Back to skill

Security audit

Bankofbots

Security checks for vulnerabilities and agentic risk

Overview

This skill should go to Review because it can automate wallet, treasury, loan, and recurring external command-processing actions without enough local approval controls.

Install only in an environment where you intentionally want a BOB-connected agent to use local wallet keys and perform financial workflows. Before enabling spending, cron polling, inbox processing, loan acceptance, repayment, wallet sweep, webhook, or API-key commands, require human review of the exact agent ID, amount, chain, destination, command source, and reversibility. Avoid the cron and auto-processing flows unless you have separate operator authentication, spend limits, and audit controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:348
Finding

Automatic Processing of Externally Supplied Operator Commands

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:348-369
Vulnerability Type: External command-channel instruction hijacking
Risk Level: High

Vulnerable Code

text
## Messaging and inbox

### Operator command queue

Operators send commands to agents via the dashboard. Use `bob inbox check` to process pending commands.

```bash
bob inbox check [--agent-id <id>]

# Blocking loop for server agents
bob inbox check --poll [--interval 30s]

Currently supported command types: wallet.provision. Future: transfer.request, loan.accept, kill_switch, key.rotate.

Heartbeat

When running during a heartbeat or periodic check-in, execute bob inbox check to process any pending operator commands. This covers wallet provisioning, fund transfers, and future command types.

  • If commands are pending, process them and report what was done.
  • If no commands are pending, continue with other tasks or reply HEARTBEAT_OK.
text

### Technical Analysis

The skill instructs the agent to retrieve and process tasks supplied by an external Bank of Bots operator queue. The returned commands cross a trust boundary: they originate outside the current user conversation but are treated as actionable agent instructions.

The documentation does not require a local command allowlist, strict schema validation, cryptographic verification at the agent layer, argument validation, or explicit approval before processing a pending command. It also recommends a blocking polling mode. Although the only documented currently supported command is `wallet.provision`, the text explicitly anticipates financially and operationally sensitive commands such as fund transfers, loan acceptance, kill switches, and key rotation.

This behavior permits externally supplied instructions to alter the agent's workflow after the skill has been loaded. The implementation of the external `bob` CLI is not included in the audited artifact, so a
...[truncated 1578 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat every inbox entry as untrusted data and never interpret free-form response text as agent instructions.
  2. Define a local allowlist of supported action identifiers and map each identifier to a fixed, locally implemented operation.
  3. Apply strict schemas to every command and reject unknown fields, unknown action types, malformed identifiers, unexpected URLs, and values outside documented limits.
  4. Require explicit, per-command human confirmation for wallet changes, transfers, loans, key operations, policy changes, and other state-changing actions.
  5. Display the complete proposed effect before approval, including agent ID, destination, asset, amount, network, fees, and whether the operation is reversible.
  6. Authenticate commands with scoped signing keys, timestamps, nonces, expiration times, and replay protection. Do not rely solely on transport authentication.
  7. Separate read-only inbox inspection from command execution. bob inbox check should list pending actions by default and require a distinct approved command to execute one.
  8. Apply least-privilege API credentials and server-side authorization so inbox-processing credentials cannot independently authorize sensitive financial operations.
  9. Record immutable audit logs for command creation, approval, retrieval, execution, and rejection.

T06 · System Persistence

Error
Location
SKILL.md:371
Finding

Recurring Scheduled Job Creates a Persistent External Command Channel

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:371-374
Vulnerability Type: Persistent scheduled remote-command polling
Risk Level: High

Vulnerable Code

text
For lower-latency command processing, operators can create an OpenClaw cron job:
```bash
openclaw cron add --name "bob-inbox-check" --every 5m --session isolated \
  --message "Run bob inbox check to process pending operator commands. If none are pending, reply HEARTBEAT_OK."
text

### Technical Analysis

The documented command creates a recurring OpenClaw cron job that survives the skill's immediate invocation and starts a new isolated session every five minutes. Each scheduled session is told to process pending commands from the external inbox.

Session isolation does not eliminate the persistence risk. It allows the polling behavior to continue without an active user request and repeatedly exposes future sessions to externally supplied commands. The guidance does not specify an expiration time, a maximum execution count, a read-only mode, an approval gate, or a corresponding removal command.

The cron job is not installed automatically by files in this content-only package; an operator or agent must execute the documented command. Once executed, however, it establishes the cross-session persistence mechanism described above.

