Back to skill

Security audit

ClawdTalk

Security checks for vulnerabilities and agentic risk

Overview

This skill is disclosed as a voice/SMS bridge, but it gives remote call and message flows broad access to the user's main agent with weak approval boundaries.

Install only if you are comfortable letting ClawdTalk phone calls, SMS, and cloud events reach your main agent session and its connected tools. Before using it, restrict sessions_send to the narrowest possible scope, avoid storing live gateway tokens in skill-config.json, keep approval fail-closed, remove voice-only approval fallback for sensitive actions, and review update/dependency handling.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (7)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ws-client.js:319
Finding

Remote ClawdTalk Events Can Inject Instructions into the Fully Privileged Main Agent Session

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ws-client.js:426
Finding

Sensitive Actions Fail Open When Approval Devices Are Unavailable

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ws-client.js:356
Finding

Remote WebSocket Messages Can Select Arbitrary Local Agent Sessions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
setup.sh:176
Finding

ClawdTalk and Gateway Bearer Tokens Are Duplicated into a Plaintext Configuration File

Content
View full analysis
"$CONFIG_FILE" << EOF { "api_key": $api_key_json, "server": "https://clawdtalk.com", "owner_name": $owner_name_json, "agent_name": $agent_name_json, "greeting": "$greeting", "gateway_url": $gateway_url_json, "gateway_token": $gateway_token_json, "agent_id": $agent_id_json } EOF ``` ### Technical Analysis Setup reads the Gateway authentication token from the primary OpenClaw or Clawdbot configuration and copies it into `skill-config.json`. It also stores the ClawdTalk API key in that file. The script does not set a restrictive `umask`, create the file atomically with a protected mode, or call `chmod 600`. The resulting access mode therefore depends on the invoking process's environment. This also unnecessarily duplicates the Gateway credential into another file, increasing its exposure surface. The Gateway token is particularly sensitive because setup enables `sessions_send`, allowing the holder to inject content into Agent sessions through `/tools/invoke`. ### Attack Path 1. The user runs `setup.sh`. 2. Setup reads the Gateway token from the existing Gateway configuration. 3. The token and ClawdTalk API key are written to `skill-config.json`. 4. A local process, another user under permissive directory conditions, a backup process, or an accidentally published archive obtains the file. 5. The attacker uses the ClawdTalk key to impersona ...[truncated 653 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/ws-client.js:1041
Finding

WebSocket Client Installs a Mutable Dependency at Runtime Through a Shell

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
update.sh:33
Finding

Self-Updater Retrieves and Installs Mutable Remote Code from a Single Trust Authority

Content
View full analysis
/dev/null || true) LATEST_VERSION="${LATEST_TAG#v}" ``` ```bash curl -sL "$ZIP_URL" -o "$ARCHIVE_ZIP" if [ -n "${CHECKSUM_URL:-}" ]; then curl -sL "$CHECKSUM_URL" -o "$CHECKSUM_FILE" fi ``` ```bash if [ "$EXPECTED_SHA" != "$ACTUAL_SHA" ]; then echo -e "${RED}Error: SHA256 checksum mismatch. Aborting update.${NC}" rm -rf "$TEMP_DIR" exit 1 fi # Extract and update echo "Installing update..." cd "$TEMP_DIR" unzip -q "$ARCHIVE_ZIP" # Copy new files (preserve skill-config.json) if [ -d "clawdtalk-client" ]; then cp -r clawdtalk-client/* "$SKILL_DIR/" 2>/dev/null || true else ARCHIVE_BASENAME=$(basename "$ARCHIVE_ZIP") CHECKSUM_BASENAME=$(basename "$CHECKSUM_FILE") shopt -s dotglob nullglob for item in *; do case "$item" in "$ARCHIVE_BASENAME"|"${CHECKSUM_BASENAME}") continue ;; esac cp -r "$item" "$SKILL_DIR/" 2>/dev/null || true done shopt -u dotglob nullglob fi ``` ```bash # Install dependencies if needed if [ -f "$SKILL_DIR/package.json" ]; then echo "Installing dependencies..." cd "$SKILL_DIR" npm install --production 2>/dev/null || true fi ``` ### Technical Analysis The updater downloads a release archive and its SHA-256 checksum from assets selected through the same GitHub repository and release metadata. The checksum can detect accidental corruption, but it does not provide independent publisher authentication: anyone able to compromise the repository, release workflow, or maintainer account can publish both a malicious archive and its matching checksum. After verification, the archive is extracted ...[truncated 1596 chars]
Remediation
View remediation

other

Warning
Location
SKILL.md:67
Finding

Skill Instructions Mandate Excessive Local and Remote Persistence of Operational Data

