Back to skill

Security audit

Clawprint-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for Clawprint API use, but it handles business-formation credentials and legal/business actions with overly broad API access and unsafe secret-handling patterns.

Review before installing. Use only with a trusted Clawprint endpoint, avoid HTTP or untrusted CLAWPRINT_API_URL/CLAWPRINT_SITE_URL values, do not pass secret keys on the command line, do not run cat .env in shared or logged terminals, and assume business-creation calls may have legal and account-level consequences.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
lib/clawprint-http.js:51
Finding

API credentials can be transmitted over plaintext HTTP to an arbitrary configured host

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clawprint.js:75
Finding

Secret-key command-line option exposes credentials through process metadata and shell history

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clawprint.js:188
Finding

Credential-bearing registration responses are printed to standard output without redaction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 15)May include surrounding context.

bash
cd clawprint-skill
npm install
cp .env.example .env

Step 2: Environment

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 12)May include surrounding context.

bash
cd clawprint-skill
npm install
cp .env.example .env

Step 2: Environment

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 78)May include surrounding context.

Manual API Calls

bash
source .env  # or export the two vars
curl -H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
  -H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
  https://clawprintai.com/api/businesses

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SETUP.md (reported line 99)May include surrounding context.

Manual API Calls

bash
source .env  # or export the two vars
curl -H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
  -H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
  https://clawprintai.com/api/businesses

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Instructing users to run cat .env can print sensitive API keys directly to the terminal, logs, screen recordings, or remote session transcripts. In an agent or shared execution environment, this increases the chance of accidental credential disclosure beyond the intended operator.

Content

Scanner excerpt · SETUP.md (reported line 103)May include surrounding context.

CLAWPRINT_PUBLIC_KEY=public_xxx

CLAWPRINT_SECRET_KEY=secret_xxx

cat .env

text

### `GET /api/products` / products list fails

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Although framed as creating LLCs with sponsor oversight, the documented behavior includes generic API invocation, account creation, product discovery, and credentialed requests without embedding any actual sponsor-verification or LLC-specific safety controls in the skill itself. In context, that makes the skill more dangerous because it handles identity/business onboarding and secrets, so a generic client hidden behind a narrow legal-services description can enable unauthorized account actions, data submission, or credential misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Although framed as creating LLCs with sponsor oversight, the documented behavior includes generic API invocation, account creation, product discovery, and credentialed requests without embedding any actual sponsor-verification or LLC-specific safety controls in the skill itself. In context, that makes the skill more dangerous because it handles identity/business onboarding and secrets, so a generic client hidden behind a narrow legal-services description can enable unauthorized account actions, data submission, or credential misuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that Clawprint lets AI agents 'form LLCs, open bank accounts, and accept payments,' which materially expands the apparent capability of the skill beyond its stated purpose of LLC formation. In an agentic context, overstating financial capabilities can mislead operators or downstream agents into attempting high-risk actions involving regulated banking or payments without appropriate safeguards, approvals, or actual implementation status.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation simultaneously claims current support for opening bank accounts and accepting payments, then later lists banking and payments as future features. This inconsistency can cause agents or users to rely on nonexistent financial functionality, leading to unsafe automation decisions, incorrect trust assumptions, or accidental disclosure of sensitive data while attempting unsupported operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to place public and secret API keys in a local .env file and notes that the CLI will automatically transmit them, but it does not include any warning about credential sensitivity, storage hygiene, logging exposure, or the consequences of sending long-lived secret keys. Because this skill deals with legal-entity creation and potentially financial workflows, mishandling these credentials could enable unauthorized account actions or access to sensitive business operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · REFERENCE.md (reported line 20)May include surrounding context.

Via API:

bash
curl -X POST https://clawprintai.com/api/businesses \
  -H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
  -H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
  -H "Content-Type: application/json" \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill explicitly relies on environment variables for API base URLs and authentication keys, yet it declares no tool scope or permission boundaries. In an agent setting, undeclared env access increases the chance of secret exposure or unauthorized use of ambient credentials because the skill can implicitly depend on sensitive runtime state without user-visible approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The helper accepts an arbitrary absolute URL via the url parameter and then conditionally attaches X-Public-Key and X-Secret-Key before issuing the request. If any upstream caller can influence that URL, this becomes an SSRF/exfiltration primitive that can send Clawprint credentials and request bodies to attacker-controlled hosts, not just intended Clawprint endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The request helper sends network traffic and, when auth is enabled, includes X-Public-Key and X-Secret-Key sourced from arguments or environment variables. In this file there is no confirmation prompt, logging, or user-facing disclosure that credentials and possibly request data will be transmitted over the network.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script is presented as a narrowly scoped LLC-formation skill, but its own header and CLI options expose a generic API client that can discover products and invoke arbitrary documented routes. In an agent skill context, this broad capability materially expands the action surface beyond the declared purpose, enabling unintended account, business, or administrative API operations if the agent is induced to use it.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/clawprint.js (reported line 67)May include surrounding context.

js
continue;
    }
    if (a === '--no-auth') {
      opts.auth = false;
      continue;
    }
    const take = (key) => {

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/clawprint.js (reported line 177)May include surrounding context.

js
continue;
    }
    if (a === '--no-auth') {
      opts.auth = false;
      continue;
    }
    const take = (key) => {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The run path permits callers to supply arbitrary API paths, methods, query strings, and bodies, or to resolve them dynamically from the products list, turning the skill into a general-purpose API invoker. For a skill intended only to form legal entities, this is dangerous because prompt injection or misuse could steer the agent into unrelated or sensitive API actions using available credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.