Back to skill

Security audit

Adam's Bounty Hunter副业系统

Security checks for vulnerabilities and agentic risk

Overview

This skill exposes sensitive-looking keys and gives an agent broad authority over trading, marketplace, publishing, and finance actions with limited fresh approval.

Install only after removing and rotating the exposed keys, replacing credentials with environment variables or a secret manager, and adding explicit per-action approval for trades, orders, price changes, public posts, package publishing, payments, wallet use, and financial reallocations. Treat the npx publishing workflow as unsafe until the CLI version and source are pinned and verified.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:105
Finding

Blanket Instructions Hijack the Agent Into Autonomous Financial and Commercial Operations

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 105-119; related role-redefinition language appears at lines 7-11 and 173-176
Vulnerability Type: Agent instruction hijacking
Risk Level: Critical

Vulnerable Skill Text

The following is an English translation of the relevant instructions:

markdown
## Autonomous Authorization

Adam's original statement: "Okay, you decide; I will cooperate at any time."

The AI has full authority to decide:
- Soul.Markets order acceptance and pricing
- Jarvis-Invest trading decisions
- Publication of new ClawHub skill packages
- Financial allocation and reminders

Adam's confirmation is required:
- Expenses greater than $100
- Launching a new platform or service
- Major strategy adjustments

Technical Analysis

The skill redefines the agent as a fully autonomous commercial and financial operator and presents a static quotation as blanket authorization. The instructions authorize order acceptance, pricing, investment trading, package publication, and financial allocation without requiring transaction-level confirmation.

A skill document cannot safely establish the authenticity, current validity, identity, or scope of the quoted authorization. When loaded into an agent with relevant tools or authenticated sessions, these instructions can alter the agent's existing objectives and induce high-impact external actions unrelated to the user's immediate request. The limited approval threshold for expenses does not adequately protect trades, binding marketplace commitments, public package publication, or financial reallocations.

Attack Path

  1. A user installs or loads the skill into an agent session.
  2. The agent interprets the role assignment and quoted statement as valid standing authorization.
  3. The agent discovers available marketplace, publishing, trading, social-media, or financial tools.
  4. Without obtaining fresh transaction-specific co ...[truncated 773 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the role-replacement language and all claims of blanket autonomous authority.
  • Treat quotations embedded in skill content as untrusted text rather than proof of consent.
  • Require explicit, current, transaction-specific approval before every trade, order acceptance, price change, public post, package publication, payment, or financial reallocation.
  • Display the destination account, amount, asset, price, irreversible effects, and estimated risk before requesting approval.
  • Separate read-only monitoring from state-changing operations and default the skill to read-only access.
  • Enforce least privilege through restricted credentials and narrowly scoped tools.
  • Add maximum transaction values, trading-loss limits, approved-asset lists, and emergency stop controls outside the skill prompt.
  • Maintain tamper-evident logs of proposals, approvals, and resulting external actions.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:29
Finding

Plaintext Soul.Markets Authentication Key Embedded in Skill Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 29
Vulnerability Type: Hardcoded authentication secret
Risk Level: Critical

Vulnerable Skill Text

markdown
**Soul Key:** `soul_5ada62059ba0f801018634ad14aac894054116a189f1659c33e68544a12912aa`

Technical Analysis

A credential in a service-specific token format is embedded directly in a distributable skill document. Anyone who can read the project, a published package, build output, logs, backups, or repository history can recover the token without bypassing access controls.

The audit could not independently verify whether the token remains active or determine its exact server-side permissions. Nevertheless, plaintext distribution must be treated as credential exposure because revocation, expiration, and scope are not established by the project.

Attack Path

  1. An attacker obtains the skill package or a copy of SKILL.md.
  2. The attacker extracts the plaintext soul_ token.
  3. The attacker identifies the referenced Soul.Markets service and attempts authentication through its API or client.
  4. If the token is active, the attacker performs operations permitted by its assigned scope while impersonating the account.
  5. The activity consumes account privileges and may remain attributed to the legitimate token owner.

Impact Assessment

The attainable privileges depend on the server-side scope of the exposed key. Potential impact includes account impersonation, unauthorized marketplace operations, access to account or order information, fraudulent service activity, and reputational or financial harm. Exposure persists in every distributed copy and may also remain in version-control history after the visible line is removed.

