Back to skill

Security audit

superrare-deploy

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its SuperRare deployment purpose, but it can send a Bankr API key to a locally configurable, unvalidated API endpoint and performs irreversible broadcast actions with limited safeguards.

Review this before installing if you use real Bankr credentials. Use dry-run first, inspect any Bankr config files that can set apiUrl, prefer the official Bankr endpoint, and treat --broadcast or DRY_RUN=0 as an irreversible on-chain action that may spend funds or deploy a live collection.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib.sh:112
Finding

Bankr API Key Can Be Exfiltrated Through an Unvalidated API Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/lib.sh:112-130; credential transmission occurs at scripts/deploy-via-bankr.sh:109-127
Vulnerability Type: Unvalidated sensitive API endpoint configuration
Risk Level: High

Vulnerable Code

scripts/lib.sh:112-130:

bash
resolve_bankr_api_url() {
  local config_path
  for config_path in \
    "$HOME/.openclaw/skills/bankr/config.json" \
    "$HOME/.openclaw/workspace/skills/bankr/config.json" \
    "$HOME/.bankr/config.json"
  do
    if [ -f "$config_path" ]; then
      local value
      value="$(jq -r '.apiUrl // empty' "$config_path")"
      if [ -n "$value" ]; then
        echo "$value"
        return
      fi
    fi
  done

  echo "https://api.bankr.bot"
}

scripts/deploy-via-bankr.sh:109-127:

bash
BANKR_API_KEY="$(resolve_bankr_api_key)"
BANKR_API_URL="$(resolve_bankr_api_url)"
REQUEST_PAYLOAD="$(jq -n \
  --arg to "$FACTORY_ADDRESS" \
  --argjson chainId "$CHAIN_ID" \
  --arg data "$CALLDATA" \
  --arg description "$DESCRIPTION" \
  '{
    transaction: {
      to: $to,
      chainId: $chainId,
      value: "0",
      data: $data
    },
    description: $description,
    waitForConfirmation: true
  }')"

RESPONSE="$(curl -sS --max-time "$BANKR_SUBMIT_TIMEOUT_SECONDS" -X POST "$BANKR_API_URL/agent/submit" \
  -H "X-API-Key: $BANKR_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$REQUEST_PAYLOAD")"

Technical Analysis

The Bankr API endpoint is read from locally writable JSON configuration files and accepted without validation. The implementation does not require HTTPS, verify that the hostname belongs to Bankr, restrict ports, or otherwise enforce an approved origin.

Credential resolution is independent of endpoint resolution. Consequently, a legitimate API key obtained from BANKR_API_KEY, the systemd user environment, or another searched configuration fi ...[truncated 2130 chars]

Remediation
View remediation

Remediation Suggestions

  1. Hard-code or allowlist the official Bankr API origin, such as https://api.bankr.bot, for normal operation.
  2. If custom endpoints are required, make them an explicit opt-in and prominently display the selected endpoint before broadcasting.
  3. Parse and validate custom URLs before transmitting credentials:
    • Require the https scheme.
    • Reject embedded usernames or passwords.
    • Reject fragments, unexpected ports, malformed hosts, and non-allowlisted domains.
    • Resolve and reject loopback, link-local, private, or otherwise disallowed destinations when arbitrary hosts are unnecessary.
  4. Harden the request with appropriate curl controls, for example:
    bash
    curl --proto '=https' --proto-redir '=https' \
      --max-redirs 0 \
      --fail-with-body \
      --max-time "$BANKR_SUBMIT_TIMEOUT_SECONDS" \
      ...
    
  5. Do not resolve the API credential and API URL from independent trust sources. Bind each credential to its explicitly configured and validated service origin.
  6. Check ownership and restrictive permissions on credential-bearing configuration files before reading them.
  7. After receiving a transaction hash, retrieve the transaction and verify its chain, recipient, calldata, value, and expected sender before accepting its receipt.
  8. Restrict deployment event extraction to logs emitted by the expected factory address rather than accepting any matching event signature in the receipt.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares shell-capable behavior and documents execution of local scripts plus use of external binaries (cast, jq, curl), but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, that omission weakens policy enforcement and can allow broader-than-intended command execution if the skill is invoked automatically or composed with other skills.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill persists deployment receipts to disk and also describes searching multiple local locations for the Bankr API key, which indicates interaction with session- or user-persistent state. Persistent artifacts can expose sensitive operational metadata such as transaction hashes, collection addresses, and deployment context to later sessions or other local processes if permissions and retention are not controlled.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- Dry-run is the default. Deployment only broadcasts with `--broadcast` or `DRY_RUN=0`.
- Supported chains for RARE factory deployment are `mainnet`, `sepolia`, `base`, and `base-sepolia`.
- If `--max-tokens` is omitted, the 2-argument factory call is used.
- Successful broadcasts write receipts into `receipts/`.

## Bankr API key resolution

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script can move from preview to live on-chain submission solely via the --broadcast flag, with no interactive confirmation, typed acknowledgment, or secondary safeguard. In a deployment skill that can submit irreversible Ethereum/Base transactions through Bankr, this raises the risk of accidental mainnet deployment or unintended spend if an operator, wrapper script, or automation passes --broadcast incorrectly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/deploy-via-bankr.sh (reported line 129)May include surrounding context.

sh
waitForConfirmation: true
  }')"

RESPONSE="$(curl -sS --max-time "$BANKR_SUBMIT_TIMEOUT_SECONDS" -X POST "$BANKR_API_URL/agent/submit" \
  -H "X-API-Key: $BANKR_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$REQUEST_PAYLOAD")"

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill searches multiple unrelated user-scoped locations and process environment sources to obtain a Bankr API key and API URL, rather than requiring explicit user-provided inputs for this deployment. This creates implicit secret ingestion and cross-skill data access, which can surprise users, widen the trust boundary, and allow unintended use of credentials from other tools or contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function silently pulls a sensitive Bankr API key from environment variables, systemctl user environment, and several user config files without any user-facing disclosure. In an agent skill context, hidden secret discovery is risky because it may cause users to authorize actions with credentials they did not intend this skill to access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code documentation-like default metadata prefix says 'SuperRare deploy via aaigotchi', which appears to be copied from another context and does not match the declared skill identity. This contradicts the intended provenance/audit labeling for this deploy skill and can mislead users reviewing generated receipts or descriptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description limits scope to deploying on Ethereum or Base, which ordinarily implies the production networks, but the implementation accepts both sepolia and base-sepolia as valid chains. This is a semantic mismatch between the claimed supported deployment scope and the actual behavior exposed by the code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The function repeatedly calls cast receipt against a provided RPC URL, which results in network communication that may transmit transaction identifiers and metadata to external RPC infrastructure. This file includes no confirmation prompt, log message, or explanatory comment indicating that network requests will be made.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This function creates directories and writes payload data to an arbitrary file path, but provides no visible disclosure such as a prompt, log message, or explanatory comment. For code files, file writes should have some user-facing warning or documentation when not otherwise disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.