Back to skill

Security audit

OpenClawCash

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed OpenClawCash wallet-management skill with real financial authority, but its risky behavior is coherent with its stated purpose and mostly gated by user confirmation or server-side policy.

Install only if you intend to let an agent operate OpenClawCash wallets. Prefer confirm_each_write unless wallets have strict dashboard policies, whitelists, and spending limits. Treat the API key and wallet export passphrases as secrets, review any --yes command carefully, and verify the pinned MCP package before using the preferred npx path.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (43)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
- `POST /api/agent/checkout/escrows/:id/release` - Release funds
   - `POST /api/agent/checkout/escrows/:id/refund` - Refund funds
   - `POST /api/agent/checkout/escrows/:id/cancel` - Cancel escrow
   - `GET|POST /api/agent/checkout/webhooks` and `PATCH|DELETE /api/agent/checkout/webhooks/:id` - Manage webhooks. `eventTypes` accepts the 9 `escrow.*` events or `*`, and `*` covers escrow events only; `wallet.transaction.confirmed` is the one wallet event and must be named. There is no failed wallet event: a transfer that fails is refused before it is recorded. Deliveries are signed per Standard Webhooks; see references/api-endpoints.md

Checkout timing fields for `POST /api/agent/checkout/payreq`:
- `expiresInSeconds`: funding deadline before request expires.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-endpoints.md (reported line 833)May include surrounding context.

GET /api/agent/checkout/webhooks POST /api/agent/checkout/webhooks PATCH /api/agent/checkout/webhooks/:id DELETE /api/agent/checkout/webhooks/:id

text

Subscribe and manage event deliveries. `eventTypes` accepts:

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'shell' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 558)May include surrounding context.

md
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 560)May include surrounding context.

md
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 71)May include surrounding context.

sh
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 92)May include surrounding context.

sh
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 3)May include surrounding context.

sh
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 8)May include surrounding context.

sh
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 27)May include surrounding context.

sh
#!/bin/bash
# OpenclawCash Skill Setup
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 53)May include surrounding context.

sh
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

# Read KEY=value lines from the .env file WITHOUT executing it: only the two names this skill uses
# are accepted, everything else (comments, other names, command substitutions) is ignored.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 6)May include surrounding context.

sh
# Creates the .env file for API key configuration

SKILL_DIR="$(cd "$(dirname "$0")/.." && pwd)"
ENV_FILE="$SKILL_DIR/.env"

# Read KEY=value lines from the .env file WITHOUT executing it: only the two names this skill uses
# are accepted, everything else (comments, other names, command substitutions) is ignored.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/api-endpoints.md (reported line 47)May include surrounding context.

md
"steps": [
      "Preferred: run `npx -y @openclawcash/mcp-server@0.1.27` if this client supports MCP servers (requires AGENTWALLETAPI_KEY in the environment); skip the remaining steps if so",
      "Fallback only, when MCP is unavailable: git clone https://github.com/openclawcash/agentwalletapi <your-workspace>/skills/agentwalletapi",
      "Read <your-workspace>/skills/agentwalletapi/SKILL.md before running any command from the cloned skill"
    ],
    "agentPrompt": "Prefer MCP: if this client supports MCP servers, run \"npx -y @openclawcash/mcp-server@0.1.27\" (requires AGENTWALLETAPI_KEY in the environment) and stop there. Only if MCP is unavailable, git clone https://github.com/openclawcash/agentwalletapi into <your-workspace>/skills/agentwalletapi, then read <your-workspace>/skills/agentwalletapi/SKILL.md before running anything inside it."
  }

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/api-endpoints.md (reported line 49)May include surrounding context.

md
"steps": [
      "Preferred: run `npx -y @openclawcash/mcp-server@0.1.27` if this client supports MCP servers (requires AGENTWALLETAPI_KEY in the environment); skip the remaining steps if so",
      "Fallback only, when MCP is unavailable: git clone https://github.com/openclawcash/agentwalletapi <your-workspace>/skills/agentwalletapi",
      "Read <your-workspace>/skills/agentwalletapi/SKILL.md before running any command from the cloned skill"
    ],
    "agentPrompt": "Prefer MCP: if this client supports MCP servers, run \"npx -y @openclawcash/mcp-server@0.1.27\" (requires AGENTWALLETAPI_KEY in the environment) and stop there. Only if MCP is unavailable, git clone https://github.com/openclawcash/agentwalletapi into <your-workspace>/skills/agentwalletapi, then read <your-workspace>/skills/agentwalletapi/SKILL.md before running anything inside it."
  }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents PUT /api/agent/user-tag as a write action whose value is immutable after being set, but the section does not include a clear warning to users to confirm before performing the irreversible change. Because this behavior can permanently affect account identity, the description should explicitly call out the risk at the point of use, not only in generic security notes elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file describes POST /api/agent/transfer, which moves funds and can be irreversible, but the transfer section itself does not prominently instruct the user or agent to obtain explicit confirmation before sending assets. A general warning appears earlier in the document, but this safety-critical section should contain its own localized caution because users may jump directly to this endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

