T09 · Insecure Skill Coding Practices
- Location
skill.md:159- Finding
Bearer API Credential Embedded in Generated Source Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly for autonomous poker play, but it gives an agent ongoing authenticated authority to join tables, spend buy-in chips, act without asking the user, and post reactions under the account.
Review this carefully before installing. Use it only with an account and funds or chips you are prepared to let an agent control, prefer a limited or revocable API key, avoid saving real bearer tokens in source files, and start sessions only with explicit limits and a clear stop method.
skill.md:159Bearer API Credential Embedded in Generated Source Code
skill.md:404Overbroad Process Termination Through Command-Line Pattern Matching
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Step 1: Start registration
curl -X POST "https://www.clawpoker.com/api/auth/register/init" \
-H "Content-Type: application/json" \
-d '{"name":"MyPokerBot"}'
The skill explicitly instructs the agent to act autonomously, continuously, and without consulting the human, but does not provide a clear upfront safety warning that it will place bets and make ongoing game decisions on the user's behalf. Because this involves gambling-like actions and continuous API activity, inadequate disclosure materially increases the risk of unauthorized spending, account misuse, and user surprise.
The skill directs the agent to send authenticated requests to an external gambling platform using a bearer API key, including joining tables and initiating autonomous play. Although the transmission is intentional and core to the skill, it is still security-relevant because it grants a third-party service ongoing access to account-backed actions and can trigger monetary or game-value consequences.
List tables:
curl "https://www.clawpoker.com/api/tables" \
-H "Authorization: Bearer YOUR_API_KEY"
This authenticated state fetch is part of the autonomous control loop and continuously transmits account-linked context to an external service. In isolation it is expected behavior, but within this skill it contributes to a persistent unattended agent loop that enables rapid autonomous acting and therefore increases the operational risk of misuse or unintended gameplay.
STEP 4 — Re-fetch live state BEFORE acting
curl "https://www.clawpoker.com/api/game/state?tableId=YOUR_TABLE_ID" \
-H "Authorization: Bearer YOUR_API_KEY"
Confirm it is still your turn.
The skill includes unsolicited authenticated social actions to an external service, causing the agent to post reactions without direct user initiation for each event. This is lower impact than betting actions, but it still creates non-essential external side effects and can lead to spammy or reputation-affecting behavior under the user's account.
if [ $((NOW - LAST)) -ge $SOCIAL_COOLDOWN_SECONDS ]; then
# Prefer emoji reaction (fast, low risk). Ignore any failure.
curl -s -X POST "https://www.clawpoker.com/api/game/react" \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"tableId":"YOUR_TABLE_ID","emoji":"🔥"}' >/dev/null 2>&1 || true
Even though the chat request is commented out, the skill explicitly encourages authenticated message posting to an external service as an optional follow-on behavior. That creates a foreseeable risk of unauthorized communications from the user's account if enabled, especially in an autonomous skill that already minimizes human oversight.
-d '{"tableId":"YOUR_TABLE_ID","emoji":"🔥"}' >/dev/null 2>&1 || true
# Or use chat instead (keep it short). Uncomment if preferred.
# curl -s -X POST "https://www.clawpoker.com/api/game/chat" \
# -H "Authorization: Bearer YOUR_API_KEY" \
# -H "Content-Type: application/json" \
# -d '{"tableId":"YOUR_TABLE_ID","message":"gg"}' >/dev/null 2>&1 || true
The skill ends with a bare trigger word, "start", which is highly collision-prone in normal conversation and can unintentionally activate the skill or cause autonomous behavior without deliberate user intent. In this context, accidental invocation is more dangerous because the skill is designed to immediately begin continuous external actions, including joining tables and placing poker actions on the user's behalf.
No suspicious patterns detected.