Back to skill

Security audit

Taskmaster Protocol

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TaskMaster integration, but it guides agents through live wallet, escrow, token approval, and private-key workflows with insufficient guardrails for irreversible financial actions.

Review this skill carefully before installing. Use only a dedicated low-value wallet, avoid pasting private keys or mnemonics into chat or source files, verify chain and contract addresses independently before signing, and require explicit human approval for approvals, deposits, releases, cancellations, and task acceptance. Treat optional related-skill installs as separate packages that need their own review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:624
Finding

Wallet Private Key Embedded Directly in Executable Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 624-648
Vulnerability Type: Plaintext secret handling in source code
Risk Level: High

Vulnerable Code

javascript
const API = 'https://api.taskmaster.tech';
const PRIVATE_KEY = 'your_key';
const TASK_ID = 'cmnge2qj1000k1ykjl704k7a2';
const RPC = 'https://base.publicnode.com'; // fallback

// 1. Login
const wallet = new ethers.Wallet(PRIVATE_KEY);
const challenge = await fetch(`${API}/auth/challenge`).then(r => r.json());
const sig = await wallet.signMessage(`TaskMaster login\nNonce: ${challenge.nonce}`);
const login = await fetch(`${API}/auth/sign-in`, {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({
    walletAddress: wallet.address,
    nonce: challenge.nonce,
    signature: sig
  })
}).then(r => r.json());
const jwt = login.token;

// 2. Get task
const task = await fetch(`${API}/tasks/${TASK_ID}`, {
  headers: { 'Authorization': `Bearer ${jwt}` }
}).then(r => r.json());
const { escrowId, chain, contractAddress } = task;
const chains = await fetch(`${API}/chains`).then(r => r.json());
const chainConfig = chains[chain];

// 3. Accept on-chain
const provider = new ethers.JsonRpcProvider(RPC);
const signer = new ethers.Wallet(PRIVATE_KEY, provider);

The quickstart workflow at SKILL.md:32-47 also documents a remote API response containing a generated wallet private key and mnemonic:

json
{
  "apiKey": "tm_...",
  "wallet": {
    "address": "0x...",
    "privateKey": "0x...",
    "mnemonic": "..."
  },
  "gasDrip": {
    "chains": ["base", "op", "arb"],
    "amount": "0.00001 ETH per chain"
  }
}

Technical Analysis

The executable example instructs users to place a cryptocurrency private key in a plaintext source-code constant. Source files are commonly exposed through version-control commits, backups, logs, support bundle ...[truncated 2100 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the plaintext PRIVATE_KEY constant from all examples.
  • Use a hardware wallet, isolated signing service, encrypted keystore, or operating-system secret manager.
  • If environment variables are demonstrated, clearly state that they are only an improvement over source embedding and may still leak through process inspection, debug output, CI configuration, or shell history.
  • Generate wallets locally with audited software instead of relying on a remote service to generate private keys.
  • Clearly warn users not to place substantial funds in remotely generated wallets.
  • Use a dedicated low-value wallet with only the assets and permissions required for the current task.
  • Never log private keys, mnemonics, signed raw transactions, or bearer tokens.
  • Add secret-scanning controls to repositories and CI pipelines.
  • If exposure is suspected, immediately migrate assets to a newly generated wallet and revoke token allowances associated with the compromised address.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:639
Finding

API-Controlled Contract Addresses Used for Financial Transactions Without Independent Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 639-653
Vulnerability Type: Untrusted transaction-target selection
Risk Level: High

Vulnerable Code

javascript
// 2. Get task
const task = await fetch(`${API}/tasks/${TASK_ID}`, {
  headers: { 'Authorization': `Bearer ${jwt}` }
}).then(r => r.json());
const { escrowId, chain, contractAddress } = task;
const chains = await fetch(`${API}/chains`).then(r => r.json());
const chainConfig = chains[chain];

// 3. Accept on-chain
const provider = new ethers.JsonRpcProvider(RPC);
const signer = new ethers.Wallet(PRIVATE_KEY, provider);
const escrow = new ethers.Contract(contractAddress, [
  'function acceptTask(uint256) external'
], signer);
const acceptTx = await escrow.acceptTask(parseInt(escrowId));

The employer workflow at SKILL.md:228-255 similarly instructs users to approve tokens and create escrow using addresses obtained through the platform workflow:

javascript
const usdc = new ethers.Contract(USDC_ADDRESS, [
  'function approve(address spender, uint256 amount) returns(bool)'
], wallet);

const approveTx = await usdc.approve(CONTRACT_ADDRESS, totalDeposit);
await approveTx.wait();

const escrow = new ethers.Contract(CONTRACT_ADDRESS, [
  'function createEscrow(address token, uint256 maxCompensation, uint256 deadline) external payable returns (uint256)'
], wallet);

const tx = await escrow.createEscrow(
  USDC_ADDRESS,
  maxCompensation,
  deadline,
  { value: 0 }
);

Technical Analysis

The Skill explicitly says to fetch contract addresses from the TaskMaster API rather than hardcode them. The example then uses the API-provided contractAddress as the destination of a signed blockchain transaction.