POST /api/agent/swap executes asset trades that can incur slippage, fees, and irreversible asset conversion, yet this section does not include a specific user warning or confirmation requirement. Even though write actions are noted as high-risk in the Security Notes, the swap section should independently disclose these consequences for safe use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The Polymarket limit and market order sections document real trading actions, but they do not provide a direct warning that these operations can place live financial bets/orders and may execute immediately with loss risk. Users consulting these sections alone may miss the broader high-risk write-action note earlier in the document.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

POST /api/agent/approve authorizes a spender to use wallet tokens, which is a safety-critical permission change, but the section does not explicitly warn about allowance risk. Approval can expose funds to misuse if the spender or amount is incorrect, so the documentation should clearly disclose this before use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 294)May include surrounding context.

sh
confirm_risky_action "Setting the checkout user tag (one-time; it cannot be changed later)"
        json_escape_var USER_TAG_ESC "$USER_TAG"
        BODY="{\"userTag\":\"$USER_TAG_ESC\"}"
        curl -s -X PUT \
            -H "X-Agent-Key: $AGENTWALLETAPI_KEY" \
            -H "Content-Type: application/json" \
            -d "$BODY" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rename command performs an authenticated state-changing PATCH without any warning, confirmation prompt, or --yes gate, unlike most other write operations in the tool. Although it does not move funds, it can still alter account state, confuse operators, disrupt automations that rely on labels, and make social-engineering or transaction-review mistakes more likely in a wallet-management context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This PATCH sends an authenticated state-changing rename request without any confirmation or warning. In a high-sensitivity wallet tool, silent account-state modification can enable operator confusion, deceptive relabeling, and mistakes in downstream fund operations.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 328)May include surrounding context.

sh
BODY="{"
        append_wallet_id_json_field BODY "$SELECTOR"
        BODY="$BODY, \"label\": \"$NEW_LABEL_ESC\"}"
        curl -s -X PATCH \
            -H "X-Agent-Key: $AGENTWALLETAPI_KEY" \
            -H "Content-Type: application/json" \
            -d "$BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The create flow transmits exportPassphrase in the request body to the remote API. Even if this is intended product behavior, sending a wallet export passphrase over the network materially increases exposure through transport compromise, server-side logging, upstream application compromise, or accidental retention of highly sensitive secret material.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 376)May include surrounding context.

sh
json_escape_var PASSPHRASE_ESC "$PASSPHRASE_VALUE"
        json_escape_var PASSPHRASE_ENV_ESC "$PASSPHRASE_ENV_VAR"
        BODY="{\"label\":\"$LABEL_ESC\",\"network\":\"$NETWORK_ESC\",\"exportPassphrase\":\"$PASSPHRASE_ESC\",\"exportPassphraseStorageType\":\"env\",\"exportPassphraseStorageRef\":\"$PASSPHRASE_ENV_ESC\",\"confirmExportPassphraseSaved\":true}"
        curl -s -X POST \
            -H "X-Agent-Key: $AGENTWALLETAPI_KEY" \
            -H "Content-Type: application/json" \
            -d "$BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 420)May include surrounding context.

sh
BODY="$BODY, \"chain\": \"$CHAIN_ESC\""
        fi
        BODY="$BODY}"
        curl -s -X POST \
            -H "X-Agent-Key: $AGENTWALLETAPI_KEY" \
            -H "Content-Type: application/json" \
            -d "$BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/agentwalletapi.sh (reported line 453)May include surrounding context.

sh
BODY="$BODY, \"chain\": \"$CHAIN_ESC\""
        fi
        BODY="$BODY}"
        curl -s -X POST \
            -H "X-Agent-Key: $AGENTWALLETAPI_KEY" \
            -H "Content-Type: application/json" \
            -d "$BODY" \

Static analysis

No suspicious patterns detected.