectivity check).** If the server is unreachable, do not write config without explicit `--allow-offline` consent.
3. **Never silently use `--force-slot`.** Slot replacement disables another plugin — always confirm with the user first.
4. **Never invent values.** If the user can't provide a required value, stop and tell them what to ask their admin.
The skill executes npx -y openclaw-openviking-setup-helper@latest, which fetches and runs remote code at install time without pinning to an immutable version. If the package is compromised, replaced, or a malicious update is published, the agent will execute attacker-controlled code with the user's local privileges during plugin installation.
This invocation again relies on npx with @latest, allowing unreviewed remote package code to run during multi-instance setup. Because the skill is specifically designed for autonomous execution by an agent, the risk is amplified: the agent may run the command without the user understanding that arbitrary code is being pulled from npm in real time.
The uninstall path also executes an unpinned remote helper via npx, so even cleanup operations can become a code-execution vector. Attackers often target maintenance or uninstall flows because they may be perceived as lower risk, yet they still grant command execution on the host.
The skill instructs the agent to collect and transmit sensitive values including an API key and potentially tenant identifiers, while also enabling long-term memory features that capture cross-session facts. Without an explicit privacy warning or minimization guidance in the skill description, users may disclose secrets or personal data without understanding what will be sent to the server or retained.
The instructions require the agent to respond in Chinese whenever the first user message contains Chinese characters, and otherwise in English. This imposes a language choice automatically rather than offering the user a preference or opt-in, which is a natural-language locale policy issue.
Detected: suspicious.destructive_delete_command, suspicious.install_untrusted_source
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
rm -rf ~/.openclaw/extensions/openviking/
"placeholder": "http://127.0.0.1:1933",