← Back to Skills Marketplace
terrycarter1985

OrderCLI Security Advisory

by terrycarter1985 · GitHub ↗ · v0.1.202605071715 · MIT-0
cross-platform ✓ Security Clean
35
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install ordercli-security-advisory
Description
Security advisory for OrderCLI — 2 high/critical issues found on 2026-05-07T09:15:31Z
README (SKILL.md)

OrderCLI Security Advisory

Date: 2026-05-07T09:15:31Z

Summary

Audit of /root/.openclaw/workspace/ordercli found 2 high/critical issues.

  • 🔴 Critical: 0
  • 🟠 High: 2
  • 🟡 Medium: 2

Findings

  • 🟡 MEDIUM: Some CRUD-like functions lack visible auth checks — manual review recommended
  • 🟠 HIGH: JSON is loaded without schema validation (1 json.load(s) calls, 0 validators)
  • 🟡 MEDIUM: File operations without try/except error handling
  • 🟠 HIGH: orders.json contains 3 PII field(s) — ensure access is restricted

Recommended Actions

  1. Fix all critical issues before any production deployment
  2. Rotate any exposed credentials immediately
  3. Add input validation and parameterized queries
  4. Restrict file permissions on data files containing PII
  5. Re-run audit after fixes: ./run-audit.sh /root/.openclaw/workspace/ordercli

Auto-generated by run-audit.sh

Usage Guidance
Before acting on the advisory, verify it refers to your intended OrderCLI project and review any local audit script before running it. The supplied skill artifacts themselves do not request special access or include executable code.
Capability Analysis
Type: OpenClaw Skill Name: ordercli-security-advisory Version: 0.1.202605071715 The bundle consists of a metadata file and a markdown-based security advisory report (SKILL.md) for a project named OrderCLI. It identifies standard security findings such as missing input validation and PII exposure, and recommends remediation steps. No executable code is included, and the suggested command to re-run an audit script is consistent with the stated purpose of the advisory.
Capability Assessment
Purpose & Capability
The artifact is coherent with its stated purpose: it reports audit findings and remediation advice for an OrderCLI project.
Instruction Scope
Instructions are limited to security remediation guidance and a user-directed audit rerun command; there is no evidence of autonomous execution or goal redirection.
Install Mechanism
There is no install spec and no code files; the skill is instruction-only.
Credentials
The metadata declares no required binaries, environment variables, credentials, config paths, or OS-specific access.
Persistence & Privilege
There is no evidence of persistence, background behavior, credential use, account access, or privilege escalation.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install ordercli-security-advisory
  3. After installation, invoke the skill by name or use /ordercli-security-advisory
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v0.1.202605071715
Initial advisory: 2 high/critical issues
Metadata
Slug ordercli-security-advisory
Version 0.1.202605071715
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is OrderCLI Security Advisory?

Security advisory for OrderCLI — 2 high/critical issues found on 2026-05-07T09:15:31Z. It is an AI Agent Skill for Claude Code / OpenClaw, with 35 downloads so far.

How do I install OrderCLI Security Advisory?

Run "/install ordercli-security-advisory" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is OrderCLI Security Advisory free?

Yes, OrderCLI Security Advisory is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does OrderCLI Security Advisory support?

OrderCLI Security Advisory is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created OrderCLI Security Advisory?

It is built and maintained by terrycarter1985 (@terrycarter1985); the current version is v0.1.202605071715.

💬 Comments