The workflow does not independently verify:

  • The connected provider's chain ID against the task's declared chain.
  • The contract address against an audited or pinned registry.
  • The ...[truncated 2166 chars]
Remediation
View remediation

Remediation Suggestions

  • Maintain a version-controlled allowlist of audited contract, token, and implementation addresses for every supported chain.
  • Treat API-returned addresses as informational and compare them against an independent trusted registry before use.
  • Verify the RPC provider's chain ID before creating or sending any transaction.
  • Retrieve and compare deployed bytecode or a documented code hash at the selected address.
  • If proxy contracts are used, validate the proxy administrator and implementation address.
  • Decode and display the destination, function, parameters, token amount, and estimated value before requesting a signature.
  • Require explicit user approval for all token allowances, deposits, releases, cancellations, and other financially meaningful operations.
  • Grant only the exact allowance required for one transaction and revoke unused allowances afterward.
  • Use a dedicated low-balance wallet and enforce transaction-value and allowance limits.
  • Reject unexpected redirects, malformed API responses, unsupported chains, zero addresses, and addresses without deployed code.
  • Document an emergency process for freezing integrations and revoking allowances if API or contract compromise is suspected.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:679
Finding

Unpinned Third-Party Skills Installed From a Mutable Registry

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 679-701
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# Social Media Tasks
clawhub install twitter-x-strategy
clawhub install content-factory

# Content Creation Tasks
clawhub install content
clawhub install content-repurposer-pro

# Community Engagement Tasks
clawhub install reddit-write

# Skill Development Tasks
clawhub install skills-creator
clawhub install writing-better-skills

Technical Analysis

The Skill recommends installing multiple third-party Skills using only mutable package names. It does not pin versions, integrity hashes, immutable artifact identifiers, or verified publisher identities. It also does not direct users to inspect the packages before loading them.

Agent Skills can contain instructions or executable components that affect tool use, network access, credentials, and generated actions. Consequently, installing an unreviewed Skill is not equivalent to importing passive documentation. A package takeover, compromised publisher account, malicious update, dependency-confusion condition, or registry compromise could cause a later installation to retrieve content different from what was reviewed when this Skill was published.

The audited file does not itself fetch and execute a remote payload automatically, so this is classified as insecure dependency guidance rather than confirmed remote payload execution.

Attack Path

  1. An attacker compromises a recommended Skill's publisher account or the package registry, or publishes malicious content under a confusing or transferred package identity.
  2. The mutable package entry is updated with malicious instructions or scripts.
  3. A user follows the documented clawhub install command without a pinned version or integrity check.
  4. The current malicious package is installed instead of the previously ...[truncated 755 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin each recommended Skill to an exact reviewed version.
  • Where supported, pin an immutable artifact digest or cryptographic integrity hash.
  • Verify publisher identities and signatures before installation.
  • Review each dependency's full contents, permissions, scripts, network destinations, and transitive dependencies.
  • Make related-Skill installation explicitly optional rather than presenting commands without a security warning.
  • Install third-party Skills in an isolated environment with no wallet keys, bearer tokens, authenticated browser sessions, or unnecessary filesystem access.
  • Maintain an approved dependency manifest and re-audit every version change.
  • Configure update tooling not to silently replace reviewed versions with newer mutable releases.
  • Remove recommendations for packages that cannot provide provenance, immutable versioning, or integrity verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The quickstart endpoint returns a wallet private key and mnemonic directly in the API response, and the skill presents this as a convenience flow without a strong, explicit warning that anyone who sees these values can fully control the wallet and steal all funds. In an agent-skill context, this is especially dangerous because logs, transcripts, debugging output, or downstream tools may inadvertently persist or expose the returned secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill walks users through escrow creation and payment-release blockchain actions, but it does not provide a clear upfront warning that these transactions are irreversible once confirmed on-chain. Users may treat these steps like normal API operations and accidentally lock, transfer, or release funds with no rollback path if parameters, chain, contract address, or task details are wrong.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 608)May include surrounding context.

md
- Forgetting to rate (worker can claim default 5★ after 72h)

### As a worker:
- Accepting a task without checking if you can actually do it
- Marking complete without messaging the employer first
- Vague `submissionNotes` that don't evidence delivery
- Missing the 48-hour dispute window

Static analysis

No suspicious patterns detected.