Back to skill

Security audit

Usdc Dance Evvm Payment

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed payment integration guide with no bundled executable code, but it handles wallet credentials and payments so users should configure strict limits before use.

Install only after reviewing or pinning the exact Privy skill version you intend to use. Use Privy policies for per-transaction limits, approved chains, contract and recipient allowlists, and keep Privy credentials scoped away from unrelated agent work. Test on the stated testnet before allowing any wallet with real value.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned Installation of a Security-Sensitive Third-Party Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 27
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
2. **Privy Skill Installed**: `clawhub install privy`

The same unpinned command is repeated in the requirements at line 171:

markdown
- Privy skill installed (`clawhub install privy`)

Technical Analysis

The installation instructions identify the privy skill only by package name. They do not pin an audited version or immutable integrity digest. Consequently, the installed artifact may change after this skill has been reviewed.

The dependency is security-sensitive because the documentation expects it to manage wallets, sign transactions, and operate in an environment containing PRIVY_APP_ID and PRIVY_APP_SECRET. The dependency's source is not included in the submitted project, so its behavior could not be audited.

This is a supply-chain weakness rather than evidence that the current privy package is malicious. Exploitation requires the registry entry, publisher account, distribution channel, or dependency-resolution process to be compromised or otherwise return an unsafe artifact.

Attack Path

  1. An attacker compromises the publisher account or package-distribution path for the mutable privy skill, or causes the package name to resolve to an unsafe release.
  2. A user follows the documented clawhub install privy instruction without selecting a reviewed version or validating an integrity digest.
  3. The package manager installs the attacker-controlled or unexpectedly modified artifact.
  4. The dependency executes in the OpenClaw environment where Privy credentials and wallet workflows may be available.
  5. Malicious dependency behavior could attempt to capture credentials, alter wallet requests, substitute transaction recipients, or initiate unauthorized signing operations, subject to the runtime permissions ...[truncated 842 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed version rather than installing the mutable latest release.
  2. Require an immutable package digest, checksum, signature, or equivalent integrity constraint where supported.
  3. Document the verified publisher identity and canonical source repository.
  4. Review the exact dependency artifact before granting it access to Privy credentials or wallet operations.
  5. Use least-privilege Privy policies, including per-transaction and aggregate spending limits, approved-chain restrictions, contract allowlists, and recipient restrictions.
  6. Isolate the dependency from unrelated secrets and system resources.
  7. Add lockfiles or equivalent reproducible dependency metadata when the complete implementation is supplied.
  8. Establish a controlled update process that requires security review before changing the pinned dependency.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep