Back to plugin

Security audit

OpenViking

Security checks for vulnerabilities and agentic risk

Overview

The plugin’s memory features are mostly disclosed and purpose-aligned, but the install skill can run an unpinned npm helper during setup or uninstall.

Review the backup install path before using it. Prefer the normal ClawHub install path, or require a pinned and trusted setup-helper version before allowing the agent to run `npx`. Only install if you are comfortable sending conversation content and selected tool outputs to the configured OpenViking server for long-term memory and retrieval.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/install-openviking-memory/SKILL.md (reported line 552)May include surrounding context.

md
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/install-openviking-memory/SKILL.md (reported line 553)May include surrounding context.

md
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/openviking-context-database/SKILL.md (reported line 203)May include surrounding context.

md
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · skills/openviking-context-database/SKILL.md (reported line 204)May include surrounding context.

md
| `source` | No | Local `SKILL.md` path or skill directory. Exactly one of `source` or `data` is required. |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skills/install-openviking-memory/SKILL.md (reported line 776)May include surrounding context.

md
## Important Rules

1. **Never ask the user to run commands.** You run everything via your shell tool.
2. **Never skip STEP 5 (connectivity check).** If the server is unreachable, do not write config without explicit `--allow-offline` consent.
3. **Never silently use `--force-slot`.** Slot replacement disables another plugin — always confirm with the user first.
4. **Never invent values.** If the user can't provide a required value, stop and tell them what to ask their admin.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill executes npx -y openclaw-openviking-setup-helper@latest, which fetches and runs remote code at install time without pinning to an immutable version. If the package is compromised, replaced, or a malicious update is published, the agent will execute attacker-controlled code with the user's local privileges during plugin installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This invocation again relies on npx with @latest, allowing unreviewed remote package code to run during multi-instance setup. Because the skill is specifically designed for autonomous execution by an agent, the risk is amplified: the agent may run the command without the user understanding that arbitrary code is being pulled from npm in real time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The uninstall path also executes an unpinned remote helper via npx, so even cleanup operations can become a code-execution vector. Attackers often target maintenance or uninstall flows because they may be perceived as lower risk, yet they still grant command execution on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to collect and transmit sensitive values including an API key and potentially tenant identifiers, while also enabling long-term memory features that capture cross-session facts. Without an explicit privacy warning or minimization guidance in the skill description, users may disclose secrets or personal data without understanding what will be sent to the server or retained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions require the agent to respond in Chinese whenever the first user message contains Chinese characters, and otherwise in English. This imposes a language choice automatically rather than offering the user a preference or opt-in, which is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command, suspicious.install_untrusted_source

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL-AGENT.md:329
Evidence
rm -rf ~/.openclaw/extensions/openviking/

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL-ZH.md:424
Evidence
rm -rf ~/.openclaw/extensions/openviking/

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:348
Evidence
rm -rf ~/.openclaw/extensions/openviking/

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
openclaw.plugin.json:79
Evidence
"placeholder": "http://127.0.0.1:1933",