T09 · Insecure Skill Coding Practices
- Location
lib/clawprint-http.js:51- Finding
API credentials can be transmitted over plaintext HTTP to an arbitrary configured host
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended for Clawprint API use, but it handles business-formation credentials and legal/business actions with overly broad API access and unsafe secret-handling patterns.
Review before installing. Use only with a trusted Clawprint endpoint, avoid HTTP or untrusted CLAWPRINT_API_URL/CLAWPRINT_SITE_URL values, do not pass secret keys on the command line, do not run cat .env in shared or logged terminals, and assume business-creation calls may have legal and account-level consequences.
lib/clawprint-http.js:51API credentials can be transmitted over plaintext HTTP to an arbitrary configured host
scripts/clawprint.js:75Secret-key command-line option exposes credentials through process metadata and shell history
scripts/clawprint.js:188Credential-bearing registration responses are printed to standard output without redaction
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd clawprint-skill
npm install
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
cd clawprint-skill
npm install
cp .env.example .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
source .env # or export the two vars
curl -H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
-H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
https://clawprintai.com/api/businesses
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
source .env # or export the two vars
curl -H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
-H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
https://clawprintai.com/api/businesses
Instructing users to run cat .env can print sensitive API keys directly to the terminal, logs, screen recordings, or remote session transcripts. In an agent or shared execution environment, this increases the chance of accidental credential disclosure beyond the intended operator.
cat .env
### `GET /api/products` / products list fails
Although framed as creating LLCs with sponsor oversight, the documented behavior includes generic API invocation, account creation, product discovery, and credentialed requests without embedding any actual sponsor-verification or LLC-specific safety controls in the skill itself. In context, that makes the skill more dangerous because it handles identity/business onboarding and secrets, so a generic client hidden behind a narrow legal-services description can enable unauthorized account actions, data submission, or credential misuse.
Although framed as creating LLCs with sponsor oversight, the documented behavior includes generic API invocation, account creation, product discovery, and credentialed requests without embedding any actual sponsor-verification or LLC-specific safety controls in the skill itself. In context, that makes the skill more dangerous because it handles identity/business onboarding and secrets, so a generic client hidden behind a narrow legal-services description can enable unauthorized account actions, data submission, or credential misuse.
The README states that Clawprint lets AI agents 'form LLCs, open bank accounts, and accept payments,' which materially expands the apparent capability of the skill beyond its stated purpose of LLC formation. In an agentic context, overstating financial capabilities can mislead operators or downstream agents into attempting high-risk actions involving regulated banking or payments without appropriate safeguards, approvals, or actual implementation status.
The documentation simultaneously claims current support for opening bank accounts and accepting payments, then later lists banking and payments as future features. This inconsistency can cause agents or users to rely on nonexistent financial functionality, leading to unsafe automation decisions, incorrect trust assumptions, or accidental disclosure of sensitive data while attempting unsupported operations.
The README instructs users to place public and secret API keys in a local .env file and notes that the CLI will automatically transmit them, but it does not include any warning about credential sensitivity, storage hygiene, logging exposure, or the consequences of sending long-lived secret keys. Because this skill deals with legal-entity creation and potentially financial workflows, mishandling these credentials could enable unauthorized account actions or access to sensitive business operations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Via API:
curl -X POST https://clawprintai.com/api/businesses \
-H "X-Public-Key: $CLAWPRINT_PUBLIC_KEY" \
-H "X-Secret-Key: $CLAWPRINT_SECRET_KEY" \
-H "Content-Type: application/json" \
The skill explicitly relies on environment variables for API base URLs and authentication keys, yet it declares no tool scope or permission boundaries. In an agent setting, undeclared env access increases the chance of secret exposure or unauthorized use of ambient credentials because the skill can implicitly depend on sensitive runtime state without user-visible approval.
The helper accepts an arbitrary absolute URL via the url parameter and then conditionally attaches X-Public-Key and X-Secret-Key before issuing the request. If any upstream caller can influence that URL, this becomes an SSRF/exfiltration primitive that can send Clawprint credentials and request bodies to attacker-controlled hosts, not just intended Clawprint endpoints.
The request helper sends network traffic and, when auth is enabled, includes X-Public-Key and X-Secret-Key sourced from arguments or environment variables. In this file there is no confirmation prompt, logging, or user-facing disclosure that credentials and possibly request data will be transmitted over the network.
The script is presented as a narrowly scoped LLC-formation skill, but its own header and CLI options expose a generic API client that can discover products and invoke arbitrary documented routes. In an agent skill context, this broad capability materially expands the action surface beyond the declared purpose, enabling unintended account, business, or administrative API operations if the agent is induced to use it.
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
continue;
}
if (a === '--no-auth') {
opts.auth = false;
continue;
}
const take = (key) => {
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
continue;
}
if (a === '--no-auth') {
opts.auth = false;
continue;
}
const take = (key) => {
The run path permits callers to supply arbitrary API paths, methods, query strings, and bodies, or to resolve them dynamically from the products list, turning the skill into a general-purpose API invoker. For a skill intended only to form legal entities, this is dangerous because prompt injection or misuse could steer the agent into unrelated or sensitive API actions using available credentials.
No suspicious patterns detected.