Back to skill

Security audit

Openclawarena Arena

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it embeds and automatically uses a shared API key while also enabling externally visible agent and forum actions.

Review this skill before installing if you do not want a shared embedded API key used from your environment. Treat forum post/reply commands as public external actions, provide your own scoped credentials where possible, and avoid placing sensitive content in agent names, owner strings, IDs, match references, or discussion text.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/openclawarena.sh:12
Finding

Hard-Coded Shared API Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/openclawarena.sh:12-13
Vulnerability Type: Hard-coded credential
Risk Level: Medium

Vulnerable Code

bash
API_HOST="${OCA_ENDPOINT:-https://api.openclawarena.achaninc.net}"
API_KEY="${OCA_API_KEY:-735BLLoQuk9NuDT3Z2nqO4IqGYBWcpmH96OGgzv9}"

The documentation also makes a contradictory security claim at SKILL.md:417-420:

markdown
- A shared platform API key is bundled as the default — override with `OCA_API_KEY` if needed
- Optional `OCA_AGENT_KEY` for agent-owned actions (queue, discussions)
- Data sent: agent names, agent IDs, match IDs, owner strings (no PII beyond what the user provides)
- No secrets stored in script files

Technical Analysis

The script embeds an API key and automatically uses it whenever OCA_API_KEY is unset. Because the project is distributed to users, this credential must be considered publicly disclosed. The key is attached to requests through the x-api-key header and permits access to the supported platform API operations.

Embedding a shared credential prevents effective attribution and least-privilege separation between users. It also contradicts the explicit claim that no secrets are stored in script files. Even if the key is intended for shared public access, representing it as a secret-style API key creates abuse, rotation, and quota-management risks.

Attack Path

  1. An attacker obtains or downloads the Skill package.
  2. The attacker reads scripts/openclawarena.sh and extracts the value assigned to API_KEY.
  3. The attacker submits requests directly to the documented REST endpoint with the extracted value in the x-api-key header.
  4. The attacker invokes any API operations authorized for that shared key without possessing an independently provisioned platform credential.
  5. Requests are charged, rate-limited, or attributed to the shared credential rather than an individual user.

...[truncated 615 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the embedded API key because it must be treated as publicly disclosed.
  2. Remove the fallback value and require callers to provide OCA_API_KEY explicitly:
    bash
    API_KEY="${OCA_API_KEY:-}"
    
  3. Retain the existing require_api_key check so execution fails safely when the variable is absent.
  4. Provision separate, scoped credentials per user or installation instead of distributing a shared credential.
  5. Restrict each credential to only the required API methods and resources.
  6. Apply server-side rate limits, anomaly monitoring, expiration, and revocation controls.
  7. Use a secret manager or another secure provisioning mechanism where automated credential delivery is required.
  8. Correct SKILL.md so its security statements accurately describe credential handling.

T08 · Insecure Dependencies

Note
Location
SKILL.md:96
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:96-98
Vulnerability Type: Unpinned dependency installation
Risk Level: Low

Vulnerable Code

bash
npm install ws

Technical Analysis

The documentation instructs users to install ws without specifying a reviewed version or using a lockfile with integrity metadata. Consequently, the installed artifact depends on mutable npm registry state at the time the command is run.

This is a supply-chain hardening weakness rather than evidence that the current ws package is malicious. If the package, its distribution account, registry metadata, or a transitive dependency were compromised in the future, users following the instruction could retrieve unintended code. npm installation can also run lifecycle scripts unless those scripts are explicitly disabled.

Attack Path

  1. A user follows the documented prerequisite and runs npm install ws.
  2. npm resolves the current package release and dependency graph from the configured registry.
  3. If the selected release, registry response, maintainer account, or transitive dependency has been compromised, npm downloads the attacker-controlled package content.
  4. Installation lifecycle behavior may execute with the privileges of the user running npm.
  5. The installed malicious or vulnerable component may subsequently execute when the example WebSocket client imports it.

Impact Assessment

Successful exploitation could execute package-controlled code with the privileges of the user performing installation or running the example agent. This could affect files, environment variables, and credentials accessible to that user, potentially including OCA_AGENT_ID and OCA_AGENT_KEY.

The scope depends on the installation environment and user privileges. The repository itself contains no evidence that the currently published dependency is compromised, so this finding is rated Low.

Remediation
View remediation

Remediation Suggestions

  1. Pin ws to a specifically reviewed version rather than resolving the latest release.
  2. Provide a committed package.json and package-lock.json containing integrity hashes.
  3. Instruct users to run npm ci against the reviewed lockfile instead of an unconstrained installation command.
  4. Use npm ci --ignore-scripts when dependency lifecycle scripts are not required.
  5. Periodically scan the locked dependency graph for known vulnerabilities and review updates before changing versions.
  6. Document the expected npm registry and avoid untrusted registry overrides.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill description says it is for registering and managing arena agents, but the documented commands also allow social/forum operations such as posting and replying. This mismatch can mislead users and reviewers about the skill's true behavior, increasing the chance of unexpected outbound actions or abuse of bundled/shared credentials for content posting.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises shell-capable behavior via required binaries and script usage, but does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity: a host may permit broader execution than the user expects, and reviewers cannot easily verify the minimum required capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that a shared platform API key is included by default, with no setup required for browsing. Bundling shared credentials for automatic outbound API access weakens accountability, obscures to users that requests are being made under common credentials, and can enable quota exhaustion, abuse, or unintended cross-tenant impact if the key is overused or leaked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

A hardcoded default API key means the script will make authenticated outbound requests even when the user has not intentionally supplied credentials. This creates unauthorized credential use, weakens accountability, and may expose a shared or embedded secret to anyone with access to the skill source.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The usage/help text and stated skill behavior focus on arena and agent management, but the script also exposes forum/discussion read-write operations. This capability mismatch is security-relevant because users and higher-level agents may invoke the skill under incomplete assumptions, leading to unintended public posting or broader data handling than disclosed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/openclawarena.sh (reported line 71)May include surrounding context.

sh
# GET request to the REST API
api_get() {
    local path="$1"
    curl --fail --show-error --silent --max-time 20 \
        -H "x-api-key: $API_KEY" \
        "${API_HOST}${path}"
}

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code includes post and reply functions that can publish user-supplied content to external discussions, which exceeds the declared arena-management purpose. Hidden write-capable behavior increases the risk of unintended outbound actions, spam, data leakage, or misuse by automation that believes the skill is read-only or management-only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.