Content
View full analysis
**Rule: If you did something, save it to memory. No exceptions. No "I'll do it later." Do it NOW.** ``` ```markdown ## Two-Layer Persistence: Memory + Events Always save to BOTH: 1. **Local Memory** (`.missions_state.json`) - Fast, survives restarts 2. **Events API** (cloud) - Permanent audit trail, survives local file loss | Action | Save Memory | Log Event | |--------|-------------|-----------| | Web search returns results | append-memory | log-event (tool_call) | | Found a contractor/lead | append-memory | log-event (custom) | | Created assistant | save-memory | log-event (custom) | | Assigned phone number | save-memory | log-event (custom) | | Scheduled a call/SMS | append-memory | log-event (custom) | | Call completed | save-memory | log-event (custom) | | Got quote/insight | save-memory | log-event (custom) | | Made a decision | save-memory | log-event (message) | | Step started | save-memory | update-step (in_progress) + log-event (step_started) | | Step completed | save-memory | update-step (completed) + log-event (step_completed) | | Step failed | save-memory | update-step (failed) + log-event (error) | | Error occurred | save-memory | log-event (error) | ``` ### Technical Analysis The Skill mandates that every significant action be retained in both local mission state and remote cloud events. The required categories include search results, leads, phone-related information, messages, decisions, quotes, tool calls, and error details. Some mission state is ...[truncated 1622 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (62)

Tainted flow: 'req' from os.environ.get (line 70, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The request destination is derived from environment/config-controlled BASE_URL and then used directly in urllib.request.urlopen while automatically attaching the Bearer API key. If an attacker can influence CLAWDTALK_API_URL or the skill-config server value, they can redirect authenticated requests to an attacker-controlled host and exfiltrate credentials and mission data.

Content

Scanner excerpt · scripts/telnyx_api.py (reported line 73)May include surrounding context.

python
req = urllib.request.Request(url, data=body, headers=headers, method=method)

    try:
        with urllib.request.urlopen(req, timeout=60) as response:
            response_body = response.read().decode("utf-8")
            if response_body:
                return json.loads(response_body)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CHANGELOG.md (reported line 35)May include surrounding context.

md
- Call reports now appear in your Telegram/Discord/etc. session instead of ephemeral sessions

## 1.2.7
- **New**: `update.sh` script for easy self-updates from GitHub
- **New**: `dist/clawdtalk-client-latest.zip` in repo for direct downloads
- Run `./update.sh` to check for and install updates

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill can update itself from GitHub, overwrite local installation files, run npm install, and stop/restart local components. Self-update plus package installation is a significant supply-chain and host-integrity risk, especially when bundled under a broad telephony description without explicit permission boundaries.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

The documentation indicates the skill can update its own configuration and references update behavior elsewhere, which is risky in combination with remote downloads and package installation. Self-modification or self-update mechanisms can be abused for persistence or supply-chain compromise if not strongly verified and user-approved.

Content

Scanner excerpt · SKILL.md (reported line 819)May include surrounding context.

md
## Troubleshooting

- **Auth failed**: Regenerate API key at clawdtalk.com
- **Gateway token/port changed**: Re-run `./setup.sh` to update skill-config.json with the new values
- **Empty responses**: Run `./setup.sh` and restart gateway
- **Slow responses**: Try a faster model in your gateway config
- **Debug mode**: `DEBUG=1 ./scripts/connect.sh restart`

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
98% confidence
Finding

The lockfile pins the project to ws 8.19.0, and the supplied advisory data indicates this version is affected by an uninitialized memory disclosure and a memory-exhaustion denial-of-service issue. Because this skill is a voice/SMS/WebSocket client, ws is likely used on a network-facing code path, which makes remotely triggered information leakage or service disruption more plausible and increases operational risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.19.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
92% confidence
Finding