Remediation
View remediation

Remediation Suggestions

  • Revoke the exposed token immediately and issue a replacement.
  • Review service audit logs for use from unexpected clients, addresses, times, or operations.
  • Remove the token from the document, package history, repository history, cached artifacts, logs, and backups where feasible.
  • Store replacement credentials in a dedicated secret manager or protected environment variable.
  • Document only a placeholder such as ${SOUL_MARKETS_KEY}.
  • Grant the replacement token only the minimum required permissions and apply expiration, rotation, rate limits, and source restrictions where supported.
  • Add automated secret scanning to local hooks and continuous-integration pipelines.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:72
Finding

Plaintext DeepSeek API Key Embedded in Skill Documentation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 72
Vulnerability Type: Hardcoded API credential
Risk Level: High

Vulnerable Skill Text

markdown
- DeepSeek API Key: `sk-5aa202974f284ecc9a82c95d9c7ca23e`

Technical Analysis

The document stores an API key in plaintext. Distribution of the skill consequently distributes the credential to every recipient and to any system that indexes, logs, backs up, or publishes the file.

No expiration, permission restrictions, quota controls, or secret-management mechanism are documented. The audit could not confirm that the key remains active, but its exposure is independently unsafe because an active key could be replayed directly against the provider.

Attack Path

  1. An attacker reads the published or locally stored skill document.
  2. The attacker extracts the sk- credential.
  3. The attacker configures an API client to submit requests using the exposed key.
  4. If the key is active, requests consume the legitimate account's quota and inherit the key's authorized access.
  5. The resulting usage may cause unexpected charges, service exhaustion, or account suspension.

Impact Assessment

Potential privileges include API access within the exposed key's server-side scope. Likely consequences include unauthorized model usage, quota depletion, unexpected billing, service denial for the legitimate owner, and exposure of account-level metadata available to that credential. Exact privileges cannot be determined from the project alone.

Remediation
View remediation

Remediation Suggestions

  • Revoke and rotate the exposed API key immediately.
  • Inspect provider usage and billing records for unauthorized requests.
  • Purge the credential from the current file, repository history, published packages, logs, and build artifacts.
  • Retrieve the replacement key at runtime from a secret manager or protected environment variable.
  • Use a placeholder in documentation and fail safely when the environment variable is absent.
  • Configure strict quotas, billing alerts, expiration, and least-privilege restrictions where supported.
  • Enable automated credential detection before commits and package publication.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Remote npm Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52-55
Vulnerability Type: Unsafe third-party dependency execution
Risk Level: Medium

Vulnerable Skill Text

bash
cd ~/.openclaw/workspace/skills
npx clawhub publish <skill-name>

Technical Analysis

The documented publishing workflow invokes npx using a package name without a pinned version, lockfile, integrity hash, or provenance verification. If the package is not already installed in the expected environment, npx may resolve and download a package from the configured npm registry and then execute its command-line code.

The effective executable can therefore change after the skill has been reviewed. A compromised maintainer account, malicious release, registry compromise, altered registry configuration, or unexpected newer version could introduce arbitrary code. Package installation and command execution may also trigger lifecycle behavior with the invoking user's permissions.

This finding does not establish that the current clawhub package is malicious; the vulnerability is the unverified and mutable dependency execution process.

Attack Path

  1. A user follows the documented publication procedure.
  2. npx searches for the named package locally and, if necessary, resolves it through the configured registry.
  3. The registry supplies the currently resolved package version rather than a version reviewed with this skill.
  4. A compromised or malicious package executes through its CLI or installation lifecycle.
  5. The code runs with the user's privileges and can access files, environment variables, credentials, network resources, and writable workspace content available to that process.

Impact Assessment

Successful supply-chain exploitation could provide arbitrary code execution under the account running npx. Accessible scope may include the OpenClaw workspace, package contents, environment-based secrets, publishin ...[truncated 217 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the command to a specifically reviewed package version rather than resolving the latest release.
  • Record and verify package integrity through a lockfile and registry integrity metadata.
  • Verify package ownership, provenance, signatures, and release history before installation.
  • Install the reviewed dependency as part of a controlled build rather than downloading it during a sensitive publishing action.
  • Use an allowlisted registry over authenticated TLS and prevent project or user configuration from silently redirecting package resolution.
  • Execute publishing tools in a restricted environment with minimal filesystem access, no unrelated secrets, and narrowly scoped publication credentials.
  • Disable unnecessary package lifecycle scripts where compatible with the verified tool.
  • Re-review and test dependency updates before changing the pinned version.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly grants broad autonomous authority for trading, publishing, financial allocation, and order handling, while only requiring limited confirmation for a few cases. In an agent setting, this can directly trigger real-world financial loss, unauthorized transactions, irreversible publishing actions, or risky market activity without meaningful user consent or safety interlocks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The operational instructions and command descriptions are presented entirely in Chinese, effectively imposing a single language for use of the skill. The file does not offer user language choice or explain a justified region- or audience-specific reason for the language constraint.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill instructs use of npx clawhub publish <skill-name> without pinning a specific package version or integrity source. That allows execution of whatever package version is current at runtime, increasing supply-chain risk if the package is compromised, typosquatted, or updated with unsafe behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:75