Back to skill

Security audit

Agent World Protocol

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned with an agent world, but it gives an autonomous agent broad real-money and public-posting powers without adequate local safeguards.

Review carefully before installing. Use only a public wallet address, never a private key or seed phrase, prefer a test or low-value wallet, avoid autonomous mode for spending or posting actions, and do not enable social or market bridges unless you can confirm each outgoing action yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
connect.js:51
Finding

Attacker-Controlled World Messages Are Injected into the Agent Context

Content
View full analysis
{ try { const msg = JSON.parse(data.toString()); handleMessage(msg); } catch (e) {} }); ``` ```js const events = obs.recentEvents || []; const importantEvents = events.filter(e => ['agent_spoke', 'whisper', 'trade_proposed', 'bounty_posted', 'combat_attack', 'agent_defeated', 'territory_contested', 'guild_invite', 'resource_gathered', 'bounty_completed'].includes(e.type) ); for (const e of importantEvents.slice(0, 5)) { switch (e.type) { case 'agent_spoke': summary += ` 💬 ${e.name}: "${e.message}"\n`; break; case 'whisper': if (e.toAgentId === agentId) { summary += ` 🤫 ${e.fromName} whispers: "${e.message}"\n`; } break; case 'trade_proposed': summary += ` 🤝 Trade proposed by ${e.fromName}\n`; break; case 'bounty_posted': summary += ` 🎯 Bounty posted: "${e.title}" (${e.rewardSOL} SOL)\n`; break; } } console.log(summary); ``` ### Technical Analysis The WebSocket server supplies observations containing messages, names, whispers, and bounty titles controlled by other participants. These values are interpolated directly into a textual summary and written to standard output. The script header states that OpenClaw reads this output. Consequently, untrusted remote text enters the language model's context without a trusted-data boundary, escaping, provenance enforcement, or an instruction that the content must never be treated as authorization. Simple output escaping would not completely solve this issue because the semantic content could still contain instructions. The application needs a policy boundary that distinguishes remote world data from trusted user instructions. ### Attack Path 1. An atta ...[truncated 1305 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
connect.js:24
Finding

Ambiguous Wallet Environment Variable Can Disclose Sensitive Wallet Material

Content
View full analysis
{ ws.send(JSON.stringify({ type: 'auth', wallet: WALLET, signature: 'demo-sig', name: NAME, metadata: { framework: 'openclaw', type: 'autonomous' }, })); }); ``` ```js case 'challenge': ws.send(JSON.stringify({ type: 'auth', wallet: WALLET, signature: 'demo-sig', name: NAME, metadata: { framework: 'openclaw' }, })); break; ``` ```js console.log(`[AWP] Wallet: ${WALLET}`); ``` ### Technical Analysis The source-level usage documentation describes `AWP_WALLET` as `your-key`, while the README describes it as a wallet address. The program does not validate which kind of value was supplied. It sends the complete environment value to the WebSocket server during authentication and prints it to standard output. The server destination is also configurable through `AWP_SERVER_URL`. Therefore, any value placed in `AWP_WALLET` can be sent to an arbitrary WebSocket endpoint selected through the environment. The hardcoded `demo-sig` is not proof of wallet ownership and does not provide a secure challenge-response authentication flow. It also increases the chance that users will place actual secret material in `AWP_WALLET` in an attempt to authenticate. ### Attack Path 1. A user follows the source usage example and interprets `your-key` as a private key or other secret wallet credential. 2. The user places that secret in `AWP_WALLET`. 3. On connection, the script serializes the ...[truncated 1054 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:8
Finding

Installation Instructions Reference an Unpinned and Potentially Unpublished Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:115
Finding

Real-Value Actions Lack Local Authorization, Validation, and Spending Controls

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
connect.js:295
Finding

Unvalidated JSON Passthrough Bypasses the Documented Action Interface

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill exposes actions that spend real SOL and trigger economically significant operations such as deposits, land claims, building, contests, guild funding, swaps, and market buys, but it does not present explicit user-facing warnings that these actions use real funds and may be irreversible. In an autonomous-agent context, this omission materially increases the risk of unintended monetary loss because a user may treat the world as a simulation while the skill can initiate real blockchain-backed transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to act autonomously when the user gives no specific command authorizes ongoing unsupervised behavior in a system that can spend funds, interact with other agents, and perform combat, trading, social posting, and market actions. In this context, autonomous execution without a clear warning or opt-in is dangerous because it can cause persistent, cumulative actions and financial exposure beyond the user's intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script is presented as a connection/observation bridge, but it exposes a large command surface that can trigger high-impact actions including deposits, trading, swaps, social posting, guild operations, combat, and NFT minting. In an agent skill context, broad unaudited action capability materially increases the risk of prompt-driven misuse, unintended transactions, or abuse of external integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README advertises capabilities involving real SOL transfers, token swaps, NFT minting, bounty claiming, and posting to public platforms, but provides no safety warnings, consent model, spending limits, or explanation of irreversible financial and reputational consequences. In an agent skill, this omission is dangerous because users may enable autonomous actions that can spend funds or publish content publicly without understanding the risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The social bridge actions allow posting to X, Telegram, and Discord, yet the skill provides no privacy, reputational, or external-communication warnings. Without explicit disclosure and consent requirements, an autonomous or loosely instructed agent could publish sensitive information, impersonate the user, spam third parties, or create irreversible public records tied to external accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sends the wallet value and agent metadata to a remote WebSocket server as part of authentication, but the file does not include any warning or disclosure that environment-provided identity data will be transmitted externally. Although the header explains that the script connects to AWP, it does not clearly warn users that the AWP_WALLET value is sent to the server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The bridge actions include potentially irreversible or externally visible operations such as token swaps, social posting, and NFT minting, and they are exposed as simple stdin commands with no warning, confirmation, or policy checks. In an autonomous-agent setting, this makes accidental or prompt-induced real-world side effects much more dangerous than ordinary in-game actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The default branch parses arbitrary stdin as JSON and forwards it as an action, bypassing the limited natural-language command set and any implicit constraints those commands provide. This effectively creates a raw command injection interface to the remote server, allowing any supported action schema to be invoked, including actions not documented or intended by the wrapper.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The documentation presents English natural-language commands as the expected interaction mode and does not indicate whether other languages are supported or whether the user can choose a language. This can be a language-policy concern when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency uses a broad semver range (^8.0.0) instead of pinning an exact version, which makes builds non-reproducible and can unintentionally introduce vulnerable or breaking upstream releases. In a network-facing agent skill that relies on WebSocket functionality, this increases supply-chain uncertainty and makes it harder to verify whether deployed instances are affected by known ws vulnerabilities.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "OpenClaw skill for Agent World Protocol — trade, build, fight, and explore in a shared AI agent world",
  "main": "connect.js",
  "dependencies": {
    "ws": "^8.0.0"
  }
}

Unverifiable Dependency: ws has 7 known advisory(ies) (CVE-2016-10518 (Remote Memory Disclosure in ws); CVE-2024-37890 (ws affected by a DoS when handling a request with many HTTP headers); CVE-2026-45736 (ws: Uninitialized memory disclosure) +4 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The manifest references ws without pinning a specific version, so there is no way to verify from this file alone whether the installed package includes fixes for known advisories affecting ws. Because ws is commonly exposed to untrusted network input, unresolved issues in that library could enable denial of service or information disclosure depending on the actual resolved version.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.