The allowed dependency range can resolve to ws 8.19.0, which is reported as affected by memory disclosure and memory-exhaustion denial-of-service vulnerabilities. In a voice/SMS client, WebSocket connectivity is likely network-facing or processes untrusted remote traffic, making crashes, resource exhaustion, or unintended data exposure more consequential.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/call.sh (reported line 45)May include surrounding context.

sh
# Find .env files
  local env_files=(
    "$HOME/.openclaw/.env"
    "$HOME/.clawdbot/.env"
    "$SKILL_DIR/.env"
  )

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/call.sh (reported line 46)May include surrounding context.

sh
# Find .env files
  local env_files=(
    "$HOME/.openclaw/.env"
    "$HOME/.clawdbot/.env"
    "$SKILL_DIR/.env"
  )

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/call.sh (reported line 47)May include surrounding context.

sh
# Find .env files
  local env_files=(
    "$HOME/.openclaw/.env"
    "$HOME/.clawdbot/.env"
    "$SKILL_DIR/.env"
  )

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/call.sh (reported line 43)May include surrounding context.

sh
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/connect.sh (reported line 11)May include surrounding context.

sh
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/connect.sh (reported line 13)May include surrounding context.

sh
#
# Usage: ./connect.sh {start|stop|status|restart} [--server <url>]
#
# Env vars: via .env
# Endpoints: none (launches ws-client.js)
# Reads: skill-config.json, .env
# Writes: .connect.pid, .connect.log

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The script sources $SKILL_DIR/.env directly with the shell '.' operator, which executes the file as shell code rather than safely parsing key-value pairs. If the .env file is modified by an attacker or contains unexpected shell syntax, arbitrary commands will run with the privileges of the user starting the connection.

Content

Scanner excerpt · scripts/connect.sh (reported line 143)May include surrounding context.

sh
echo "🚀 Starting WebSocket connection..."
    
    # Source skill's own .env if it exists (for skill-specific env vars only)
    [ -f "$SKILL_DIR/.env" ] && . "$SKILL_DIR/.env"
    
    # Rotate log if it's too big (> 1MB)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line is the same direct sourcing of the skill-local .env file and therefore enables arbitrary shell execution from what users may assume is passive configuration data. In an agent skill context, this is especially risky because setup artifacts and working directories may be writable by automation or other tools.

Content

Scanner excerpt · scripts/connect.sh (reported line 144)May include surrounding context.

sh
echo "🚀 Starting WebSocket connection..."
    
    # Source skill's own .env if it exists (for skill-specific env vars only)
    [ -f "$SKILL_DIR/.env" ] && . "$SKILL_DIR/.env"
    
    # Rotate log if it's too big (> 1MB)
    if [ -f "$LOG_FILE" ] && [ $(stat -f%z "$LOG_FILE" 2>/dev/null || stat -c%s "$LOG_FILE" 2>/dev/null || echo 0) -gt 1048576 ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/telnyx_api.py (reported line 50)May include surrounding context.

python
BASE_URL = _get_base_url()

def get_api_key():
    """Get API key from env var or skill-config.json."""
    key = os.environ.get("CLAWDTALK_API_KEY")
    if key:
        return key

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The header claims the script writes nothing, but the code later performs package installation that writes to disk and can alter the execution environment. This mismatch is security-relevant because operators may trust the file comment when evaluating whether the client is safe to run on a host.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The embedded approval narrative permits fallback from push approval to simple voice assent such as 'yes' or 'go ahead' for sensitive actions. In a voice channel, that weakens authentication and makes social engineering, spoofed callers, accidental assent, or STT transcription errors materially more likely to authorize destructive operations.

Content

No source excerpt is available for this finding.

Ssd 1

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The injected voicePrefix tells the downstream agent not to request approval because it has 'already been handled' and to perform the action directly. Combined with the weak/skip approval branches, this suppresses downstream safeguards and can cause sensitive actions to execute even when robust authorization was never actually obtained.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.credential_exposure_instructions, suspicious.dangerous_exec, suspicious.env_credential_access (+1 more)

Instructions expose credentials through shell, git config, or agent memory.

Critical
Code
suspicious.credential_exposure_instructions
Location
SKILL.md:71

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/ws-client.js:1043

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/ws-client.js:28

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/ws-client.js:162