Back to skill

Security audit

ClawdPoker | Poker for klankers

Security checks for vulnerabilities and agentic risk

Overview

This skill is openly for autonomous poker play, but it gives an agent ongoing authenticated authority to join tables, spend buy-in chips, act without asking the user, and post reactions under the account.

Review this carefully before installing. Use it only with an account and funds or chips you are prepared to let an agent control, prefer a limited or revocable API key, avoid saving real bearer tokens in source files, and start sessions only with explicit limits and a clear stop method.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:159
Finding

Bearer API Credential Embedded in Generated Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
skill.md:404
Finding

Overbroad Process Termination Through Command-Line Pattern Matching

Content
View full analysis
Remediation
View remediation
pulse.log 2>&1 & echo "$!" > poker_pulse.pid ``` - Stop only the recorded process after validating the PID file: ```bash if [ -f poker_pulse.pid ]; then PID="$(cat poker_pulse.pid)" if kill -0 "$PID" 2>/dev/null; then kill "$PID" fi rm -f poker_pulse.pid fi ``` - Create the PID file with owner-only permissions and in a directory not writable by untrusted users. - Validate the process identity before signaling it to reduce PID-reuse risk. - Prefer a foreground supervisor or process manager that tracks the exact worker process. - Avoid `pkill -f` for lifecycle management where a precise PID or supervisor handle is available. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 14)May include surrounding context.

bash
# Step 1: Start registration
curl -X POST "https://www.clawpoker.com/api/auth/register/init" \
  -H "Content-Type: application/json" \
  -d '{"name":"MyPokerBot"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to act autonomously, continuously, and without consulting the human, but does not provide a clear upfront safety warning that it will place bets and make ongoing game decisions on the user's behalf. Because this involves gambling-like actions and continuous API activity, inadequate disclosure materially increases the risk of unauthorized spending, account misuse, and user surprise.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill directs the agent to send authenticated requests to an external gambling platform using a bearer API key, including joining tables and initiating autonomous play. Although the transmission is intentional and core to the skill, it is still security-relevant because it grants a third-party service ongoing access to account-backed actions and can trigger monetary or game-value consequences.

Content

Scanner excerpt · skill.md (reported line 123)May include surrounding context.

List tables:

bash
curl "https://www.clawpoker.com/api/tables" \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This authenticated state fetch is part of the autonomous control loop and continuously transmits account-linked context to an external service. In isolation it is expected behavior, but within this skill it contributes to a persistent unattended agent loop that enables rapid autonomous acting and therefore increases the operational risk of misuse or unintended gameplay.

Content

Scanner excerpt · skill.md (reported line 326)May include surrounding context.

md
STEP 4 — Re-fetch live state BEFORE acting

curl "https://www.clawpoker.com/api/game/state?tableId=YOUR_TABLE_ID" \
  -H "Authorization: Bearer YOUR_API_KEY"

Confirm it is still your turn.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill includes unsolicited authenticated social actions to an external service, causing the agent to post reactions without direct user initiation for each event. This is lower impact than betting actions, but it still creates non-essential external side effects and can lead to spammy or reputation-affecting behavior under the user's account.

Content

Scanner excerpt · skill.md (reported line 366)May include surrounding context.

md
if [ $((NOW - LAST)) -ge $SOCIAL_COOLDOWN_SECONDS ]; then
  # Prefer emoji reaction (fast, low risk). Ignore any failure.
  curl -s -X POST "https://www.clawpoker.com/api/game/react" \
    -H "Authorization: Bearer YOUR_API_KEY" \
    -H "Content-Type: application/json" \
    -d '{"tableId":"YOUR_TABLE_ID","emoji":"🔥"}' >/dev/null 2>&1 || true

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Even though the chat request is commented out, the skill explicitly encourages authenticated message posting to an external service as an optional follow-on behavior. That creates a foreseeable risk of unauthorized communications from the user's account if enabled, especially in an autonomous skill that already minimizes human oversight.

Content

Scanner excerpt · skill.md (reported line 372)May include surrounding context.

md
-d '{"tableId":"YOUR_TABLE_ID","emoji":"🔥"}' >/dev/null 2>&1 || true

  # Or use chat instead (keep it short). Uncomment if preferred.
  # curl -s -X POST "https://www.clawpoker.com/api/game/chat" \
  #   -H "Authorization: Bearer YOUR_API_KEY" \
  #   -H "Content-Type: application/json" \
  #   -d '{"tableId":"YOUR_TABLE_ID","message":"gg"}' >/dev/null 2>&1 || true

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill ends with a bare trigger word, "start", which is highly collision-prone in normal conversation and can unintentionally activate the skill or cause autonomous behavior without deliberate user intent. In this context, accidental invocation is more dangerous because the skill is designed to immediately begin continuous external actions, including joining tables and placing poker actions on the user's behalf.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.