Back to skill

Security audit

ClawPeers

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for ClawPeers marketplace matching, but it needs review because it stores credentials locally, can start a background WebSocket runtime, and exposes a broad signed event-publishing command.

Review before installing. Use this only if you trust the ClawPeers service and are comfortable with a local ClawPeers identity, bearer token, drafts, profiles, and message/event data being stored on disk. Avoid the generic publish-event path unless the action and payload are explicitly approved, and avoid WebSocket mode unless you want a background inbox process.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/clawpeers_runtime.mjs:1166
Finding

Sensitive intro approvals and direct messages can be transmitted without runtime consent enforcement

Content
View full analysis
10 ? envelopeJson : signEnvelope( { v: String(envelopeJson.v), type: String(envelopeJson.type ?? ''), ts: Number(envelopeJson.ts), from: String(envelopeJson.from), nonce: String(envelopeJson.nonce), payload: envelopeJson.payload, }, identity.signing_private_jwk, ); } else { const type = String(args.type ?? '').trim(); if (!type) { throw new Error('--type is required when --envelope-json is not provided'); } ...[truncated 2988 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clawpeers_runtime.mjs:210
Finding

Private keys, bearer tokens, and personal marketplace data are persisted without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is request routing for people-finding and marketplace interactions, but the skill also instructs onboarding, bearer-token authentication, inbox polling, acknowledgments, and operational status checks. That mismatch is dangerous because it can cause an agent or reviewer to authorize a skill for a narrow conversational purpose while it performs broader authenticated operational actions against backend services.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
`scripts/clawpeers_runtime.mjs` is the canonical merged runtime:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
`scripts/clawpeers_runtime.mjs` is the canonical merged runtime:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
`scripts/clawpeers_runtime.mjs` is the canonical merged runtime:

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The publish-event command allows callers to choose any topic and provide arbitrary payloads or even prebuilt envelopes, which the runtime will sign with the local identity key and send using the authenticated token. That makes this skill a generic signed-message publisher, not merely a routing helper, enabling unauthorized or unintended actions on the remote platform under the user’s identity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes networked and runtime command behavior, including authenticated HTTP calls and shell-invoked scripts, but does not declare any explicit tool scope such as permissions or allowed-tools. This creates a capability-transparency gap: a host may permit broader execution than users or reviewers expect, increasing the risk of unintended network access, token use, or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very common language such as 'I need', 'find', and 'looking for', which can match many ordinary requests unrelated to marketplace posting. Overbroad triggers can cause the skill to capture conversations unexpectedly, steer users into publish flows they did not intend, and expose user data to external services under mistaken activation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The rule to trigger on requests to find or connect with a person lacks precise boundaries and examples of disallowed or ambiguous cases. In context, that matters because this skill leads into external drafting, preview, and possible publishing flows, so ambiguous activation can result in unnecessary collection, retention, or transmission of user requests and personal details.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
### 5. Consent and Safety Rules

- Never auto-approve intro requests unless user explicitly instructs approval.
- Never send DM payloads without an approved thread context.
- Keep user identity and exact location private unless user explicitly chooses to reveal.
- If auth expires or returns 401, re-run challenge/verify and retry once.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt uses very broad lexical triggers such as 'I need', 'find', and 'looking for' to route users into the ClawPeers workflow. Because these phrases appear in many unrelated requests, the skill may be invoked when the user did not intend marketplace or people-finding behavior, causing misrouting, unnecessary data collection, or accidental progression toward posting/publishing flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow allows short, generic confirmations such as 'please', 'yes', 'ok', 'go ahead', and 'continue' to advance a stored need draft based on prior chat context. In a marketplace/person-finding skill, those terms frequently appear in ordinary conversation, so the agent may misinterpret unrelated replies as approval and proceed toward publishing sensitive or reputation-impacting requests without sufficiently specific consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code generates identity keys and persists private JWK material in plaintext JSON under the user’s home directory. If the local machine, account, backups, or filesystem permissions are compromised, an attacker can steal the signing identity and impersonate the user for future authenticated or signed actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The runtime stores bearer tokens on disk in the session file without a user-facing warning, which creates a reusable credential artifact on the local system. Anyone who can read that file can likely act as the user against the ClawPeers API until expiry, and refresh logic may keep the session active over time.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The runtime exposes substantially broader capabilities than the skill description justifies, including profile publication, subscription management, inbox polling/acking, arbitrary event publishing, WebSocket daemon management, and stateful local persistence. For a skill whose stated purpose is routing people-finding and marketplace requests into a need-draft/preview/explicit publish flow, this expanded control surface increases the chance an agent can take side-effecting actions unrelated to the user’s request.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.exposed_secret_literal

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/clawpeers_runtime.mjs:535

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/clawpeers_runtime.mjs:284