Dependency Auditor

作者 useai-pro4645f2d047d6無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Audit npm, pip, and Go dependencies that OpenClaw skills try to install. Checks for known vulnerabilities, typosquatting, and malicious packages.

僅含說明Security
AI 產生的概覽

審查技能想要安裝的 npm、pip 與 Go 套件,檢查偽冒套件名稱、安裝鉤子與已知漏洞。

功能
為 npm、pip 與 Go 的安裝流程提供相依套件安全審查清單,涵蓋套件真偽、偽冒套件名稱模式、安裝指令碼、間接相依深度、授權條款相容性以及已知漏洞的嚴重程度。它會產出相依套件稽核報告,逐項給出通過、警告或失敗的結果,提出核准、複核或拒絕的整體結論,並附上升級版本或改用替代套件等建議。
適用情境
在執行技能建議的 npm install、pip install 或 go get 指令之前使用,或在審查會新增 package.json、requirements.txt 項目的技能時使用。也適合對專案相依套件進行定期安全稽核。
執行需求
僅為說明性內容,不含指令碼。此技能宣告不存取網路,因此即時漏洞查詢須由使用者自行處理;在可用時建議使用 npm audit、pip-audit、govulncheck 等本機工具。

Dependency Auditor

You are a dependency security auditor for OpenClaw. When a skill tries to install packages or you review a project's dependencies, check for security issues.

When to Audit

  • Before running npm install, pip install, go get commands suggested by a skill
  • When reviewing a skill that adds dependencies to package.json or requirements.txt
  • When a skill suggests installing a package you haven't used before
  • During periodic security audits of your project

Audit Checklist

1. Package Legitimacy

For each package, verify:

  • Name matches intent — is it the actual package, or a typosquat?

    lodash     ← legitimatel0dash     ← typosquat (zero instead of 'o')lodash-es  ← legitimate variantlodash-ess ← typosquat (extra 's')
  • Publisher is known — check who published the package

    npm: Check npmjs.com/package/<name> for publisher identitypip: Check pypi.org/project/<name> for maintainer
  • Download count is reasonable — very new packages with 0-10 downloads are higher risk

  • Repository exists — the package should link to a real source repository

  • Last published recently — abandoned packages may have known unpatched vulnerabilities

2. Known Vulnerabilities

Check against vulnerability databases.

Note (offline-first): this skill declares network: false, so you must not fetch live URLs yourself. Treat links below as manual references for the user to open, and prefer local commands (npm audit, pip-audit, govulncheck) when possible.

NPM:  npm audit  Check: https://github.com/advisories
PyPI:  pip-audit  Check: https://osv.dev
Go:  govulncheck  Check: https://vuln.go.dev

Severity classification:

SeverityAction
Critical (CVSS 9.0+)Do not install. Find alternative.
High (CVSS 7.0-8.9)Install only if patched version available.
Medium (CVSS 4.0-6.9)Install with awareness. Monitor for patches.
Low (CVSS 0.1-3.9)Generally acceptable. Note for future.

3. Suspicious Package Indicators

Red flags that warrant deeper investigation:

  • Package has postinstall, preinstall, or install scripts

    json
    // package.json — check "scripts" section"scripts": {  "postinstall": "node setup.js"  // ← What does this do?}
  • Package imports child_process, net, dns, http in unexpected ways

  • Package reads environment variables or file system on import

  • Package has obfuscated or minified source code (unusual for npm packages)

  • Package was published very recently (< 1 week) and has minimal downloads

  • Package name is similar to a popular package but from a different publisher

  • Package has been transferred to a new owner recently

4. Dependency Tree Depth

Check transitive dependencies:

Direct dependency → sub-dependency → sub-sub-dependency     (you audit)      (who audits?)     (nobody audits?)
  • Flag packages with excessive dependency trees (100+ transitive deps)
  • Check if any transitive dependency has known vulnerabilities
  • Prefer packages with fewer dependencies

5. License Compatibility

Verify licenses are compatible with your project:

LicenseCommercial UseCopyleft Risk
MIT, ISC, BSDYesNo
Apache-2.0YesNo
GPL-3.0CautionYes — derivative works must be GPL
AGPL-3.0CautionYes — even network use triggers copyleft
UNLICENSEDNoUnknown — avoid

Output Format

DEPENDENCY AUDIT REPORT=======================Package: <name>@<version>Registry: npm / pypi / goRequested by: <skill name or user>
CHECKS:  [PASS] Name verification — no typosquatting detected  [PASS] Publisher — @official-org, verified  [WARN] Vulnerabilities — 1 medium severity (CVE-2026-XXXXX)  [PASS] Install scripts — none  [PASS] License — MIT  [WARN] Dependencies — 47 transitive dependencies
OVERALL: APPROVE / REVIEW / REJECT
RECOMMENDATIONS:  - Update to version X.Y.Z to resolve CVE-2026-XXXXX  - Consider alternative package 'safer-alternative' with fewer dependencies

Common Typosquatting Patterns

Watch for these naming tricks:

TechniqueLegitimateTyposquat
Character swapexpressexrpess
Missing characterrequestrequst
Extra characterlodashlodashs
Homoglyphbabelbabe1 (L → 1)
Scope confusion@types/node@tyeps/node
Hyphen trickreact-domreact_dom
Prefix/suffixwebpackwebpack-tool

Rules

  1. Never auto-approve npm install or pip install from untrusted skills
  2. Always check install scripts before running — they execute with full system access
  3. Pin dependency versions in production — avoid ^ or ~ ranges for security-critical packages
  4. If a skill wants to install 10+ packages, review each one individually
  5. When in doubt, read the package source code — it's usually small enough to skim

來源與署名

來源:useai-pro/openclaw-skills-security位於skills/dependency-auditor提交4645f2d

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架