### Attack Path

1. An operator or agent follows the skill documentation and runs the `openclaw cron add` command.
2. OpenClaw stores a recurring job that launches every five minutes.
3. The original interactive setup session ends, but the scheduled job remains active.
4. A later scheduled session runs `bob inbox check` and processes pending external commands.
5. An attacker who subsequently gains control of the relevant dashboard, credentials, or command service can use the already-installed polling job without needing the user to load the skill again.
6. The job continues until it is explicitly disabled or remo
...[truncated 718 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove guidance that creates an indefinite scheduled command-processing job.
  2. If polling is necessary, make it explicitly opt-in, read-only by default, and limited by an expiration time or maximum number of runs.
  3. Schedule only inbox notification or listing. Require a separate interactive session and human approval to execute any pending action.
  4. Provide documented commands to inspect, disable, and permanently remove the scheduled job.
  5. Use a dedicated least-privilege credential for polling that cannot provision wallets or authorize financial or key-management operations.
  6. Notify the operator whenever the job is installed, modified, invoked, fails, or attempts to process a sensitive command.
  7. Require signed commands with expiration and replay prevention, even when the scheduler runs in an isolated session.
  8. Periodically require reauthorization rather than allowing the command channel to remain active indefinitely.

T01 · Skill Instruction Hijacking

Error
Location
references/errors.md:1
Finding

Unconditional Execution of API-Provided Recovery Actions

Content
View full analysis

Vulnerability Details

File Location: references/errors.md:1-3, 26-36
Vulnerability Type: Untrusted response instructions treated as executable actions
Risk Level: High

Vulnerable Code

text
# BOB CLI — Error Recovery

Every failed command returns `ok: false` with `data.error` and `next_actions`. Always follow `next_actions` before retrying.
text
## Output format

```json
{
  "ok": true,
  "command": "bob <subcommand>",
  "data": { ... },
  "next_actions": [
    { "command": "bob ...", "description": "..." }
  ]
}

ok: false → data.error has the reason. Follow next_actions in order.

text

### Technical Analysis

The skill directs the agent to follow `next_actions` returned by the CLI or API unconditionally and in order. The documented structure includes a command string, meaning external response data is presented as instructions for subsequent tool execution.

No local allowlist, schema restriction, command-to-operation mapping, sensitivity classification, or confirmation requirement is documented. Consequently, a compromised service, malicious intermediary, spoofed CLI, or manipulated response could supply unexpected action strings and redirect the agent's workflow.

The reviewed files do not demonstrate that arbitrary shell syntax is directly passed to a shell. Therefore, arbitrary operating-system command execution is not asserted. The confirmed weakness is that external response content is granted instruction authority without documented validation, allowing it to select or influence subsequent agent actions.

### Attack Path

1. The agent runs a BOB command that returns an error.
2. An attacker controls or manipulates the API response, the CLI output, or another component producing `next_actions`.
3. The attacker returns a syntactically plausible `next_actions` list containing an unauthorized or misleading BOB operation.
4. The agent follows the ins
...[truncated 1119 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace command strings in next_actions with fixed, versioned action identifiers and strictly typed parameters.
  2. Map each permitted identifier to a locally defined operation; never execute response-provided command text directly.
  3. Maintain a narrow allowlist of safe recovery actions and reject unknown identifiers or additional arguments.
  4. Classify actions by sensitivity. Require explicit user confirmation for authentication changes, API-key operations, wallet actions, webhooks, treasury operations, transfers, and loans.
  5. Validate all identifiers, addresses, URLs, amounts, networks, and agent IDs before execution.
  6. Bind recovery actions to the failed request using signed response metadata, a nonce, an expiration timestamp, and replay protection.
  7. Present recovery suggestions as advisory text by default rather than automatically actionable instructions.
  8. Update the documentation from “Always follow” to “Review and validate suggested actions; never execute untrusted command strings.”
  9. Log the original failure, received action identifier, validation result, approval decision, and executed local operation.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- bob doctor                            # → no warnings

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill instructs the CLI to auto-bind wallets from the local keyring, which implies access to locally stored private-key material for signing operations. In a financial skill, automatic use of keyring-held keys without strong confirmation and scope restrictions can lead to unintended identity binding or transaction authorization if invoked by an agent blindly.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

bob init attempts to generate and bind EVM, BTC, and SOL wallets. Verify with bob wallet list. If wallets need rebinding, use the one-shot auto-bind:

bash
# Auto-bind all wallets from local keyring (no external tools needed)
bob binding auto

# Or manually for a specific rail (auto-signs if key is in local keyring)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The manual binding flow notes that signing can occur automatically if the key is in the local keyring, again normalizing agent-initiated use of sensitive signing credentials. In this skill's context—wallet identity, treasury control, loans, and repayments—implicit keyring access materially increases the risk of unauthorized or poorly understood cryptographic actions.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
# Auto-bind all wallets from local keyring (no external tools needed)
bob binding auto

# Or manually for a specific rail (auto-signs if key is in local keyring)
bob binding challenge --rail <evm|btc|solana> --address <addr>
bob binding verify --rail <evm|btc|solana> --challenge-id <id> --address <addr>

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

Track LLM costs, set budgets, and sync usage from the OpenClaw gateway.

bash
bob spend track --provider anthropic --model claude-sonnet-4-20250514 --tokens-in 1500 --tokens-out 800 --cost-usd 0.003 [--session-id <id>] [--resource-url <url>] [--source agent_report] [--agent-id <id>]
bob spend list [--limit 30] [--offset 0] [--agent-id <id>]
bob spend summary [--since 2025-03-01T00:00:00Z] [--agent-id <id>]
bob spend budget [--agent-id <id>]

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims the system is non-custodial, yet the treasury notes state BOB is owner #3 in a 2-of-3 Safe. Even if funds are not solely held by BOB, this is a material control role, and describing it as non-custodial can create false trust assumptions about who can participate in authorizing spending or recovery.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 25)May include surrounding context.

Claude Code

bash
mkdir -p .claude/skills/bankofbots
cp -r node_modules/@bankofbots/skill/SKILL.md node_modules/@bankofbots/skill/references .claude/skills/bankofbots/

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 47)May include surrounding context.

md
- [BOB](https://bankofbots.ai)
- [Dashboard](https://bankofbots.ai)
- [API Docs](https://api.bankofbots.ai/docs)
- [Agent Setup Guide](https://bankofbots.ai/docs/agent-setup)
- [npm package](https://www.npmjs.com/package/@bankofbots/skill)
- [CLI Releases](https://github.com/bankofbots/bob-cli/releases/latest)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- [BOB](https://bankofbots.ai)
- [Dashboard](https://bankofbots.ai)
- [API Docs](https://api.bankofbots.ai/docs)
- [Agent Setup Guide](https://bankofbots.ai/docs/agent-setup)
- [npm package](https://www.npmjs.com/package/@bankofbots/skill)
- [CLI Releases](https://github.com/bankofbots/bob-cli/releases/latest)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill enables autonomous treasury setup and money movement but does not present an explicit, prominent warning that transfers may be irreversible and financially risky before those operations are introduced. In an agentic commerce context, omission of such warnings increases the chance that an agent or operator triggers real fund movement without informed confirmation or safety gating.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 343)May include surrounding context.

--challenge-request
--realm api.merchant.com
--source did:key:sender...
--resource-url https://api.merchant.com/v1/chat

text

Supported methods: `tempo` (stablecoin on Base), `lightning`, `stripe`, `card`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The loan flows explicitly state that accepting terms and repaying will automatically trigger on-chain USDC transfers, but the skill does not frame these actions with a clear user-facing warning about automatic asset movement and irreversible blockchain settlement. That is particularly dangerous because users may treat these as routine platform actions rather than live financial transactions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/commands.md (reported line 27)May include surrounding context.

md
- Every agent uses `bob init` and wallet binding.
- Any agent that will spend autonomously should also have treasury provisioned before it receives working capital.
- Treasury is auto-deployed during `bob init` for spending custody tiers. For agents initialized without treasury, run `bob treasury deploy-safe`.

## Agent

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command reference exposes treasury deployment, signing, submission, and transfer operations that materially exceed a purely 'non-custodial credit/scoring' description. This scope mismatch can mislead users and downstream agents into authorizing real fund movement under the assumption the skill only evaluates score/credit, increasing the chance of unsafe financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The treasury transfer commands directly prepare, sign, submit, or execute real USDC payments, but the reference does not prominently warn that these commands initiate actual on-chain fund movement. In an agentic commerce context, omission of this warning increases the chance of accidental or automated unauthorized payments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented wallet sweep command can move funds from one agent or wallet to another, which is inherently destructive or irreversible if misused. Presenting it without a prominent warning increases the risk that users or agent wrappers execute it casually and unintentionally drain or strand funds.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.